SlideShare ist ein Scribd-Unternehmen logo
1 von 14
RISK FRAMEWORK
Vincent Onwuka
WHAT?
◦ Internal Auditing is an Independent, objective assurance and advisory activity
designed to add value and improve an organization’s operations. It helps and
organization accomplish its objectives by bringing a systematic, disciplined
approach to evaluate and improve the effectiveness of risk management,
internal controls and governance processes.
◦ {The Institute of Internal Auditors, USA}
◦ The definition of I/A provides comprehensive guidelines for the framework of internal audit. It should always be kept in mind
while I/A work is being carried out.
WHY?
◦ The Main Objectives of I/A are:
◦ To provide assurance on the adequacy, efficiency and effectiveness of the whole control environment,
◦ Advise at an early stage in the implementation of any system developments, amendments to processes, making recommendations in
the formation of policies, procedures and controls and
◦ Noting deviations from organizational policies, procedures and controls and recommending actions to mitigate the risks arising out of
such deviations.
◦ Further I/A provides:
◦ Assurance that the organizations values are preserved, and
◦ That rules, laws and regulations are complied with in their letter and spirit
◦ To ensure that financial statements and other information are accurate and reliable and
◦ That human, financial and other resources are managed efficiently and effectively
◦ Wider anti-fraud and anti-corruption framework
◦ Both feedback and feed forward controls
TYPES
◦ Following types of audits make the framework of I/A:
◦ Compliance Audit: To ensure compliance with rules, regulations and laws applicable to drugstoc.
◦ Operational Audit: To ensure efficient and effective conduct of operations of drugstoc
◦ Information System Audit: To ensure proper functioning of the information system throughout the life of business
activities
◦ Performance Audit: To ensure the efficient use of resources to obtain the objectives of drugstoc
◦ Environmental Audits: To ensure compliance with the environmental laws and regulations.
◦ Special Assignments: relate to investigations on fraud and corruption, or any other special service.
THE STANDARDS
◦ Internal auditors carryout their work in accordance with the given set of rules, guidelines, regulations and standards. These standards
are provided by the Institute of Internal Auditors, are known as, International Standards for the Professional Practice of Internal Auditing
(the standards). The standards provide guidance on assurance and advisory activities of an internal auditor.
◦ The application of these standards is mandatory for internal auditors during their work.
◦ Following are the types of the standards:
◦ Attribute standards: pertain to Drugstoc and team/staff performing the audit work
◦ Performance Standards: are about the nature of internal auditing and provide quality criteria for the performance of the work.
◦ Implementation Standards: provide guidance for each attribute or performance standard to be applicable to assurance (A) or Advisory
(A) activity.
AUTHORITY
◦ Internal audit is fully authorized to:
◦ Have complete and unrestricted access to records, personnel, and physical properties/assets relevant to the performance of I/A
engagement.
◦ Delegate duties, allocate resources, select team, determine scope of work, budget time & cost and select required
techniques/procedures to accomplish objectives.
◦ Obtain necessary assistance of personnel in auditee departments and other specialized services within or outside the
organization.
SCOPE
◦ The scope of the internal Auditing encompasses, but not limited to, the examination and evaluation of the adequacy and
effectiveness of the organizations governance, risk management, and internal process as well as the quality of performance in
carrying out assigned responsibilities to achieve the organization’s stated goals and objectives.
◦ This scope of I/A generally includes the following:
Evaluating the reliability and integrity of information and the means used to identify, measure, classify, and report such
information.
Evaluating the systems established to ensure compliance with those policies, plans, procedures, laws and regulations which
could have a significant impact on the organization
Evaluating the means of safeguarding assets and, as appropriate, verifying the existence of such assets
Evaluating the effectiveness and efficiency with which resources are employed.
ANNUAL AUDIT PLAN
◦ In cooperation with executive management, the following is performed:
Conduct a preliminary risk assessment (with Risk team) by utilizing interview or best strategy
Gather Top management input on the assessment.
Prepare a Draft Risk Based Annual Audit Plan
Obtain the formal approval of the Audit Committee or the Board.
The plan is subject to reviews during the course of audit work to ensure that the focus continues to be on the higher risk areas. In
addition, the need to conduct special assignments requested from the Audit Committee and senior management may also require
the deferral of planned audit work.
PLANNING
◦ Evaluating operations or programs to ascertain whether results are consistent with established objectives and goals and
whether the operations or programs are being carried out as planned.
◦ Monitoring and evaluating governance processes
◦ Monitoring and evaluating the effectiveness of the organization’s risk management processes
◦ Evaluating the quality of performance of external auditors and the degree of coordination required with internal audit work
◦ Performing consulting and advisory related to governance, risk management and control as appropriate for drugstoc
◦ Reporting periodically on the internal audit activity’s purpose, authority, responsibility and performance relative to its plan
◦ Reporting significant risk exposures and control issues, including fraud risks, governance issues and other matters needed or
requested.
PERFORM AUDIT FIELDWORK
1. Carry out fieldwork as indicated in the annual audit plan
2. Obtain cooperation from management and staff as necessary to identify, obtain documentation and conduct interviews, etc.
3. Conduct fieldwork with minimal disruption to operations of drugstoc.
REPORT RESULTS
◦ Share important and sensitive findings with responsible managers upon verification
◦ Make notes of comments/responses of the management/personnel on all observations
discussed with them.
◦ Prepare a first draft of the final report and discuss with responsible managers after the audit
FINAL REPORT
1. Issue final report to the management.
2. Prepare checklist of issues to be discussed with the management in the next period audit
3. Write down comments of management on the audit report
O b j e c t i v e s & G o a l s
DrugStoc E-Hub
Limited
13
 This plan is designed to cover all areas of Drugstoc business operations and to significantly reduce to acceptable level the exposure of the
organization to all risks that are characterized with the sector. These risks include operational risks, credit risks, reputational risk, IT risk,
legal/compliance risk
 Risk-Based Internal Audit is essential to evaluate risk management practices, internal control systems and compliance with both corporate and
regulatory policies with the aim of bringing to the attention of management and areas of vulnerability and facilitating improvements where
necessary.
 Our Focus
Operational Risk
► Internal and external fraud.
► Employment practices and workplace
safety
► Errors.
► Income/ expense leakages.
► Loss/damage of physical asset.
► Incomplete documentation.
► Non-adherence to policies and
procedures.
Information Technology
► Back up/ offsite storage.
► Disaster recovery and contingency.
► Business continuity plan.
► Access restriction.
► IT Strategic plan.
► Mandate/Report/ minutes of IT
steering committee.
► IT equipment- storage facilities &
condition.
► Complaints Register review and
Review of support services.
Credit Risk
► Customers’ unwillingness to pay due to
character deficiency.
► Death of a customer.
► Customers not having the capacity to
repay loans.
Liquidity Risk
► Negative impact of the creation of new
business/product.
► Bad loans
► Loss of revenue
Reputation, Compliance
Risk
► Tax, CIT
► Annual returns
► Non-adherence to laws and regulatory
guides.
► Customers surveys, feedbacks
mechanisms, complaints resolutions
Financial Risk
► Capital Adequacy
► Accounting and Reporting
► Cash management
► Transaction postings/GL proof
14

Weitere ähnliche Inhalte

Was ist angesagt?

04 a iso 9001 2015 checklist
04 a iso 9001 2015 checklist04 a iso 9001 2015 checklist
04 a iso 9001 2015 checklist
Son Pham
 
Handling FDA Inspection - Do's and Dont's
Handling FDA Inspection - Do's and Dont'sHandling FDA Inspection - Do's and Dont's
Handling FDA Inspection - Do's and Dont's
Arun Purohit
 

Was ist angesagt? (20)

Internal audit ppt
Internal audit pptInternal audit ppt
Internal audit ppt
 
Process Audit and ISO
Process Audit and ISOProcess Audit and ISO
Process Audit and ISO
 
Internal Auditor Roles
Internal Auditor RolesInternal Auditor Roles
Internal Auditor Roles
 
Iso 9001 internal audit tips
Iso 9001 internal audit tipsIso 9001 internal audit tips
Iso 9001 internal audit tips
 
Internal audit
Internal auditInternal audit
Internal audit
 
The Internal Audit Framework
The Internal Audit FrameworkThe Internal Audit Framework
The Internal Audit Framework
 
Iso 9001 2015 process audit checklist
Iso 9001 2015 process audit checklistIso 9001 2015 process audit checklist
Iso 9001 2015 process audit checklist
 
04 a iso 9001 2015 checklist
04 a iso 9001 2015 checklist04 a iso 9001 2015 checklist
04 a iso 9001 2015 checklist
 
Internal auditing
Internal auditingInternal auditing
Internal auditing
 
Quality Management System ISO 9001 Interpretation and Internal Audit
Quality Management System ISO 9001 Interpretation and Internal AuditQuality Management System ISO 9001 Interpretation and Internal Audit
Quality Management System ISO 9001 Interpretation and Internal Audit
 
Handling FDA Inspection - Do's and Dont's
Handling FDA Inspection - Do's and Dont'sHandling FDA Inspection - Do's and Dont's
Handling FDA Inspection - Do's and Dont's
 
Documentation ppt mal 2 [repaired]
Documentation ppt mal 2 [repaired]Documentation ppt mal 2 [repaired]
Documentation ppt mal 2 [repaired]
 
Iso 9001:2015 internal auditor Course
Iso 9001:2015  internal auditor Course Iso 9001:2015  internal auditor Course
Iso 9001:2015 internal auditor Course
 
The role of internal audit department
The role of internal audit departmentThe role of internal audit department
The role of internal audit department
 
ISO 19011 Revision
ISO 19011 RevisionISO 19011 Revision
ISO 19011 Revision
 
Improving effectiveness of internal auditing
Improving effectiveness of internal auditingImproving effectiveness of internal auditing
Improving effectiveness of internal auditing
 
Internal auditor 9001 day 1
Internal auditor 9001 day 1Internal auditor 9001 day 1
Internal auditor 9001 day 1
 
Basic internal auditing
Basic internal auditingBasic internal auditing
Basic internal auditing
 
Internal audit report writing
Internal audit report writingInternal audit report writing
Internal audit report writing
 
Audit Report Writing
Audit Report WritingAudit Report Writing
Audit Report Writing
 

Ähnlich wie Audit Framework presentation.pptx

ISO 19001ISO 19001Student’s NameUniversity Name.docx
ISO 19001ISO 19001Student’s NameUniversity Name.docxISO 19001ISO 19001Student’s NameUniversity Name.docx
ISO 19001ISO 19001Student’s NameUniversity Name.docx
priestmanmable
 
Implementing Internal Audit Governance
Implementing Internal Audit GovernanceImplementing Internal Audit Governance
Implementing Internal Audit Governance
Aswin Kumar
 

Ähnlich wie Audit Framework presentation.pptx (20)

Process Level Auditing Presentation
Process Level Auditing   PresentationProcess Level Auditing   Presentation
Process Level Auditing Presentation
 
Auditing Management systems based on ISO19011 By Eng. Karam Malkawi - Jordan
Auditing Management systems based on ISO19011 By Eng. Karam Malkawi - JordanAuditing Management systems based on ISO19011 By Eng. Karam Malkawi - Jordan
Auditing Management systems based on ISO19011 By Eng. Karam Malkawi - Jordan
 
Internal audits role in compliance
Internal audits role in complianceInternal audits role in compliance
Internal audits role in compliance
 
Audit Interview: Commonly Asked Questions & Expert Answers | Academy Tax4wealth
Audit Interview: Commonly Asked Questions & Expert Answers | Academy Tax4wealth Audit Interview: Commonly Asked Questions & Expert Answers | Academy Tax4wealth
Audit Interview: Commonly Asked Questions & Expert Answers | Academy Tax4wealth
 
2019_SOU_Internal_Audit.pptx
2019_SOU_Internal_Audit.pptx2019_SOU_Internal_Audit.pptx
2019_SOU_Internal_Audit.pptx
 
ISO 19001ISO 19001Student’s NameUniversity Name.docx
ISO 19001ISO 19001Student’s NameUniversity Name.docxISO 19001ISO 19001Student’s NameUniversity Name.docx
ISO 19001ISO 19001Student’s NameUniversity Name.docx
 
PART II INTERNAL AUDITING in local government.ppt
PART II  INTERNAL AUDITING in local government.pptPART II  INTERNAL AUDITING in local government.ppt
PART II INTERNAL AUDITING in local government.ppt
 
introduction on auditing
introduction on auditingintroduction on auditing
introduction on auditing
 
Information system control and audit
Information system control and auditInformation system control and audit
Information system control and audit
 
Internal controls
Internal controlsInternal controls
Internal controls
 
CHAPTER-1 Management Audit and Planning procedure.pdf
CHAPTER-1 Management Audit and Planning procedure.pdfCHAPTER-1 Management Audit and Planning procedure.pdf
CHAPTER-1 Management Audit and Planning procedure.pdf
 
Navigating the Realm of Audits: Understanding, Preparation, and Compliance
Navigating the Realm of Audits: Understanding, Preparation, and ComplianceNavigating the Realm of Audits: Understanding, Preparation, and Compliance
Navigating the Realm of Audits: Understanding, Preparation, and Compliance
 
Standards of Internal Audit
Standards of Internal AuditStandards of Internal Audit
Standards of Internal Audit
 
AUDIT - AUDITING STRATEGIES.pptx
AUDIT - AUDITING STRATEGIES.pptxAUDIT - AUDITING STRATEGIES.pptx
AUDIT - AUDITING STRATEGIES.pptx
 
internal audit and its characteristic and features .pptx
internal audit and its characteristic and features .pptxinternal audit and its characteristic and features .pptx
internal audit and its characteristic and features .pptx
 
Frequently asked questions on auditing in dubai
Frequently asked questions on auditing in dubaiFrequently asked questions on auditing in dubai
Frequently asked questions on auditing in dubai
 
Implementing Internal Audit Governance
Implementing Internal Audit GovernanceImplementing Internal Audit Governance
Implementing Internal Audit Governance
 
Quality Audit in pharmaceutical industry
Quality Audit in pharmaceutical industryQuality Audit in pharmaceutical industry
Quality Audit in pharmaceutical industry
 
Audit Process: How to Successfully Plan Audit
Audit Process: How to Successfully Plan Audit Audit Process: How to Successfully Plan Audit
Audit Process: How to Successfully Plan Audit
 
The process of issuing audit report by ca firm
The process of issuing audit report by ca firmThe process of issuing audit report by ca firm
The process of issuing audit report by ca firm
 

Kürzlich hochgeladen

Kürzlich hochgeladen (20)

Top Rated Pune Call Girls Hadapsar ⟟ 6297143586 ⟟ Call Me For Genuine Sex Se...
Top Rated  Pune Call Girls Hadapsar ⟟ 6297143586 ⟟ Call Me For Genuine Sex Se...Top Rated  Pune Call Girls Hadapsar ⟟ 6297143586 ⟟ Call Me For Genuine Sex Se...
Top Rated Pune Call Girls Hadapsar ⟟ 6297143586 ⟟ Call Me For Genuine Sex Se...
 
Call Girls Service Connaught Place @9999965857 Delhi 🫦 No Advance VVIP 🍎 SER...
Call Girls Service Connaught Place @9999965857 Delhi 🫦 No Advance  VVIP 🍎 SER...Call Girls Service Connaught Place @9999965857 Delhi 🫦 No Advance  VVIP 🍎 SER...
Call Girls Service Connaught Place @9999965857 Delhi 🫦 No Advance VVIP 🍎 SER...
 
VIP Russian Call Girls in Indore Ishita 💚😋 9256729539 🚀 Indore Escorts
VIP Russian Call Girls in Indore Ishita 💚😋  9256729539 🚀 Indore EscortsVIP Russian Call Girls in Indore Ishita 💚😋  9256729539 🚀 Indore Escorts
VIP Russian Call Girls in Indore Ishita 💚😋 9256729539 🚀 Indore Escorts
 
Climate change and safety and health at work
Climate change and safety and health at workClimate change and safety and health at work
Climate change and safety and health at work
 
2024 Zoom Reinstein Legacy Asbestos Webinar
2024 Zoom Reinstein Legacy Asbestos Webinar2024 Zoom Reinstein Legacy Asbestos Webinar
2024 Zoom Reinstein Legacy Asbestos Webinar
 
Top Rated Pune Call Girls Wadgaon Sheri ⟟ 6297143586 ⟟ Call Me For Genuine S...
Top Rated  Pune Call Girls Wadgaon Sheri ⟟ 6297143586 ⟟ Call Me For Genuine S...Top Rated  Pune Call Girls Wadgaon Sheri ⟟ 6297143586 ⟟ Call Me For Genuine S...
Top Rated Pune Call Girls Wadgaon Sheri ⟟ 6297143586 ⟟ Call Me For Genuine S...
 
Climate change and occupational safety and health.
Climate change and occupational safety and health.Climate change and occupational safety and health.
Climate change and occupational safety and health.
 
Call Girls Sangamwadi Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Sangamwadi Call Me 7737669865 Budget Friendly No Advance BookingCall Girls Sangamwadi Call Me 7737669865 Budget Friendly No Advance Booking
Call Girls Sangamwadi Call Me 7737669865 Budget Friendly No Advance Booking
 
CBO’s Recent Appeals for New Research on Health-Related Topics
CBO’s Recent Appeals for New Research on Health-Related TopicsCBO’s Recent Appeals for New Research on Health-Related Topics
CBO’s Recent Appeals for New Research on Health-Related Topics
 
Just Call Vip call girls Wardha Escorts ☎️8617370543 Starting From 5K to 25K ...
Just Call Vip call girls Wardha Escorts ☎️8617370543 Starting From 5K to 25K ...Just Call Vip call girls Wardha Escorts ☎️8617370543 Starting From 5K to 25K ...
Just Call Vip call girls Wardha Escorts ☎️8617370543 Starting From 5K to 25K ...
 
The U.S. Budget and Economic Outlook (Presentation)
The U.S. Budget and Economic Outlook (Presentation)The U.S. Budget and Economic Outlook (Presentation)
The U.S. Budget and Economic Outlook (Presentation)
 
Get Premium Balaji Nagar Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...
Get Premium Balaji Nagar Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...Get Premium Balaji Nagar Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...
Get Premium Balaji Nagar Call Girls (8005736733) 24x7 Rate 15999 with A/c Roo...
 
Regional Snapshot Atlanta Aging Trends 2024
Regional Snapshot Atlanta Aging Trends 2024Regional Snapshot Atlanta Aging Trends 2024
Regional Snapshot Atlanta Aging Trends 2024
 
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
(NEHA) Bhosari Call Girls Just Call 7001035870 [ Cash on Delivery ] Pune Escorts
 
Junnar ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
Junnar ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...Junnar ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready For S...
Junnar ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready For S...
 
(NEHA) Call Girls Nagpur Call Now 8250077686 Nagpur Escorts 24x7
(NEHA) Call Girls Nagpur Call Now 8250077686 Nagpur Escorts 24x7(NEHA) Call Girls Nagpur Call Now 8250077686 Nagpur Escorts 24x7
(NEHA) Call Girls Nagpur Call Now 8250077686 Nagpur Escorts 24x7
 
Incident Command System xxxxxxxxxxxxxxxxxxxxxxxxx
Incident Command System xxxxxxxxxxxxxxxxxxxxxxxxxIncident Command System xxxxxxxxxxxxxxxxxxxxxxxxx
Incident Command System xxxxxxxxxxxxxxxxxxxxxxxxx
 
Top Rated Pune Call Girls Bhosari ⟟ 6297143586 ⟟ Call Me For Genuine Sex Ser...
Top Rated  Pune Call Girls Bhosari ⟟ 6297143586 ⟟ Call Me For Genuine Sex Ser...Top Rated  Pune Call Girls Bhosari ⟟ 6297143586 ⟟ Call Me For Genuine Sex Ser...
Top Rated Pune Call Girls Bhosari ⟟ 6297143586 ⟟ Call Me For Genuine Sex Ser...
 
Zechariah Boodey Farmstead Collaborative presentation - Humble Beginnings
Zechariah Boodey Farmstead Collaborative presentation -  Humble BeginningsZechariah Boodey Farmstead Collaborative presentation -  Humble Beginnings
Zechariah Boodey Farmstead Collaborative presentation - Humble Beginnings
 
Postal Ballots-For home voting step by step process 2024.pptx
Postal Ballots-For home voting step by step process 2024.pptxPostal Ballots-For home voting step by step process 2024.pptx
Postal Ballots-For home voting step by step process 2024.pptx
 

Audit Framework presentation.pptx

  • 2. WHAT? ◦ Internal Auditing is an Independent, objective assurance and advisory activity designed to add value and improve an organization’s operations. It helps and organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management, internal controls and governance processes. ◦ {The Institute of Internal Auditors, USA} ◦ The definition of I/A provides comprehensive guidelines for the framework of internal audit. It should always be kept in mind while I/A work is being carried out.
  • 3. WHY? ◦ The Main Objectives of I/A are: ◦ To provide assurance on the adequacy, efficiency and effectiveness of the whole control environment, ◦ Advise at an early stage in the implementation of any system developments, amendments to processes, making recommendations in the formation of policies, procedures and controls and ◦ Noting deviations from organizational policies, procedures and controls and recommending actions to mitigate the risks arising out of such deviations. ◦ Further I/A provides: ◦ Assurance that the organizations values are preserved, and ◦ That rules, laws and regulations are complied with in their letter and spirit ◦ To ensure that financial statements and other information are accurate and reliable and ◦ That human, financial and other resources are managed efficiently and effectively ◦ Wider anti-fraud and anti-corruption framework ◦ Both feedback and feed forward controls
  • 4. TYPES ◦ Following types of audits make the framework of I/A: ◦ Compliance Audit: To ensure compliance with rules, regulations and laws applicable to drugstoc. ◦ Operational Audit: To ensure efficient and effective conduct of operations of drugstoc ◦ Information System Audit: To ensure proper functioning of the information system throughout the life of business activities ◦ Performance Audit: To ensure the efficient use of resources to obtain the objectives of drugstoc ◦ Environmental Audits: To ensure compliance with the environmental laws and regulations. ◦ Special Assignments: relate to investigations on fraud and corruption, or any other special service.
  • 5. THE STANDARDS ◦ Internal auditors carryout their work in accordance with the given set of rules, guidelines, regulations and standards. These standards are provided by the Institute of Internal Auditors, are known as, International Standards for the Professional Practice of Internal Auditing (the standards). The standards provide guidance on assurance and advisory activities of an internal auditor. ◦ The application of these standards is mandatory for internal auditors during their work. ◦ Following are the types of the standards: ◦ Attribute standards: pertain to Drugstoc and team/staff performing the audit work ◦ Performance Standards: are about the nature of internal auditing and provide quality criteria for the performance of the work. ◦ Implementation Standards: provide guidance for each attribute or performance standard to be applicable to assurance (A) or Advisory (A) activity.
  • 6. AUTHORITY ◦ Internal audit is fully authorized to: ◦ Have complete and unrestricted access to records, personnel, and physical properties/assets relevant to the performance of I/A engagement. ◦ Delegate duties, allocate resources, select team, determine scope of work, budget time & cost and select required techniques/procedures to accomplish objectives. ◦ Obtain necessary assistance of personnel in auditee departments and other specialized services within or outside the organization.
  • 7. SCOPE ◦ The scope of the internal Auditing encompasses, but not limited to, the examination and evaluation of the adequacy and effectiveness of the organizations governance, risk management, and internal process as well as the quality of performance in carrying out assigned responsibilities to achieve the organization’s stated goals and objectives. ◦ This scope of I/A generally includes the following: Evaluating the reliability and integrity of information and the means used to identify, measure, classify, and report such information. Evaluating the systems established to ensure compliance with those policies, plans, procedures, laws and regulations which could have a significant impact on the organization Evaluating the means of safeguarding assets and, as appropriate, verifying the existence of such assets Evaluating the effectiveness and efficiency with which resources are employed.
  • 8. ANNUAL AUDIT PLAN ◦ In cooperation with executive management, the following is performed: Conduct a preliminary risk assessment (with Risk team) by utilizing interview or best strategy Gather Top management input on the assessment. Prepare a Draft Risk Based Annual Audit Plan Obtain the formal approval of the Audit Committee or the Board. The plan is subject to reviews during the course of audit work to ensure that the focus continues to be on the higher risk areas. In addition, the need to conduct special assignments requested from the Audit Committee and senior management may also require the deferral of planned audit work.
  • 9. PLANNING ◦ Evaluating operations or programs to ascertain whether results are consistent with established objectives and goals and whether the operations or programs are being carried out as planned. ◦ Monitoring and evaluating governance processes ◦ Monitoring and evaluating the effectiveness of the organization’s risk management processes ◦ Evaluating the quality of performance of external auditors and the degree of coordination required with internal audit work ◦ Performing consulting and advisory related to governance, risk management and control as appropriate for drugstoc ◦ Reporting periodically on the internal audit activity’s purpose, authority, responsibility and performance relative to its plan ◦ Reporting significant risk exposures and control issues, including fraud risks, governance issues and other matters needed or requested.
  • 10. PERFORM AUDIT FIELDWORK 1. Carry out fieldwork as indicated in the annual audit plan 2. Obtain cooperation from management and staff as necessary to identify, obtain documentation and conduct interviews, etc. 3. Conduct fieldwork with minimal disruption to operations of drugstoc.
  • 11. REPORT RESULTS ◦ Share important and sensitive findings with responsible managers upon verification ◦ Make notes of comments/responses of the management/personnel on all observations discussed with them. ◦ Prepare a first draft of the final report and discuss with responsible managers after the audit
  • 12. FINAL REPORT 1. Issue final report to the management. 2. Prepare checklist of issues to be discussed with the management in the next period audit 3. Write down comments of management on the audit report
  • 13. O b j e c t i v e s & G o a l s DrugStoc E-Hub Limited 13  This plan is designed to cover all areas of Drugstoc business operations and to significantly reduce to acceptable level the exposure of the organization to all risks that are characterized with the sector. These risks include operational risks, credit risks, reputational risk, IT risk, legal/compliance risk  Risk-Based Internal Audit is essential to evaluate risk management practices, internal control systems and compliance with both corporate and regulatory policies with the aim of bringing to the attention of management and areas of vulnerability and facilitating improvements where necessary.  Our Focus Operational Risk ► Internal and external fraud. ► Employment practices and workplace safety ► Errors. ► Income/ expense leakages. ► Loss/damage of physical asset. ► Incomplete documentation. ► Non-adherence to policies and procedures. Information Technology ► Back up/ offsite storage. ► Disaster recovery and contingency. ► Business continuity plan. ► Access restriction. ► IT Strategic plan. ► Mandate/Report/ minutes of IT steering committee. ► IT equipment- storage facilities & condition. ► Complaints Register review and Review of support services. Credit Risk ► Customers’ unwillingness to pay due to character deficiency. ► Death of a customer. ► Customers not having the capacity to repay loans. Liquidity Risk ► Negative impact of the creation of new business/product. ► Bad loans ► Loss of revenue Reputation, Compliance Risk ► Tax, CIT ► Annual returns ► Non-adherence to laws and regulatory guides. ► Customers surveys, feedbacks mechanisms, complaints resolutions Financial Risk ► Capital Adequacy ► Accounting and Reporting ► Cash management ► Transaction postings/GL proof
  • 14. 14