Risk Management in ILRI John CM Mwangi Associate Director CGIAR Internal Auditing Unit ILRI APM 2006 INTERNAL AUDITING UNIT
Official definition of Internal Audit from the IIA (Institute of Internal Auditors) Internal auditing is an independent, objective assurance and consulting activity designed to add value and improve an organization's operations. It helps an organization accomplish its objectives by bringing a systematic, disciplined approach to evaluate and improve the effectiveness of risk management , control, and governance processes. IAU
The CGIAR Internal Auditing Unit IAU Provides audit and advisory services to Future Harvest Centers (full or joint) Disseminates learning and good practices Acts as catalyst within the CGIAR System on control, risk management and governance issues Develops professional internal audit across the Future Harvest Centers
IAU The CGIAR IAU Organization DIRECTOR (IRRI, Los Banos ) SR. INT. AUDITOR (IS auditor) (IRRI, Los Banos ) INT. AUDITOR (IRRI, Los Banos) ASSOCIATE DIRECTOR (Africa Region) (ILRI, Nairobi) ASSOCIATE DIRECTOR (Americas Region) (CIMMYT, Mexico) INT AUDITOR (Asia Region ) (ICRISAT, Hyderabad) ADMIN ASST (IRRI, Los Banos)
IAU What is risk management ? Definition of Risks and Opportunities An occurrence that will have an Adverse / Advantageous impact on the achievements of the organizations objectives, resulting from inadequate or failed systems or processes, mistakes or external events
PURPOSE – Why do we exist ? and what factors affect the achievement of the Centre’s vision and mission IAU RESEARCH STRATEGY AND PROJECT PORTFOLIO PEOPLE PHYSICAL INFRASTRUCTURE TECHNOLOGY INTELLECTUAL AND GERMPLASM ASSETS FINANCE INTERNAL PROCESSES EXTERNAL ENVIRONMENT
IDENTIFY Categories of opportunities and risks facing Canters IAU OPERATIONAL EFFECTIVENESS FINANCIAL INTEGRITY AND COMPLIANCE LEGAL COMPLIANCE EFFICIENCY SAFETY AND SECURITY
ANALYSE & PRIORITISE : Assess impact/likelihood and isolate major risks IAU IMPACT LIKELIHOOD High Medium Low High Medium Low
Risk analysis: Risk Profile format IAU Impact MEDIUM HIGH LOW Likelihood LOW MEDIUM HIGH
End product of risk analysis: The risk Profile IAU Some Examples..............
Center-wide risk analysis example: Project implementation risks IAU Likelihood Impact HIGH MEDIUM LOW LOW MEDIUM HIGH PROJECT RELEVANCE PROJECT QUALITY FAILURE DONOR AGREEMENT NON-COMPLIANCE RESEARCH DATA LOSS PRODUCT LIABILITY PROJECT TIME/ COST OVERRUN PROJECT EFFORTS NOT ALIGNED WITH STRATEGY SCIENTIFIC FRAUD INADEQUATE RESULTS DISSEMINATION FAIL TO GET PROPER IP LICENSES/AGR – LITIGATION
Matrix analysis example: Financial risks IAU Likelihood Impact HIGH MEDIUM LOW LOW MEDIUM HIGH ERRONEOUS PAYMENTS INTERNAL EMBEZZLEMENT * INTERNET BANKING * CHEQUE/WIRE MISUSE OF CENTER ASSETS ADMINISTRATIVE INEFFICIENCY FINANCIAL CONFLICTS OF INTEREST WITHHOLDING TAX LIABILITIES TERRORIST FINANCING OVER-PRICED GOODS&SERV