Lecture 8 of the ACCA course focuses on the critical role of risk management and internal control systems within organizations. It covers various methodologies for risk assessment and emphasizes the internal audit's crucial role in ensuring effective control mechanisms are in place to mitigate identified risks.
Introduction to Risk Management and Internal Control
Organizations face various risks impacting objectives and operations.
Risk management identifies, assesses, and mitigates these risks.
Internal control systems provide structures to manage risks effectively.
Risk and control systems are interconnected for achieving organizational goals.
Governance bodies like the IIA and COSO highlight best practices.
Key terms: Risk Management, Internal Control
Importance of Risk Management in Organizations
Preserves organizational resources and reputation.
Supports compliance with legal and regulatory requirements.
Enhances resilience by preparing for uncertainties.
Improves strategic decision-making through risk-informed insights.
Reduces financial losses resulting from unforeseen risks.
Key terms: Resilience, Regulatory Compliance
Understanding Internal Control Systems
Internal control is a process to achieve operational, reporting, and compliance objectives.
Established by the COSO framework for enterprise risk oversight.
Controls address risk areas by preventing, detecting, or correcting errors.
Includes governance mechanisms for accountability.
Internal controls are integral to effective risk management.
Hayes, R. et al. (2005) Principles of Auditing. Pearson Education.
Healy, P.M. and Palepu, K.G. (2003) 'The fall of Enron'. Journal of Economic Perspectives, 17(2), pp. 3-26.
Hull, J. (2018) Risk Management and Financial Institutions. 5th Edn. John Wiley & Sons.
Manuj, I. and Mentzer, J.T. (2008) 'Global Supply Chain Risk Management Strategies'. International Journal of Physical Distribution & Logistics Management.
Hopkin, P. (2018) Fundamentals of Risk Management. 5th edn. London: Kogan Page.
ACCA (2021) 'Risk Management in Industries'. Professional Insights.
ISO (2018) 'ISO 27001: Data Security Protocols'.
Mintz, S. and Morris, R. (2017) Ethical Obligations and Decision Making in Accounting. New York: McGraw Hill.
COSO (2017) Enterprise Risk Management - Integrating with Strategy and Performance.
International Organization for Standardization (2018). Risk management guidelines, ISO 31000:2018.
COSO (2013) Internal Control — Integrated Framework.