
Internal Audit Assurance: Refining the ERM Framework of a Regulated Institution by Independent Audit
Founder's Case Study
The Enterprise Risk Management (ERM) department serves as a critical internal control mechanism. It enhances decision-making by monitoring regulatory and legal risks, challenging the risk responses of customer-facing departments, and distributing vital risk information across the organization. Ultimately, it embeds a risk-aware culture through continuous staff training and awareness initiatives.
1. Context
I was engaged to conduct an independent review of the ERM department at a financial institution. This newly formed department was established in response to a regulatory mandate highlighting the need for more structured assessments and management of the institution's primary risk exposures.
2. The Challenge
While the Risk Management department had performed reasonably well since its inception two years prior, its operations had not yet undergone independent review. The objective of this audit was to determine whether the department was fulfilling its organizational mandate. Specifically, we evaluated its ability to identify, measure, and communicate entity-level risks to senior management, the Board's Risk Committee, and the wider organization.
3. My Intervention
Framework Audit: Audited the ERM framework against the Committee of Sponsoring Organizations (COSO) standard to evaluate the design, structure, and content of departmental policies and procedures.
Operational Effectiveness Review: Assessed how risk policies, procedures, and key controls were developed, updated, communicated, and utilized. This comprehensive review involved:
Conducting interviews with policy owners and business unit leaders.
Testing formalized approval and review workflows.
Evaluating alignment between operational procedures and the Board-approved Risk Appetite Statement.
Assessing enterprise-wide risk identification, risk assessment, risk mitigation activities and controls.
Evaluating the quality of departmental reporting to the Board's Risk Committee.
4. The Results & Findings
The audit identified several operational deficiencies, including:
Inconsistent execution and maintenance of established risk policies and procedures.
Inadequate second line monitoring and testing, resulting in backlog of reviews of key control activities.
Inadequate risk training to staff of the organization.
5. Recommendations & Roadmap
To mature the ERM program, I delivered a set of actionable recommendations alongside a phased Implementation Roadmap targeting immediate remediation, medium-term process improvements, and long-term governance enhancements. Key recommendations included:
Defining formal approval and review workflows for all organizational policies.
Improving Risk and Control Self-Assessment (RCSA) processes to enable timely self-certification by departments.
Enhancing the Operational Risk Events and Case Handling processes.
6. Founder's Insight
This review highlighted that significant risk exposure rarely stems from the isolated failure of a single key control. Instead, it accumulates through systemic breakdowns in underlying risk processes, which compound residual risk and leave financial institutions vulnerable. Furthermore, repeated control failures serve as an indicator of how an organization truly values its risk and control functions, pointing directly to the areas requiring immediate cultural and operational emphasis.
