Communicating with the Risk Management Function
Communicating with the risk management function means how internal audit shares engagement results, monitoring outcomes, and risk insights with the people responsible for enterprise risk management (ERM), such as a chief risk officer or second-line risk and compliance teams. Under the IIA Three Lin… Communicating with the risk management function means how internal audit shares engagement results, monitoring outcomes, and risk insights with the people responsible for enterprise risk management (ERM), such as a chief risk officer or second-line risk and compliance teams. Under the IIA Three Lines Model, management owns and manages risk (first line), the risk management function supports and oversees it (second line), and internal audit gives independent assurance (third line). Good communication between the second and third lines helps the organization see its risks clearly, avoids duplicated work, and lets reliance be placed on each other's work where appropriate. Key elements include: 1. Coordination and reliance: The chief audit executive should coordinate with other assurance providers, including risk management, to share risk assessments, audit plans, and results. This matches Global Internal Audit Standard 9.5. Internal audit may rely on risk management's work only after evaluating its objectivity, competence, and methodology. 2. Sharing engagement results: Findings about control weaknesses, emerging risks, or poor risk responses should reach risk management so risk registers, risk appetite measures, and key risk indicators can be updated. Communications must be accurate, objective, clear, concise, constructive, complete, and timely. 3. Monitoring progress: Internal audit tracks whether management's action plans are put in place. Sharing the status of open issues with risk management keeps residual risk ratings realistic. 4. Risk acceptance: If the CAE concludes that management has accepted a level of risk above the organization's risk appetite, the CAE must discuss it with senior management. If it is not resolved, the CAE escalates it to the board. Risk management is often involved in judging such tolerance decisions. 5. Independence safeguards: Internal audit may advise on ERM, but it must not take on management responsibilities, such as setting risk appetite or owning risks. Doing so would impair its objectivity. In short, structured and ongoing communication with the risk management function strengthens governance, supports combined assurance, and improves the board's view of organizational risk.
Communicating with the Risk Management Function: A Complete CIA Exam Guide
Introduction
Communicating with the risk management function is a key topic in the CIA exam under Engagement Results and Monitoring. It covers how internal audit shares engagement results, risk observations and assurance conclusions with the people who identify, assess and manage risk across the organization. These people include the Chief Risk Officer (CRO), enterprise risk management (ERM) teams and other second-line functions. Under the IIA's Global Internal Audit Standards (2024) and the Three Lines Model, internal audit (the third line) must coordinate with second-line functions. The goal is to give the board and senior management a full, efficient and consistent view of risk.
Why It Is Important
1. Holistic risk view: The risk management function keeps the organization's risk register and risk appetite framework. Audit findings show whether risks are really controlled as reported. Sharing them helps keep risk profiles accurate.
2. Avoiding duplication and gaps: Coordination lets audit and risk management avoid testing the same areas twice. It also helps make sure no significant risk is left uncovered. The Standards require the CAE to coordinate with other assurance providers to reduce duplication.
3. Supporting risk-based audit planning: Information from risk management feeds the internal audit plan. Audit results in turn update risk assessments. The relationship is a two-way loop.
4. Strengthening governance: The board relies on consistent risk messages. If audit and risk management report conflicting views without reconciling them, governance is weakened.
5. Communicating unaccepted risk: If management accepts a level of risk that may be unacceptable to the organization, the CAE must discuss it with senior management. The risk management function's view of risk appetite is relevant to that discussion. If the matter is still unresolved, the CAE escalates it to the board.
6. Preserving independence: Clear communication protocols help internal audit share information without taking on risk management responsibilities. Owning risk management would impair objectivity.
What It Is
Communicating with the risk management function means the formal and informal sharing of the following:
- Engagement observations, findings and recommendations relevant to risk exposures.
- Assessments of control effectiveness over key risks.
- Emerging risks spotted during engagements.
- Information on residual risk levels and whether they exceed risk appetite.
- The status of management's action plans (monitoring and follow-up results).
- Overall assurance opinions on the effectiveness of governance, risk management and control processes.
It also includes receiving information from risk management, such as:
- Risk assessments and heat maps.
- Key risk indicators (KRIs).
- Loss event data.
- Changes in risk appetite.
Key Concepts and Frameworks
- Three Lines Model: The first line is operational management, which owns and manages risk. The second line is risk management, compliance and similar functions, which provide expertise, monitoring and challenge. The third line is internal audit, which provides independent assurance. The lines must communicate and coordinate, while internal audit keeps its independence.
- Coordination and reliance: The CAE may rely on the work of other assurance providers, including risk management. Before doing so, the CAE evaluates their competence, objectivity and due professional care. Communication is essential to understand the scope and quality of their work.
- Assurance mapping: This is a document showing which assurance providers cover which risks. It is often built jointly with risk management and supports combined assurance.
- Combined assurance: This is a coordinated approach that aligns the lines of assurance to give a unified view to the board.
- Role of internal audit in ERM: The IIA position paper on this topic separates three groups of activities.
- Core roles internal audit should perform: giving assurance on risk management processes and on the correct evaluation of risks.
- Legitimate roles with safeguards: facilitating risk workshops and coaching management.
- Roles to avoid: setting risk appetite, owning risk management processes, making risk response decisions on management's behalf and taking accountability for risk management.
How It Works
1. Planning stage: The CAE consults the CRO and the ERM risk register to prioritize audit engagements. Audit may also share its own risk assessment for alignment.
2. During engagements: Auditors may obtain risk data such as KRIs and loss events from risk management. Significant new risks found during fieldwork may be communicated promptly, especially if they are urgent.
3. Final communications: Engagement reports are distributed to parties who can ensure results get proper consideration. The risk management function is often on the distribution list when findings concern risk exposures.
- The CAE decides who receives results.
- Before sharing outside the organization, the CAE assesses the potential risk to the organization, consults senior management or legal counsel as needed, and controls dissemination.
4. Monitoring and follow-up: The CAE sets up a process to monitor management actions. Follow-up status, including overdue actions and risk acceptance, may be shared with risk management so risk registers show current residual risk.
5. Periodic reporting: The CAE reports to the board and senior management on significant risk exposures, control issues, fraud risks and governance issues. Coordinated reporting with the CRO gives consistent messages.
6. Regular meetings and protocols: Scheduled meetings, shared risk taxonomies, common rating scales and agreed escalation procedures make communication efficient.
Confidentiality and Independence Safeguards
- Share information on a need-to-know basis and follow organizational policies.
- Do not let risk management direct audit scope or conclusions. Internal audit decides independently.
- If internal audit also performs risk management activities, disclose the impairment and keep safeguards in place. Examples include board oversight and having assurance over those activities provided by a third party.
Common Exam Scenarios
- An auditor finds a significant control weakness affecting a key enterprise risk. Best action: Communicate it in the engagement report to appropriate parties, including risk management, so the risk assessment can be updated.
- The CRO asks internal audit to set the organization's risk appetite. Best answer: Decline. Setting risk appetite is a management and board responsibility.
- The CAE wants to cut duplicate testing with the compliance and risk functions. Best answer: Coordinate through assurance mapping and evaluate whether reliance is appropriate.
- Management accepts a risk the CAE believes is unacceptable. Best answer: Discuss with senior management, and escalate to the board if unresolved. Do not simply inform risk management and stop there.
Exam Tips: Answering Questions on Communicating with the Risk Management Function
1. Think Three Lines: Identify which line each party belongs to. Internal audit gives independent assurance. It coordinates with risk management but never takes over its role.
2. Watch for independence traps: Reject answers in which internal audit does any of the following:
- owns risks,
- sets risk appetite,
- makes risk response decisions,
- lets risk management dictate audit conclusions.
3. Prefer coordination over duplication: When a question asks about efficiency or coverage, look for coordination, assurance mapping, combined assurance or evaluated reliance.
4. Reliance requires evaluation: Before relying on risk management's work, the CAE must assess competence, objectivity and due professional care. Answers suggesting automatic reliance are wrong.
5. Escalation path matters: For unacceptable risk acceptance, go to senior management first, then the board. Risk management can be informed, but it is not the final authority.
6. Two-way flow: Remember that risk management inputs feed audit planning and audit results feed risk assessments. Answers showing this mutual flow are usually correct.
7. The CAE controls dissemination: The CAE decides who receives engagement results. Sharing with risk management is appropriate when relevant, under confidentiality protocols.
8. Choose the most complete answer: CIA questions often have several plausible options. Pick the one that best fits the Standards and is most proactive, independent and value-adding.
9. Know the keywords: coordination, reliance, assurance map, combined assurance, residual risk, risk appetite, escalation, objectivity, safeguards.
10. Read the role carefully: Questions may describe the CRO, compliance officer or ERM committee. Identify whether each is a second-line function and whether it is independent of internal audit.
Summary
Communicating with the risk management function makes sure internal audit's insights strengthen enterprise risk management. Audit coverage is coordinated, and the board gets a consistent picture of risk. For the exam, remember three things: coordinate and share, keep independence, and escalate unresolved unacceptable risk to senior management and then the board.
Unlock Premium Access
Certified Internal Auditor Part 3
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2946 Superior-grade Certified Internal Auditor Part 3 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 3: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!