Supporting the Organization's Risk Management Practices
Supporting the organization's risk management practices covers how internal audit adds value to enterprise risk management (ERM) while preserving its independence and objectivity. Under the IIA's Global Internal Audit Standards and the Three Lines Model, management, as the first and second lines, o… Supporting the organization's risk management practices covers how internal audit adds value to enterprise risk management (ERM) while preserving its independence and objectivity. Under the IIA's Global Internal Audit Standards and the Three Lines Model, management, as the first and second lines, owns and manages risk. The board oversees risk, and internal audit, as the third line, provides independent assurance and advice on whether governance, risk management, and control processes work effectively. The IIA position paper on internal audit's role in ERM sorts activities into three groups. Core assurance roles include: - Giving assurance on risk management processes - Confirming that risks are correctly evaluated - Evaluating risk management processes - Assessing how key risks are reported - Reviewing how key risks are managed Legitimate consulting roles, permitted with safeguards, include: - Facilitating risk identification and evaluation - Coaching management on responding to risks - Coordinating ERM activities - Consolidating risk reporting - Maintaining and developing the ERM framework - Championing the establishment of ERM - Developing a risk management strategy for board approval Roles internal audit should not undertake include setting the risk appetite, imposing risk management processes, managing assurances on risks, making risk response decisions, implementing responses for management, and being accountable for risk management. When internal audit takes on consulting roles, the chief audit executive must apply safeguards. Management must remain responsible for risk decisions. The board should approve the roles, and the internal audit charter should document them. Any impairments to independence or objectivity must be disclosed. Internal audit should not later give assurance on work it helped design. In practice, internal audit supports risk management through several activities: - Using risk-based audit planning that draws on the organization's risk assessments - Assessing the maturity of the risk culture - Evaluating whether frameworks such as COSO ERM or ISO 31000 are applied effectively - Testing whether risk responses keep residual risk within the approved appetite - Communicating significant risk exposures to senior management and the board If management accepts a level of risk the chief audit executive believes is unacceptable, the CAE must discuss it with senior management. If the matter is not resolved, the CAE escalates it to the board. For the exam, the key point is the balance: internal audit strengthens risk management through assurance and advice, but never assumes management's ownership of risk.
Supporting the Organization's Risk Management Practices (CIA Part 3 - Internal Audit Operations)
Introduction
Supporting the organization's risk management practices is a core theme in the Certified Internal Auditor (CIA) Part 3 syllabus. It covers how the internal audit activity (IAA) helps management and the board identify, assess, respond to, and monitor risk, and how it does so without compromising its independence and objectivity. Under the IIA's Global Internal Audit Standards (2024) and the earlier International Professional Practices Framework (IPPF), internal audit has a clear duty to evaluate risk management processes and help improve them. Management, however, keeps ownership of risk.
Why It Is Important
1. Value creation and protection: Organizations exist to create value, and every objective carries uncertainty. Effective risk management increases the chance that objectives are achieved. Internal audit's support strengthens this capability.
2. Board and senior management assurance: Boards are responsible for overseeing risk. They rely on internal audit for independent, objective assurance that key risks are being managed within the organization's risk appetite.
3. Regulatory and stakeholder expectations: Regulators, investors, and rating agencies increasingly expect mature enterprise risk management (ERM). Internal audit's involvement makes ERM more credible.
4. Risk-based auditing: The audit plan itself must be risk-based. Understanding and supporting the organization's risk management practices directly shapes where audit resources are deployed.
5. Protecting independence: Getting this wrong carries a real danger. If internal audit drifts into owning risk decisions, its objectivity is impaired and the board loses an independent source of assurance.
What It Is
Risk management is a process to identify, assess, manage, and control potential events or situations, to provide reasonable assurance regarding the achievement of the organization's objectives. Common frameworks include:
- COSO ERM (2017) - Enterprise Risk Management: Integrating with Strategy and Performance. It has five components: Governance and Culture; Strategy and Objective-Setting; Performance; Review and Revision; and Information, Communication, and Reporting. These are supported by 20 principles.
- ISO 31000:2018. It consists of principles, a framework (leadership and commitment, integration, design, implementation, evaluation, improvement), and a process (scope/context/criteria, risk assessment, risk treatment, monitoring and review, communication and consultation, recording and reporting).
- The IIA's Three Lines Model (2020). It defines roles:
- the governing body (accountability and oversight);
- management, covering first-line roles (providing products and services, owning and managing risk) and second-line roles (expertise, support, monitoring, and challenge on risk matters, such as risk management and compliance functions);
- internal audit as the third line (independent and objective assurance and advice).
Key concepts:
- Risk appetite: the broad amount of risk an organization is willing to accept in pursuit of value.
- Risk tolerance: the acceptable variation in performance around specific objectives.
- Inherent risk: risk before management's actions.
- Residual risk: risk remaining after management's responses.
- Risk responses: avoid, reduce (mitigate), share (transfer), and accept. Some frameworks add pursue or exploit.
- Risk owner: the person or entity with accountability and authority to manage a risk. This is always management, never internal audit.
How It Works: Internal Audit's Role
1. Evaluating effectiveness of risk management. Internal audit must evaluate the effectiveness of risk management processes and contribute to their improvement. To conclude that the processes are effective, the internal auditor assesses whether:
- organizational objectives support and align with the mission;
- significant risks are identified and assessed;
- appropriate risk responses are selected that align risks with the risk appetite;
- relevant risk information is captured and communicated in a timely manner across the organization, so that staff, management, and the board can carry out their responsibilities.
2. Specific risk areas. Internal audit evaluates risk exposures relating to governance, operations, and information systems. These include:
- achievement of strategic objectives;
- reliability and integrity of financial and operational information;
- effectiveness and efficiency of operations and programs;
- safeguarding of assets;
- compliance with laws, regulations, policies, procedures, and contracts.
Internal audit must also evaluate the potential for fraud and how the organization manages fraud risk.
3. Consulting engagements. During consulting work, auditors address risk consistent with the engagement's objectives and stay alert to other significant risks. Knowledge gained can be used in evaluating risk management. When assisting management in establishing or improving risk management, internal auditors must refrain from assuming management responsibility by actually managing risks.
4. The IIA position on internal audit's role in ERM (the ERM fan). This is heavily tested. The IIA position paper groups activities into three categories:
(a) Core internal audit roles (assurance):
- giving assurance on risk management processes;
- giving assurance that risks are correctly evaluated;
- evaluating risk management processes;
- evaluating the reporting of key risks;
- reviewing the management of key risks.
(b) Legitimate roles with safeguards (consulting):
- facilitating identification and evaluation of risks;
- coaching management in responding to risks;
- coordinating ERM activities;
- consolidated reporting on risks;
- maintaining and developing the ERM framework;
- championing establishment of ERM;
- developing a risk management strategy for board approval.
Required safeguards include:
- management remains responsible for risk management;
- the role is documented in the internal audit charter and approved by the board;
- internal audit does not manage risks on management's behalf;
- internal audit provides advice, challenge, and support, but does not make management decisions;
- internal audit cannot also give objective assurance on any part of the ERM framework it is responsible for. Such assurance should come from other suitably qualified parties;
- any work beyond assurance is recognized as consulting, and the IIA consulting standards apply.
(c) Roles internal audit should NOT undertake:
- setting the risk appetite;
- imposing risk management processes;
- management assurance on risks;
- taking decisions on risk responses;
- implementing risk responses on management's behalf;
- accountability for risk management.
5. Maturity-dependent approach.
- Mature risk management (formal ERM, risk registers, embedded culture): internal audit relies on management's risk assessment for audit planning and focuses on assurance.
- Immature risk management: internal audit may play a larger consulting role, such as facilitating workshops or championing ERM. It may also use its own risk assessment for planning, while recommending improvements and safeguarding independence.
- No risk management process: the chief audit executive (CAE) should bring this to senior management's and the board's attention, recommend establishing one, and perform its own risk assessment to build the audit plan.
6. Practical activities.
- Control self-assessment (CSA) and risk workshops: internal audit facilitates while management identifies and owns risks.
- Risk-based audit planning: the audit universe is ranked by risk, the plan is updated at least annually, and it is aligned with organizational strategy and input from senior management and the board.
- Coordination and reliance: internal audit works with second-line functions (risk, compliance, information security) and external assurance providers to reduce duplication. Combined assurance and assurance maps help here.
- Reporting: the CAE periodically reports significant risk exposures and control issues, including fraud risks and governance issues, to senior management and the board.
- Risk acceptance: if the CAE concludes management has accepted a level of risk that may be unacceptable, the CAE must discuss it with senior management. If unresolved, the CAE must communicate it to the board. The CAE does not resolve the risk personally.
- Emerging risks: internal audit can add value by highlighting emerging risks such as cyber, ESG/climate, AI, and geopolitical risks, and by testing whether the risk framework captures them.
7. Global Internal Audit Standards (2024) touchpoints.
- Domain III (Governing the Internal Audit Function) and Domain IV (Managing the Internal Audit Function): Principle 9 (Plan Strategically) and Standard 9.4 (Internal Audit Plan) require a risk-based plan based on a documented assessment of the organization's strategies, objectives, and risks.
- Domain V (Performing Internal Audit Services): risk assessment at the engagement level.
- Domain II (Ethics and Professionalism): Principle 2, Maintain Objectivity, together with Standard 7.1 (Organizational Independence), deals with impairments when internal audit takes on risk management responsibilities.
Exam Tips: Answering Questions on Supporting the Organization's Risk Management Practices
1. Remember who owns risk. Management owns and manages risk, and the board oversees it. Reject any answer where internal audit sets risk appetite, decides risk responses, implements controls, or is accountable for risk management.
2. Apply the ERM fan quickly. Classify every option as core, legitimate with safeguards, or should not undertake. Questions that ask what is most appropriate usually point to a core assurance role. Questions about an immature organization often accept a facilitating or coordinating role with safeguards.
3. Look for safeguards. If internal audit takes a consulting role in ERM, the correct answer often mentions board approval, documentation in the charter, management retaining responsibility, or treating the work as a consulting engagement.
4. Watch for independence traps. If internal audit designed or runs part of the ERM framework, it cannot objectively provide assurance on that part. The best answer typically has another qualified party provide that assurance, or discloses the impairment.
5. Know the four-part effectiveness test. The four parts are objectives aligned with mission, significant risks identified and assessed, responses aligned with appetite, and risk information communicated. Questions may ask which is NOT a criterion, or which evidence best supports a conclusion.
6. Match the approach to maturity.
- No ERM: recommend establishing one, inform the board, and do your own risk assessment.
- Mature ERM: rely on management's assessment, after validating it.
7. Follow the risk acceptance escalation sequence. The order is: discuss with senior management first, then communicate to the board if unresolved. The CAE never overrides management or fixes the problem personally.
8. Use the Three Lines Model terminology. Second line equals expertise, monitoring, and challenge (such as the risk management function). Third line equals independent assurance. Do not confuse the risk management function with internal audit.
9. Separate appetite from tolerance. Appetite is broad and entity-level, set by management with board oversight. Tolerance is specific variation around objectives.
10. Identify the best answer, not just a correct one. CIA questions often contain several plausible options. Prefer answers that:
- are risk-based;
- preserve independence;
- add value at the strategic level;
- involve the board where appropriate.
11. Watch for keywords. Words like 'facilitate', 'coach', 'assist', and 'evaluate' usually indicate acceptable roles. Words like 'decide', 'set', 'own', 'implement', 'approve risk responses', and 'accountable' usually signal wrong answers.
12. Link to audit planning. Questions about building the annual plan should prompt you to think risk assessment, alignment with strategy, input from senior management and the board, and periodic updating as risks change.
13. Know the response categories. Be able to classify examples:
- buying insurance or outsourcing: share/transfer;
- exiting a market: avoid;
- adding controls: reduce;
- doing nothing within appetite: accept.
14. Consider fraud. Internal audit evaluates the potential for fraud and how the organization manages fraud risk. However, detection and prevention remain management's responsibility.
Quick Example
Question: A newly formed company has no formal risk management process. The board asks the CAE to help. Which action is most appropriate?
Analysis: Internal audit may champion and facilitate ERM, but only with safeguards. Because there is no process to rely on, it should also perform its own risk assessment for planning.
Best answer: Recommend that management establish a risk management process, and offer to facilitate it as a documented, board-approved consulting role, while management retains ownership.
Wrong answers: The CAE sets the risk appetite, approves risk responses, or becomes the chief risk officer while continuing to give assurance.
Summary
Internal audit supports risk management in three ways: by providing independent assurance on its effectiveness, by offering consulting advice that improves it, and by using it as the foundation of risk-based audit planning. The guiding principle for both the job and the exam is that internal audit evaluates, advises, and facilitates, while management owns, decides, and implements. Master the ERM fan, the Three Lines Model, the four-part effectiveness test, and the escalation path for risk acceptance, and you will answer most questions in this topic correctly.
Unlock Premium Access
Certified Internal Auditor Part 3
- Access to ALL Certifications: Study for any certification on our platform with one subscription
- 2946 Superior-grade Certified Internal Auditor Part 3 practice questions
- Unlimited practice tests across all certifications
- Detailed explanations for every question
- CIA Part 3: 5 full exams plus all other certification exams
- 100% Satisfaction Guaranteed: Full refund if unsatisfied
- Risk-Free: 7-day free trial with all premium features!