SlideShare a Scribd company logo
Governance, risk and compliance or GRC programs are complex – an organization has to use its GRC
program to address the regulatory requirements expected of, among others, the following:
 Enterprise Risk Management
 COSO Internal Controls
 Environmental Compliance (EPA rules)
 Anti Trust
 Anti Money Laundering
 Anti Bribery/Corruption
 Quality Management and Standards such as ISO 9000, 9001
 Process Management such as Six Sigma
 Anti Harassment
 Human Capital
 Whistle-blowing
 HR Processes
The areas listed above are just few of those that come under the purview of a robust GRC program.
 Given the complex nature of regulations around the world today and the
increasing risks of doing business, it is important that the GRC program in an
organization is audited frequently. Most of the lapses in corporate governance
occur due to outdated GRC programs that have not been audited and updated
to reflect the current regulatory environment.
 Internal audits of GRC programs allow management and the board to identify
risks and areas that need strengthening and root out any non-compliance.
 An audit can help evaluate the adequacy of the program’s design and
effectiveness as well as new practices and technologies to be implemented.
 Audits of the GRC program have to be carried out periodically – these should
supplement an ongoing, daily evaluation of the effectiveness of the program,
including monitoring of controls and responses.
1. Define evaluation scope, objectives, and the type of evaluation.
2. Define the level and type of assurance
3. Identify the evaluation team and skills required.
4. Develop evaluation plan.
5. Perform design adequacy evaluation.
6. Perform operational effectiveness evaluation.
7. Communicate evaluation results and ensure follow-up to address issues.
 Before carrying out the audit, the risks need to be understood and assessed. Risk
assessment is important in ensuring that the audit plan, program and specific tests that
need to be carried out are appropriate and adequate. The risk assessment needs to be
carried out while the audit is underway as well.
 Some of the key risk factors in GRC program audits include:
◦ The scope and complexity of the program.
◦ The scope and complexity of the organization.
◦ The current regulatory environment.
◦ Breaking news and developments relevant to corporate governance.
◦ The experience of the GRC program management team.
◦ Implications of Sarbanes Oxley on the business.
◦ The day-to-day involvement and support of the management and board.
◦ The pace of updates and changes to the program’s efforts.
◦ The maturity of the program.
◦ The robustness of the GRC program’s project management processes.
 Plan Your Audit Properly
 Define Your Audit Scope and Objectives
 Conduct Proper Risk Assessment
 Ensure Audit Testing is Carried Out
 Issue a Comprehensive Audit Report
Want to learn more about audit, and best practices for
auditing? ComplianceOnline webinars and seminars are a
great training resource. Check out the following links:
 How to Audit GRC Programs?
 Role of the Audit Committee in Corporate
Governance
 Internal Audit's Role in Enterprise Risk Management
 OCEG Approved GRC (Governance, Risk and
Compliance) Professional Seminar
 Auditing Technology and IT Investment
Management

More Related Content

What's hot

Risk based thinking
Risk based thinkingRisk based thinking
Risk based thinking
Ramasubramanian S
 
Expectation from qms lecture 5
Expectation from qms lecture 5Expectation from qms lecture 5
Expectation from qms lecture 5
Abdul Basit
 
All You Need to Know about the Firm’s Risk Assessment Process
All You Need to Know about the Firm’s Risk Assessment ProcessAll You Need to Know about the Firm’s Risk Assessment Process
All You Need to Know about the Firm’s Risk Assessment Process
International Federation of Accountants
 
Rsm Introduction
Rsm IntroductionRsm Introduction
Rsm Introduction
erry wardhana
 
IAASB Quality Management Webinar Series: Webinar One
IAASB Quality Management Webinar Series: Webinar OneIAASB Quality Management Webinar Series: Webinar One
IAASB Quality Management Webinar Series: Webinar One
International Federation of Accountants
 
Free PMP Sample Q & A
Free PMP Sample Q & AFree PMP Sample Q & A
Free PMP Sample Q & A
OSP International LLC
 
Fundamentals of testing SQA
Fundamentals of testing SQAFundamentals of testing SQA
Fundamentals of testing SQA
nethisip13
 
Free PMP Sample Q & A
Free PMP Sample Q & AFree PMP Sample Q & A
Free PMP Sample Q & A
OSP International LLC
 
IAASB Quality Management Webcast Series: Webcast Three
IAASB Quality Management Webcast Series: Webcast ThreeIAASB Quality Management Webcast Series: Webcast Three
IAASB Quality Management Webcast Series: Webcast Three
International Federation of Accountants
 
Patrick Carroll Consulting Limited
Patrick Carroll Consulting LimitedPatrick Carroll Consulting Limited
Patrick Carroll Consulting Limited
Patrick Carroll
 
Quality Assurance and Technical IA
Quality Assurance and Technical IAQuality Assurance and Technical IA
Quality Assurance and Technical IA
Wayne Poggenpoel
 
Strategy Execution - An Introduction to Project Management
Strategy Execution - An Introduction to Project ManagementStrategy Execution - An Introduction to Project Management
Strategy Execution - An Introduction to Project Management
ESI14
 
Barela Edward GBW REVIEW Spring 2015
Barela Edward GBW REVIEW Spring 2015Barela Edward GBW REVIEW Spring 2015
Barela Edward GBW REVIEW Spring 2015
Edward Barela
 
Free PMP Sample Q & A
Free PMP Sample Q & AFree PMP Sample Q & A
Free PMP Sample Q & A
OSP International LLC
 
8.1 Cost of Quality
8.1 Cost of Quality8.1 Cost of Quality
8.1 Cost of Quality
DavidMcLachlan1
 
software engineering
software engineeringsoftware engineering
software engineering
shreeuva
 
Andrea Rayner
Andrea RaynerAndrea Rayner
Andrea Rayner
Andrea Rayner
 
Soft mgmt
Soft mgmtSoft mgmt
Soft mgmt
Rishav Upreti
 
IC-Services
IC-ServicesIC-Services
IC-Services
jmedica
 
Risk Based Quality Management System Auditing
Risk Based Quality Management System AuditingRisk Based Quality Management System Auditing
Risk Based Quality Management System Auditing
AQSS-USA
 

What's hot (20)

Risk based thinking
Risk based thinkingRisk based thinking
Risk based thinking
 
Expectation from qms lecture 5
Expectation from qms lecture 5Expectation from qms lecture 5
Expectation from qms lecture 5
 
All You Need to Know about the Firm’s Risk Assessment Process
All You Need to Know about the Firm’s Risk Assessment ProcessAll You Need to Know about the Firm’s Risk Assessment Process
All You Need to Know about the Firm’s Risk Assessment Process
 
Rsm Introduction
Rsm IntroductionRsm Introduction
Rsm Introduction
 
IAASB Quality Management Webinar Series: Webinar One
IAASB Quality Management Webinar Series: Webinar OneIAASB Quality Management Webinar Series: Webinar One
IAASB Quality Management Webinar Series: Webinar One
 
Free PMP Sample Q & A
Free PMP Sample Q & AFree PMP Sample Q & A
Free PMP Sample Q & A
 
Fundamentals of testing SQA
Fundamentals of testing SQAFundamentals of testing SQA
Fundamentals of testing SQA
 
Free PMP Sample Q & A
Free PMP Sample Q & AFree PMP Sample Q & A
Free PMP Sample Q & A
 
IAASB Quality Management Webcast Series: Webcast Three
IAASB Quality Management Webcast Series: Webcast ThreeIAASB Quality Management Webcast Series: Webcast Three
IAASB Quality Management Webcast Series: Webcast Three
 
Patrick Carroll Consulting Limited
Patrick Carroll Consulting LimitedPatrick Carroll Consulting Limited
Patrick Carroll Consulting Limited
 
Quality Assurance and Technical IA
Quality Assurance and Technical IAQuality Assurance and Technical IA
Quality Assurance and Technical IA
 
Strategy Execution - An Introduction to Project Management
Strategy Execution - An Introduction to Project ManagementStrategy Execution - An Introduction to Project Management
Strategy Execution - An Introduction to Project Management
 
Barela Edward GBW REVIEW Spring 2015
Barela Edward GBW REVIEW Spring 2015Barela Edward GBW REVIEW Spring 2015
Barela Edward GBW REVIEW Spring 2015
 
Free PMP Sample Q & A
Free PMP Sample Q & AFree PMP Sample Q & A
Free PMP Sample Q & A
 
8.1 Cost of Quality
8.1 Cost of Quality8.1 Cost of Quality
8.1 Cost of Quality
 
software engineering
software engineeringsoftware engineering
software engineering
 
Andrea Rayner
Andrea RaynerAndrea Rayner
Andrea Rayner
 
Soft mgmt
Soft mgmtSoft mgmt
Soft mgmt
 
IC-Services
IC-ServicesIC-Services
IC-Services
 
Risk Based Quality Management System Auditing
Risk Based Quality Management System AuditingRisk Based Quality Management System Auditing
Risk Based Quality Management System Auditing
 

Viewers also liked

Sec what you need to know
Sec what you need to knowSec what you need to know
Sec what you need to know
complianceonline123
 
I 9 compliance- how to avoid errors
I 9 compliance- how to avoid errorsI 9 compliance- how to avoid errors
I 9 compliance- how to avoid errors
complianceonline123
 
Out in the open protecting your privacy in the digital age
Out in the open  protecting your privacy in the digital ageOut in the open  protecting your privacy in the digital age
Out in the open protecting your privacy in the digital age
complianceonline123
 
Reaching Clean Power Plan Goals at No Cost: Securing the Smart Grid’s Potential
Reaching Clean Power Plan Goals at No Cost: Securing the Smart Grid’s PotentialReaching Clean Power Plan Goals at No Cost: Securing the Smart Grid’s Potential
Reaching Clean Power Plan Goals at No Cost: Securing the Smart Grid’s Potential
complianceonline123
 
Export contols basics
Export contols  basicsExport contols  basics
Export contols basics
complianceonline123
 
510K Table of Contents - Medical Device Description
510K Table of Contents - Medical Device Description510K Table of Contents - Medical Device Description
510K Table of Contents - Medical Device Description
complianceonline123
 
Social media risks rules policies procedures
Social media risks rules policies  proceduresSocial media risks rules policies  procedures
Social media risks rules policies procedures
complianceonline123
 
A Step-by-Step Guide for Method Validation
A Step-by-Step Guide for Method ValidationA Step-by-Step Guide for Method Validation
A Step-by-Step Guide for Method Validation
complianceonline123
 
Understanding 21 cfr part 11
Understanding 21 cfr part 11Understanding 21 cfr part 11
Understanding 21 cfr part 11
complianceonline123
 

Viewers also liked (9)

Sec what you need to know
Sec what you need to knowSec what you need to know
Sec what you need to know
 
I 9 compliance- how to avoid errors
I 9 compliance- how to avoid errorsI 9 compliance- how to avoid errors
I 9 compliance- how to avoid errors
 
Out in the open protecting your privacy in the digital age
Out in the open  protecting your privacy in the digital ageOut in the open  protecting your privacy in the digital age
Out in the open protecting your privacy in the digital age
 
Reaching Clean Power Plan Goals at No Cost: Securing the Smart Grid’s Potential
Reaching Clean Power Plan Goals at No Cost: Securing the Smart Grid’s PotentialReaching Clean Power Plan Goals at No Cost: Securing the Smart Grid’s Potential
Reaching Clean Power Plan Goals at No Cost: Securing the Smart Grid’s Potential
 
Export contols basics
Export contols  basicsExport contols  basics
Export contols basics
 
510K Table of Contents - Medical Device Description
510K Table of Contents - Medical Device Description510K Table of Contents - Medical Device Description
510K Table of Contents - Medical Device Description
 
Social media risks rules policies procedures
Social media risks rules policies  proceduresSocial media risks rules policies  procedures
Social media risks rules policies procedures
 
A Step-by-Step Guide for Method Validation
A Step-by-Step Guide for Method ValidationA Step-by-Step Guide for Method Validation
A Step-by-Step Guide for Method Validation
 
Understanding 21 cfr part 11
Understanding 21 cfr part 11Understanding 21 cfr part 11
Understanding 21 cfr part 11
 

Similar to Auditing your grc programs

Internal Audit’s Evolving Role in Corporate GRC Strategy
Internal Audit’s Evolving Role in Corporate GRC StrategyInternal Audit’s Evolving Role in Corporate GRC Strategy
Internal Audit’s Evolving Role in Corporate GRC Strategy
David Fernandes
 
Audit Process: How to Successfully Plan Audit
Audit Process: How to Successfully Plan Audit Audit Process: How to Successfully Plan Audit
Audit Process: How to Successfully Plan Audit
complianceonline123
 
Insights on grc grc technology au1488
Insights on grc grc technology au1488Insights on grc grc technology au1488
Insights on grc grc technology au1488
Ashwin Kumar
 
External quality assessment presentation august 29 2013
External quality assessment presentation august 29 2013External quality assessment presentation august 29 2013
External quality assessment presentation august 29 2013
Jerry Montes
 
Spire Brief - Risk Consulting
Spire Brief - Risk ConsultingSpire Brief - Risk Consulting
Spire Brief - Risk Consulting
Prashant Jain
 
dt_mt_SREP_Pub_Transformation
dt_mt_SREP_Pub_Transformationdt_mt_SREP_Pub_Transformation
dt_mt_SREP_Pub_Transformation
Mark Micallef
 
Crafting an End-to-End Pharma GRC Strategy
Crafting an End-to-End Pharma GRC StrategyCrafting an End-to-End Pharma GRC Strategy
Crafting an End-to-End Pharma GRC Strategy
Cognizant
 
The role of the new ISO 9001:2015 leadership requirements in companies
The role of the new ISO 9001:2015 leadership requirements in companiesThe role of the new ISO 9001:2015 leadership requirements in companies
The role of the new ISO 9001:2015 leadership requirements in companies
PECB
 
SFC Plan of engagement
SFC Plan of engagementSFC Plan of engagement
SFC Plan of engagement
Jonathan Lamboi
 
Covering Your Bases McDonald
Covering Your Bases McDonaldCovering Your Bases McDonald
Covering Your Bases McDonald
EDR
 
Developing Standards for Enterprise Schedule Quality
Developing Standards for Enterprise Schedule QualityDeveloping Standards for Enterprise Schedule Quality
Developing Standards for Enterprise Schedule Quality
Acumen
 
Building a strong BC programme with ISO 22301
Building a strong BC programme with ISO 22301Building a strong BC programme with ISO 22301
Building a strong BC programme with ISO 22301
PECB
 
Leveraging Gap Assessments and Internal Audits in ISO 22301
Leveraging Gap Assessments and Internal Audits in ISO 22301Leveraging Gap Assessments and Internal Audits in ISO 22301
Leveraging Gap Assessments and Internal Audits in ISO 22301
PECB
 
Strategic PMO - Align Projects to Corporate Strategy
Strategic PMO - Align Projects to Corporate StrategyStrategic PMO - Align Projects to Corporate Strategy
Strategic PMO - Align Projects to Corporate Strategy
Andries Jacobs PhD,MCom, CMC®
 
Program management scope management
Program management   scope managementProgram management   scope management
Program management scope management
Julen Mohanty
 
AUDIT - AUDITING STRATEGIES.pptx
AUDIT - AUDITING STRATEGIES.pptxAUDIT - AUDITING STRATEGIES.pptx
AUDIT - AUDITING STRATEGIES.pptx
Mohamed Fazil M
 
A brief Introduction to ISO 9001 2015-Quality Management System
A brief Introduction to ISO 9001 2015-Quality Management SystemA brief Introduction to ISO 9001 2015-Quality Management System
A brief Introduction to ISO 9001 2015-Quality Management System
SARWAR SALAM
 
The Journey to Integrated Risk Management: Lessons from the Field
The Journey to Integrated Risk Management: Lessons from the Field The Journey to Integrated Risk Management: Lessons from the Field
The Journey to Integrated Risk Management: Lessons from the Field
Resolver Inc.
 
A New Era of Compliance: Innovations in ServiceNow GRC 
A New Era of Compliance: Innovations in ServiceNow GRC A New Era of Compliance: Innovations in ServiceNow GRC 
A New Era of Compliance: Innovations in ServiceNow GRC 
Aelum Consulting
 
module_1.pptx
module_1.pptxmodule_1.pptx
module_1.pptx
ssuser432862
 

Similar to Auditing your grc programs (20)

Internal Audit’s Evolving Role in Corporate GRC Strategy
Internal Audit’s Evolving Role in Corporate GRC StrategyInternal Audit’s Evolving Role in Corporate GRC Strategy
Internal Audit’s Evolving Role in Corporate GRC Strategy
 
Audit Process: How to Successfully Plan Audit
Audit Process: How to Successfully Plan Audit Audit Process: How to Successfully Plan Audit
Audit Process: How to Successfully Plan Audit
 
Insights on grc grc technology au1488
Insights on grc grc technology au1488Insights on grc grc technology au1488
Insights on grc grc technology au1488
 
External quality assessment presentation august 29 2013
External quality assessment presentation august 29 2013External quality assessment presentation august 29 2013
External quality assessment presentation august 29 2013
 
Spire Brief - Risk Consulting
Spire Brief - Risk ConsultingSpire Brief - Risk Consulting
Spire Brief - Risk Consulting
 
dt_mt_SREP_Pub_Transformation
dt_mt_SREP_Pub_Transformationdt_mt_SREP_Pub_Transformation
dt_mt_SREP_Pub_Transformation
 
Crafting an End-to-End Pharma GRC Strategy
Crafting an End-to-End Pharma GRC StrategyCrafting an End-to-End Pharma GRC Strategy
Crafting an End-to-End Pharma GRC Strategy
 
The role of the new ISO 9001:2015 leadership requirements in companies
The role of the new ISO 9001:2015 leadership requirements in companiesThe role of the new ISO 9001:2015 leadership requirements in companies
The role of the new ISO 9001:2015 leadership requirements in companies
 
SFC Plan of engagement
SFC Plan of engagementSFC Plan of engagement
SFC Plan of engagement
 
Covering Your Bases McDonald
Covering Your Bases McDonaldCovering Your Bases McDonald
Covering Your Bases McDonald
 
Developing Standards for Enterprise Schedule Quality
Developing Standards for Enterprise Schedule QualityDeveloping Standards for Enterprise Schedule Quality
Developing Standards for Enterprise Schedule Quality
 
Building a strong BC programme with ISO 22301
Building a strong BC programme with ISO 22301Building a strong BC programme with ISO 22301
Building a strong BC programme with ISO 22301
 
Leveraging Gap Assessments and Internal Audits in ISO 22301
Leveraging Gap Assessments and Internal Audits in ISO 22301Leveraging Gap Assessments and Internal Audits in ISO 22301
Leveraging Gap Assessments and Internal Audits in ISO 22301
 
Strategic PMO - Align Projects to Corporate Strategy
Strategic PMO - Align Projects to Corporate StrategyStrategic PMO - Align Projects to Corporate Strategy
Strategic PMO - Align Projects to Corporate Strategy
 
Program management scope management
Program management   scope managementProgram management   scope management
Program management scope management
 
AUDIT - AUDITING STRATEGIES.pptx
AUDIT - AUDITING STRATEGIES.pptxAUDIT - AUDITING STRATEGIES.pptx
AUDIT - AUDITING STRATEGIES.pptx
 
A brief Introduction to ISO 9001 2015-Quality Management System
A brief Introduction to ISO 9001 2015-Quality Management SystemA brief Introduction to ISO 9001 2015-Quality Management System
A brief Introduction to ISO 9001 2015-Quality Management System
 
The Journey to Integrated Risk Management: Lessons from the Field
The Journey to Integrated Risk Management: Lessons from the Field The Journey to Integrated Risk Management: Lessons from the Field
The Journey to Integrated Risk Management: Lessons from the Field
 
A New Era of Compliance: Innovations in ServiceNow GRC 
A New Era of Compliance: Innovations in ServiceNow GRC A New Era of Compliance: Innovations in ServiceNow GRC 
A New Era of Compliance: Innovations in ServiceNow GRC 
 
module_1.pptx
module_1.pptxmodule_1.pptx
module_1.pptx
 

More from complianceonline123

Fda adverse event reporting requirements for otc drugs
Fda adverse event reporting requirements  for otc drugsFda adverse event reporting requirements  for otc drugs
Fda adverse event reporting requirements for otc drugs
complianceonline123
 
Fmla ada overlap
Fmla  ada  overlapFmla  ada  overlap
Fmla ada overlap
complianceonline123
 
Hipaa enforcement examples
Hipaa enforcement examplesHipaa enforcement examples
Hipaa enforcement examples
complianceonline123
 
Excel spreadsheets how to ensure 21 cfr part 11 compliance
Excel spreadsheets  how to ensure 21 cfr part 11 complianceExcel spreadsheets  how to ensure 21 cfr part 11 compliance
Excel spreadsheets how to ensure 21 cfr part 11 compliance
complianceonline123
 
Retail loss
Retail lossRetail loss
Retail loss
complianceonline123
 
Hipaa privacy rule
Hipaa privacy ruleHipaa privacy rule
Hipaa privacy rule
complianceonline123
 
Fda warning letters
Fda  warning lettersFda  warning letters
Fda warning letters
complianceonline123
 
Dietary supplement
Dietary supplementDietary supplement
Dietary supplement
complianceonline123
 
Basics of internal audit
Basics of internal auditBasics of internal audit
Basics of internal audit
complianceonline123
 
Free trade zones
Free trade zonesFree trade zones
Free trade zones
complianceonline123
 
Aml non bank finanacial institutions
Aml non bank finanacial institutionsAml non bank finanacial institutions
Aml non bank finanacial institutions
complianceonline123
 
Gdp how to manage documentation lifecycle
Gdp  how to manage documentation lifecycleGdp  how to manage documentation lifecycle
Gdp how to manage documentation lifecycle
complianceonline123
 
Workplace harrasment
Workplace harrasmentWorkplace harrasment
Workplace harrasment
complianceonline123
 
Good documentation practices
Good documentation practicesGood documentation practices
Good documentation practices
complianceonline123
 
Information security threats
Information security threatsInformation security threats
Information security threats
complianceonline123
 
Flsa what you need to know
Flsa  what you need to knowFlsa  what you need to know
Flsa what you need to know
complianceonline123
 
FLSA Exemptions: How to Identify Exempt Employees
FLSA Exemptions: How to Identify Exempt EmployeesFLSA Exemptions: How to Identify Exempt Employees
FLSA Exemptions: How to Identify Exempt Employees
complianceonline123
 
Method Validation: What Are Its Key Parameters
Method Validation:What Are Its Key ParametersMethod Validation:What Are Its Key Parameters
Method Validation: What Are Its Key Parameters
complianceonline123
 
Complying with HIPAA Security Rule
Complying with HIPAA Security RuleComplying with HIPAA Security Rule
Complying with HIPAA Security Rule
complianceonline123
 
Understanding Its Suspicious Activity Reporting (SAR) Requirement
Understanding Its Suspicious Activity Reporting (SAR) RequirementUnderstanding Its Suspicious Activity Reporting (SAR) Requirement
Understanding Its Suspicious Activity Reporting (SAR) Requirement
complianceonline123
 

More from complianceonline123 (20)

Fda adverse event reporting requirements for otc drugs
Fda adverse event reporting requirements  for otc drugsFda adverse event reporting requirements  for otc drugs
Fda adverse event reporting requirements for otc drugs
 
Fmla ada overlap
Fmla  ada  overlapFmla  ada  overlap
Fmla ada overlap
 
Hipaa enforcement examples
Hipaa enforcement examplesHipaa enforcement examples
Hipaa enforcement examples
 
Excel spreadsheets how to ensure 21 cfr part 11 compliance
Excel spreadsheets  how to ensure 21 cfr part 11 complianceExcel spreadsheets  how to ensure 21 cfr part 11 compliance
Excel spreadsheets how to ensure 21 cfr part 11 compliance
 
Retail loss
Retail lossRetail loss
Retail loss
 
Hipaa privacy rule
Hipaa privacy ruleHipaa privacy rule
Hipaa privacy rule
 
Fda warning letters
Fda  warning lettersFda  warning letters
Fda warning letters
 
Dietary supplement
Dietary supplementDietary supplement
Dietary supplement
 
Basics of internal audit
Basics of internal auditBasics of internal audit
Basics of internal audit
 
Free trade zones
Free trade zonesFree trade zones
Free trade zones
 
Aml non bank finanacial institutions
Aml non bank finanacial institutionsAml non bank finanacial institutions
Aml non bank finanacial institutions
 
Gdp how to manage documentation lifecycle
Gdp  how to manage documentation lifecycleGdp  how to manage documentation lifecycle
Gdp how to manage documentation lifecycle
 
Workplace harrasment
Workplace harrasmentWorkplace harrasment
Workplace harrasment
 
Good documentation practices
Good documentation practicesGood documentation practices
Good documentation practices
 
Information security threats
Information security threatsInformation security threats
Information security threats
 
Flsa what you need to know
Flsa  what you need to knowFlsa  what you need to know
Flsa what you need to know
 
FLSA Exemptions: How to Identify Exempt Employees
FLSA Exemptions: How to Identify Exempt EmployeesFLSA Exemptions: How to Identify Exempt Employees
FLSA Exemptions: How to Identify Exempt Employees
 
Method Validation: What Are Its Key Parameters
Method Validation:What Are Its Key ParametersMethod Validation:What Are Its Key Parameters
Method Validation: What Are Its Key Parameters
 
Complying with HIPAA Security Rule
Complying with HIPAA Security RuleComplying with HIPAA Security Rule
Complying with HIPAA Security Rule
 
Understanding Its Suspicious Activity Reporting (SAR) Requirement
Understanding Its Suspicious Activity Reporting (SAR) RequirementUnderstanding Its Suspicious Activity Reporting (SAR) Requirement
Understanding Its Suspicious Activity Reporting (SAR) Requirement
 

Recently uploaded

World Food Safety Day 2024- Communication-toolkit.
World Food Safety Day 2024- Communication-toolkit.World Food Safety Day 2024- Communication-toolkit.
World Food Safety Day 2024- Communication-toolkit.
Christina Parmionova
 
快速办理(Bristol毕业证书)布里斯托大学毕业证Offer一模一样
快速办理(Bristol毕业证书)布里斯托大学毕业证Offer一模一样快速办理(Bristol毕业证书)布里斯托大学毕业证Offer一模一样
快速办理(Bristol毕业证书)布里斯托大学毕业证Offer一模一样
3woawyyl
 
PPT Item # 4 - 434 College Blvd. (sign. review)
PPT Item # 4 - 434 College Blvd. (sign. review)PPT Item # 4 - 434 College Blvd. (sign. review)
PPT Item # 4 - 434 College Blvd. (sign. review)
ahcitycouncil
 
Combined Illegal, Unregulated and Unreported (IUU) Vessel List.
Combined Illegal, Unregulated and Unreported (IUU) Vessel List.Combined Illegal, Unregulated and Unreported (IUU) Vessel List.
Combined Illegal, Unregulated and Unreported (IUU) Vessel List.
Christina Parmionova
 
Opinions on EVs: Metro Atlanta Speaks 2023
Opinions on EVs: Metro Atlanta Speaks 2023Opinions on EVs: Metro Atlanta Speaks 2023
Opinions on EVs: Metro Atlanta Speaks 2023
ARCResearch
 
Item # 10 -- Historical Presv. Districts
Item # 10 -- Historical Presv. DistrictsItem # 10 -- Historical Presv. Districts
Item # 10 -- Historical Presv. Districts
ahcitycouncil
 
PUBLIC FINANCIAL MANAGEMENT SYSTEM (PFMS) and DBT.pptx
PUBLIC FINANCIAL MANAGEMENT SYSTEM (PFMS) and DBT.pptxPUBLIC FINANCIAL MANAGEMENT SYSTEM (PFMS) and DBT.pptx
PUBLIC FINANCIAL MANAGEMENT SYSTEM (PFMS) and DBT.pptx
Marked12
 
2024: The FAR - Federal Acquisition Regulations, Part 40
2024: The FAR - Federal Acquisition Regulations, Part 402024: The FAR - Federal Acquisition Regulations, Part 40
2024: The FAR - Federal Acquisition Regulations, Part 40
JSchaus & Associates
 
A proposed request for information on LIHTC
A proposed request for information on LIHTCA proposed request for information on LIHTC
A proposed request for information on LIHTC
Roger Valdez
 
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHO
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHOMonitoring Health for the SDGs - Global Health Statistics 2024 - WHO
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHO
Christina Parmionova
 
在线办理(ISU毕业证书)爱荷华州立大学毕业证学历证书一模一样
在线办理(ISU毕业证书)爱荷华州立大学毕业证学历证书一模一样在线办理(ISU毕业证书)爱荷华州立大学毕业证学历证书一模一样
在线办理(ISU毕业证书)爱荷华州立大学毕业证学历证书一模一样
yemqpj
 
United Nations World Oceans Day 2024; June 8th " Awaken new dephts".
United Nations World Oceans Day 2024; June 8th " Awaken new dephts".United Nations World Oceans Day 2024; June 8th " Awaken new dephts".
United Nations World Oceans Day 2024; June 8th " Awaken new dephts".
Christina Parmionova
 
Donate to charity during this holiday season
Donate to charity during this holiday seasonDonate to charity during this holiday season
Donate to charity during this holiday season
SERUDS INDIA
 
Invitation Letter for an alumni association
Invitation Letter for an alumni associationInvitation Letter for an alumni association
Invitation Letter for an alumni association
elmerdalida001
 
PAS PSDF Mop Up Workshop Presentation 2024 .pptx
PAS PSDF Mop Up Workshop Presentation 2024 .pptxPAS PSDF Mop Up Workshop Presentation 2024 .pptx
PAS PSDF Mop Up Workshop Presentation 2024 .pptx
PAS_Team
 
原版制作(Hope毕业证书)利物浦霍普大学毕业证文凭证书一模一样
原版制作(Hope毕业证书)利物浦霍普大学毕业证文凭证书一模一样原版制作(Hope毕业证书)利物浦霍普大学毕业证文凭证书一模一样
原版制作(Hope毕业证书)利物浦霍普大学毕业证文凭证书一模一样
ii2sh2v
 
PPT Item # 7 - 231 Encino Avenue (sign. review)
PPT Item # 7 - 231 Encino Avenue (sign. review)PPT Item # 7 - 231 Encino Avenue (sign. review)
PPT Item # 7 - 231 Encino Avenue (sign. review)
ahcitycouncil
 
Indira P.S Vs sub Collector Kochi - The settlement register is not a holy cow...
Indira P.S Vs sub Collector Kochi - The settlement register is not a holy cow...Indira P.S Vs sub Collector Kochi - The settlement register is not a holy cow...
Indira P.S Vs sub Collector Kochi - The settlement register is not a holy cow...
Jamesadhikaram land matter consultancy 9447464502
 
IEA World Energy Investment June 2024- Statistics
IEA World Energy Investment June 2024- StatisticsIEA World Energy Investment June 2024- Statistics
IEA World Energy Investment June 2024- Statistics
Energy for One World
 
CFYT Rolling Ads Dawson City Yukon Canada
CFYT Rolling Ads Dawson City Yukon CanadaCFYT Rolling Ads Dawson City Yukon Canada
CFYT Rolling Ads Dawson City Yukon Canada
pmenzies
 

Recently uploaded (20)

World Food Safety Day 2024- Communication-toolkit.
World Food Safety Day 2024- Communication-toolkit.World Food Safety Day 2024- Communication-toolkit.
World Food Safety Day 2024- Communication-toolkit.
 
快速办理(Bristol毕业证书)布里斯托大学毕业证Offer一模一样
快速办理(Bristol毕业证书)布里斯托大学毕业证Offer一模一样快速办理(Bristol毕业证书)布里斯托大学毕业证Offer一模一样
快速办理(Bristol毕业证书)布里斯托大学毕业证Offer一模一样
 
PPT Item # 4 - 434 College Blvd. (sign. review)
PPT Item # 4 - 434 College Blvd. (sign. review)PPT Item # 4 - 434 College Blvd. (sign. review)
PPT Item # 4 - 434 College Blvd. (sign. review)
 
Combined Illegal, Unregulated and Unreported (IUU) Vessel List.
Combined Illegal, Unregulated and Unreported (IUU) Vessel List.Combined Illegal, Unregulated and Unreported (IUU) Vessel List.
Combined Illegal, Unregulated and Unreported (IUU) Vessel List.
 
Opinions on EVs: Metro Atlanta Speaks 2023
Opinions on EVs: Metro Atlanta Speaks 2023Opinions on EVs: Metro Atlanta Speaks 2023
Opinions on EVs: Metro Atlanta Speaks 2023
 
Item # 10 -- Historical Presv. Districts
Item # 10 -- Historical Presv. DistrictsItem # 10 -- Historical Presv. Districts
Item # 10 -- Historical Presv. Districts
 
PUBLIC FINANCIAL MANAGEMENT SYSTEM (PFMS) and DBT.pptx
PUBLIC FINANCIAL MANAGEMENT SYSTEM (PFMS) and DBT.pptxPUBLIC FINANCIAL MANAGEMENT SYSTEM (PFMS) and DBT.pptx
PUBLIC FINANCIAL MANAGEMENT SYSTEM (PFMS) and DBT.pptx
 
2024: The FAR - Federal Acquisition Regulations, Part 40
2024: The FAR - Federal Acquisition Regulations, Part 402024: The FAR - Federal Acquisition Regulations, Part 40
2024: The FAR - Federal Acquisition Regulations, Part 40
 
A proposed request for information on LIHTC
A proposed request for information on LIHTCA proposed request for information on LIHTC
A proposed request for information on LIHTC
 
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHO
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHOMonitoring Health for the SDGs - Global Health Statistics 2024 - WHO
Monitoring Health for the SDGs - Global Health Statistics 2024 - WHO
 
在线办理(ISU毕业证书)爱荷华州立大学毕业证学历证书一模一样
在线办理(ISU毕业证书)爱荷华州立大学毕业证学历证书一模一样在线办理(ISU毕业证书)爱荷华州立大学毕业证学历证书一模一样
在线办理(ISU毕业证书)爱荷华州立大学毕业证学历证书一模一样
 
United Nations World Oceans Day 2024; June 8th " Awaken new dephts".
United Nations World Oceans Day 2024; June 8th " Awaken new dephts".United Nations World Oceans Day 2024; June 8th " Awaken new dephts".
United Nations World Oceans Day 2024; June 8th " Awaken new dephts".
 
Donate to charity during this holiday season
Donate to charity during this holiday seasonDonate to charity during this holiday season
Donate to charity during this holiday season
 
Invitation Letter for an alumni association
Invitation Letter for an alumni associationInvitation Letter for an alumni association
Invitation Letter for an alumni association
 
PAS PSDF Mop Up Workshop Presentation 2024 .pptx
PAS PSDF Mop Up Workshop Presentation 2024 .pptxPAS PSDF Mop Up Workshop Presentation 2024 .pptx
PAS PSDF Mop Up Workshop Presentation 2024 .pptx
 
原版制作(Hope毕业证书)利物浦霍普大学毕业证文凭证书一模一样
原版制作(Hope毕业证书)利物浦霍普大学毕业证文凭证书一模一样原版制作(Hope毕业证书)利物浦霍普大学毕业证文凭证书一模一样
原版制作(Hope毕业证书)利物浦霍普大学毕业证文凭证书一模一样
 
PPT Item # 7 - 231 Encino Avenue (sign. review)
PPT Item # 7 - 231 Encino Avenue (sign. review)PPT Item # 7 - 231 Encino Avenue (sign. review)
PPT Item # 7 - 231 Encino Avenue (sign. review)
 
Indira P.S Vs sub Collector Kochi - The settlement register is not a holy cow...
Indira P.S Vs sub Collector Kochi - The settlement register is not a holy cow...Indira P.S Vs sub Collector Kochi - The settlement register is not a holy cow...
Indira P.S Vs sub Collector Kochi - The settlement register is not a holy cow...
 
IEA World Energy Investment June 2024- Statistics
IEA World Energy Investment June 2024- StatisticsIEA World Energy Investment June 2024- Statistics
IEA World Energy Investment June 2024- Statistics
 
CFYT Rolling Ads Dawson City Yukon Canada
CFYT Rolling Ads Dawson City Yukon CanadaCFYT Rolling Ads Dawson City Yukon Canada
CFYT Rolling Ads Dawson City Yukon Canada
 

Auditing your grc programs

  • 1.
  • 2. Governance, risk and compliance or GRC programs are complex – an organization has to use its GRC program to address the regulatory requirements expected of, among others, the following:  Enterprise Risk Management  COSO Internal Controls  Environmental Compliance (EPA rules)  Anti Trust  Anti Money Laundering  Anti Bribery/Corruption  Quality Management and Standards such as ISO 9000, 9001  Process Management such as Six Sigma  Anti Harassment  Human Capital  Whistle-blowing  HR Processes The areas listed above are just few of those that come under the purview of a robust GRC program.
  • 3.  Given the complex nature of regulations around the world today and the increasing risks of doing business, it is important that the GRC program in an organization is audited frequently. Most of the lapses in corporate governance occur due to outdated GRC programs that have not been audited and updated to reflect the current regulatory environment.  Internal audits of GRC programs allow management and the board to identify risks and areas that need strengthening and root out any non-compliance.  An audit can help evaluate the adequacy of the program’s design and effectiveness as well as new practices and technologies to be implemented.  Audits of the GRC program have to be carried out periodically – these should supplement an ongoing, daily evaluation of the effectiveness of the program, including monitoring of controls and responses.
  • 4. 1. Define evaluation scope, objectives, and the type of evaluation. 2. Define the level and type of assurance 3. Identify the evaluation team and skills required. 4. Develop evaluation plan. 5. Perform design adequacy evaluation. 6. Perform operational effectiveness evaluation. 7. Communicate evaluation results and ensure follow-up to address issues.
  • 5.  Before carrying out the audit, the risks need to be understood and assessed. Risk assessment is important in ensuring that the audit plan, program and specific tests that need to be carried out are appropriate and adequate. The risk assessment needs to be carried out while the audit is underway as well.  Some of the key risk factors in GRC program audits include: ◦ The scope and complexity of the program. ◦ The scope and complexity of the organization. ◦ The current regulatory environment. ◦ Breaking news and developments relevant to corporate governance. ◦ The experience of the GRC program management team. ◦ Implications of Sarbanes Oxley on the business. ◦ The day-to-day involvement and support of the management and board. ◦ The pace of updates and changes to the program’s efforts. ◦ The maturity of the program. ◦ The robustness of the GRC program’s project management processes.
  • 6.  Plan Your Audit Properly  Define Your Audit Scope and Objectives  Conduct Proper Risk Assessment  Ensure Audit Testing is Carried Out  Issue a Comprehensive Audit Report
  • 7. Want to learn more about audit, and best practices for auditing? ComplianceOnline webinars and seminars are a great training resource. Check out the following links:  How to Audit GRC Programs?  Role of the Audit Committee in Corporate Governance  Internal Audit's Role in Enterprise Risk Management  OCEG Approved GRC (Governance, Risk and Compliance) Professional Seminar  Auditing Technology and IT Investment Management