MONITORING AND EVALUATION OF THE RISK MANAGEMENT FRAMEWORK
HOW TO MONITOR AND
EVALUATE THE RISK MANAGEMENT
FRAMEWORK
The ongoing relevance and usefulness of a risk management framework is largely informed by the extent to which it is continually improved. It is therefore essential for all organizations to monitor, review and enhance the effectiveness
of their risk management
framework.
By
ensuring that a risk management framework remains fit for purpose and is customized to meet changing
organizational circumstances and new leading
practices, organizations will obtain
significant value for risk management.
This section therefore, describes the importance and process of monitoring
the risk management framework. It covers monitoring and review and continual improvement of risk management
framework.
Monitoring and Reviewing the Framework
Both monitoring
and review of the risk management
framework,
risk
management process and
control are essential facets
to enable
continuous
improvement Monitoring refers to continual checking, supervising, critically observing or determining the status in order to identify change from
the performance level
required or expected.
Review entails determining the suitability,
adequacy and
effectiveness
of
the
risk
management
framework, risk
management process and control. When monitoring and reviewing are combined together, they generally seek to address
the following:
a) Risks are being effectively identified and appropriately analyzed,
b) There is
adequate and appropriate implementation
of risk management strategies
and controls,
c)
There is effective monitoring and review by management
an executives
to detect changes
in risks and controls.
Monitoring and review at the organization level should first be carried out by management. This
should normally be done through periodic
reporting on the way risk management
strategies and controls are being implemented.
The risk management coordinator will play a key role in the organization regarding effective reporting.
The following will help the organization in ensuring monitoring and review of risk management activities:
a) Preparation and
submission of quarterly risk
management implementation
reports
b) Annual review and
updating of the risk register
c) Periodic review
and updating of
the risk management
framework as put forth in the policy
Another key organ in ensuring effective review of the risk management framework
or components is an internal
audit.
Assurance
on the Effectiveness
of Risk Management
(internal audit)
Assurance on the effectiveness of risk management is normally obtained through use of
audits (internal and external audit) and oversight bodies;
Internal audit (IA) plays a significant role in the monitoring and review regarding the effectiveness
of the organization risk management
processes.
This is done through its core functions i.e. giving assurance, evaluating and reviewing.
Role of Internal Audit in Risk Management
- Giving Assurance on;
a) Control
systems
effectiveness
b) Risk
management processes
c) That risks are
correctly evaluated
- Evaluating the followings;
a) Risk
management processes
b) Reporting
of materials risks
- Reviewing the management of material risks
Internal auditor will conduct evaluation/ review or audit of the risk management process, based on its risk-based internal audit plans, prepare and submit report to the Audit Committee
and/or Accounting Officer. The reports (audit recommendations) will form basis for steps to be
taken to improve the risk management processes; For audit procedures and techniques
for the risk management framework and processes refer
to internal audit manual of respective organization.
Continual Improvement
of the Risk Management
Framework
The key objective of continual improvement is to ensure the ongoing relevancy and
effectiveness of risk
management activities within an organization. Hence, to achieve the greatest benefits from continuous improvement, it must encompass all risk management framework elements including
the process, capability, behaviors,
tools and templates and reporting structures, and the practices used to manage actual
risks.
The initiatives that are identified during monitoring and review activities should be taken on board, prioritized and then included within the risk management strategy and plans. They should further be approved and
implemented accordingly.
Inclusion of these initiatives in the strategy will also increase accountability as well as
continuous improvement in
service delivery. By continuously improving
its risk management
framework, a organization
will
obtain
the
following benefits:
NOTE:
Benefits of continual improvement:
i.
Organizational resilience by being more proactive in managing risks as compared to reactive in managing
issues;
ii.
Better governance through regular reporting which strengthens an organisation’s ability to oversee its risks and direct changes in approach;
iii.
Increased accountability through well defined risk management responsibilities against which performance
is measured;
iv.
Being able to leverage leading risk management practice in its risk management approach.
YsubsriYprof_e1979 Gina Sinclair https://wakelet.com/wake/p_4m4X3Jq0cbS020ASwQq
ReplyDeletemusmanace