2017年-德勤全球_Strengthening_internal_audit’s_impact_and_influence_14页_6mb
报告摘要
Deloitte: Strengthening Internal Audit's Impact and Influence
Core Content
Deloitte's report, Where insights lead, highlights the need for Internal Audit (IA) to increase its impact and influence within organizations. Based on the 2016 Global Chief Audit Executive Survey, only 28% of CAEs believe IA has strong impact, while 16% think it has little to none. However, two-thirds of CAEs expect IA to play a more significant role in the future. The report outlines nine proven strategies to achieve this, emphasizing that increasing impact is not about doing more, but doing the right things well.
Main Points and Key Strategies
1. Develop and Launch a Brand Identity
- What stakeholders need: A clear understanding of IA's role in providing assurance, advisory, and risk anticipation services.
- How to get moving:
- Define what IA should be known for (e.g., value-adding, insightful).
- Develop a value proposition that aligns with stakeholders' business goals and risks.
- Embed messaging in all communications to maintain consistency.
- Deliver more value than expected to strengthen IA's reputation.
2. Link Advisory Activities to Assurance Work
- What stakeholders need: IA should not only identify risks but also provide solutions and guidance.
- How to get moving:
- Adopt an advisory mindset, focusing on solving problems rather than just identifying them.
- Use external data and benchmarks to support recommendations.
- Network with peers to share best practices and solutions.
- Provide clear advice on the path forward, considering the implications of decisions.
3. Provide Cyberassurance Services
- What stakeholders need: Objective assurance on cyber risk management and how management is addressing these risks.
- How to get moving:
- Adopt a cyber risk framework (e.g., Deloitte’s framework).
- Conduct a comprehensive risk assessment, identifying digital assets and potential threats.
- Establish a dynamic assurance cycle that reflects current and emerging cyber threats.
4. Audit the End-to-End Risk Management Function
- What stakeholders need: Clear understanding of risk management roles and responsibilities across the organization.
- How to get moving:
- Audit both first and second lines of defense to ensure alignment with strategic goals.
- Identify strategic and enterprise-level risks and ensure they are adequately managed.
- Use insights to recommend improvements in risk management processes.
5. Review the Strategic Planning Process
- What stakeholders need: Assurance that strategic planning is effective and aligned with organizational goals.
- How to get moving:
- Ensure the organization has a clearly defined strategy and process.
- Understand how the strategy is developed, approved, and communicated.
- Recommend strategic flexibility and performance indicators to enhance plan effectiveness.
6. Adopt Analytics
- What stakeholders need: Insight and foresight through data analysis.
- How to get moving:
- Assess current analytics maturity and set achievable goals.
- Choose early projects that align with stakeholder concerns and offer high value.
- Use analytics to identify risks, improve audit efficiency, and support decision-making.
- Invest in data wranglers and other roles that can combine and manipulate data.
7. Contemporize Internal Audit Reporting
- What stakeholders need: Clear, concise, and dynamic reporting that reflects current risk landscapes.
- How to get moving:
- Use visual tools like heat maps and dashboards to convey insights effectively.
- Focus on key findings and recommendations in the forefront of reports.
- Move to dynamic or real-time reporting to stay relevant and forward-looking.
8. Enhance Internal Audit's Skills and Capabilities
- What stakeholders need: IA must be equipped to provide assurance and advice on emerging risks and technologies.
- How to get moving:
- Continuously assess and update required skills based on organizational strategy and risk environment.
- Consider alternative resourcing models (e.g., guest auditors, cosourcing).
- Diversify hiring practices to attract and retain skilled professionals, especially in areas like data analytics and cyber risk.
Key Information
- Current Impact: Only 28% of CAEs believe IA has strong impact and influence.
- Future Expectations: Two-thirds of CAEs expect IA to have a stronger impact in the coming years.
- Critical Areas for Impact: Cyber risk, strategic planning, analytics, and risk management are key areas where IA can increase its influence.
- Analytics Maturity Levels: From initial (no or limited capabilities) to leading (continuous improvement methodologies), IA should aim for higher maturity.
- Reporting Trends: Static reports will decrease in use, with a shift toward dynamic and visual formats.
Conclusion
To increase its impact and influence, Internal Audit must evolve its brand, expand its advisory role, adopt analytics, and modernize reporting. These steps, when implemented with commitment and focus, can significantly enhance IA's value and relevance in an increasingly complex and risk-driven business environment.
试读结束,高清完整版pdf/doc/ppt,请点下载