With so many risk management standards and government regulations out there that require risk assessments, how should internal audit evaluate the effectiveness of your organization’s risk management program? How would you apply any one of these frameworks to an audit? How do you meet the reporting requirements of so many external stakeholders from regulators to investors to customers to rating agencies?
Challenges with using risk management frameworks:
- Many standards to choose from: COSO, ISO 31