Risk Based Auditing offers a method of audit planning that maximises the assurance to the business that the risk management process is operating and key risks are covered. The implementation of Risk Based Auditing needs planning, revisions to methodology and work in analysing and mapping risks. Our experience in these areas means we can give practical advice and assist in all stages of the process. The use of Magique and Galileo software tools supports implementation of this approach.
Risk based auditing serves to align audit activity with board expectations and focuses attention on those elements of process and decision making that are most important in achieving corporate objectives.
Where potentially grave risks are kept in check by controls that reduce the impact and likelihood of occurrence, audit’s task is to give assurance about the effectiveness of those controls. Our approach maximises the effectiveness of the audit work to report on the highest risk areas and those controls on which the most reliance is placed.
Internal audit has an added role in the risk based audit environment, to review and report on the risk management process itself.
Experience shows that companies mature in the way they manage risk and control their businesses. Audit activity is conditioned by the progress that has been made and the audit techniques can and should evolve with the development of risk management.
We can advise on Risk Based Auditing Methodologies, assist in analysing risk registers to derive the key areas to audit and create the audit plan to optimise the risk and control coverage. In addition we can conduct audits of the risk management process and advise on techniques.
Whether you choose a fully outsourced service or an in-house service with external support, Horwath is here to help. Resourcing needs for an internal audit department are subject to peaks and troughs and certain assignments need specialist skills. Our approach is to coordinate our expertise and resources with those required to meet the internal audit programme. We aim to establish and maintain a true partnership with our clients, in order to achieve the best result in terms of quality and return on investment.
We assist an in house internal audit function where typically there are issues with:
- getting the right balance of numbers (two is too many, one too few);
- getting the breadth of skills in one or two people;
- motivating staff who may be performing repetitive tasks and seeing the same businesses all the time;
- easing the burden for Chairman and Audit Committee to manage the function;
- finding staff that are willing to travel.
In many small to medium size organisations the flexibility of external resources, along with the ability to resource more specific skills and locations, provides significant benefits together with the advantage of skills transfer to internal, dedicated staff.
Horwath’s team of internal audit and risk management specialists have the necessary skills and experience, as well as access to the latest technical innovations and trends, to provide a fully outsourced or joint sourced internal audit function.
IT Audit Services
Since Information Technology (IT) automates an increasing number of business processes and supports information for critical decision making, managing technology risk is vital. Horwath Risk Consulting offers information risk assessment; security, privacy, and business continuity; assurance; and IT compliance services.
Information Technology Reviews - Advances in information technology (IT) now means that technologies can provide an organisation with substantial benefits including trading opportunities and a competitive edge against its competitors, and cost reduction through straight line processing with little manual intervention.
However, increased complexity, speed, interconnectivity and globalisation mean that IT can involve huge costs and enormous risks. The growing dependence of most organisations on their IT, coupled with the risks, benefits and opportunities IT carries with it have provided some major challenges to the Board and senior management.
IT Governance – we assist clients in assessing the adequacy of the IT governance structure by ensuring there are adequate controls to mitigate IT risks.
IT Project Advisory – we assist organisations implement appropriate project governance structure, monitoring and control processes to reduce the risk of project failure or increase the projects likelihood of success.
IT and Systems Assurance and Controls – Our experience across a wide range of industries have helped many clients to risk assess their IT controls and make practical recommendations to their control concerns.
Information Security and Data Management – we assist clients implement security controls to mitigate key IT risks and safeguard the organisation’s assets, sensitive information or critical data.
Data interrogation services
Data interrogation is a powerful technique to analyse large volumes of transactions and identify anomalies, trends and invalid items. Horwath has extensive experience of using data interrogation tools to supplement the work of auditors. Examples where interrogations are of help include:
- Investigations into fraud, VAT and tax enquiries,
- Audit planning, to stratify audit populations, extract performance statistics and create new information,
- Audit reviews of duplicate payments, payroll and many other areas,
- Reperformance of programmed controls, accounting data generation or reporting routines that cannot be proved by conventional means,
- Integrity checks on files during transfers of data to new systems,
- Technical analysis of IT access logs, telephone records etc.
Our expert staff can carry out one-off interrogations for you or set up enquiries that you can re-run many times to support recurring audits.
Specialist reviews and health checks
Our internal audit methodology is tailored to meet our client’s needs and executed in the most effective manner given the nature of the audit assignment identified during the risk assessment process. A team is brought together at the start of the assignment which reflects the scope and objectives of the work to be performed and includes specialists (IT, financial, operational, investigative etc), an internal audit manager and the required support staff.
Back to Risk Consulting
Back to Services and Solutions
Contact
Horwath Risk Consulting S A (Pty) Ltd
Derek Cellarius
Tel: +27 11 217 8000
Fax: +27 11 217 8001