A practical guide
The document is a practical guide titled “Auditing Risk Culture” developed by the Institute of Internal Auditors – Australia in collaboration with experts from Macquarie University, Kiel Advisory Group, and QSuper. The guide aims to assist internal auditors, board audit committees, senior managers, and other assurance providers in auditing risk culture within organizations. It emphasizes the importance of measuring risk culture due to its impact on effective risk management.
The guide outlines a ten-step model for auditing risk culture, providing a comprehensive approach rather than a checklist, recognizing the uniqueness of each organization’s stakeholders, context, and audit capability. It acknowledges that auditing risk culture is a relatively new concept for many organizations, and different organizations may be at varying stages in their risk culture audit “journey.”
Various methodologies for a risk culture audit program are presented, ranging from surface-level assessments to more comprehensive audits. The guide includes a Toolbox of risk culture audit techniques for internal audit practitioners to utilize. It also highlights the importance of communication in delivering audit results, offering different tools such as holding up the mirror workshops, unrated reports, internal audit opinion papers, and risk culture dashboards.
Additionally, the document provides further resources for obtaining background information on auditing culture and behavior, including practice guides from The Institute of Internal Auditors. It defines key terms related to internal auditing, such as assurance services, audit committee, chief audit executive, compliance, control environment, independence, risk appetite, risk culture, and risk management.
Overall, the guide aims to offer a practical, evidence-based approach to auditing risk culture, emphasizing the need for organizations to assess their risk culture and address any underlying issues that may impact their operations. It is not mandatory but serves as a valuable resource for organizations looking to enhance their risk management practices through the evaluation of their risk culture.
Views: 12


















































