SlideShare a Scribd company logo
29-8-2017
1
GRC and Combined Assurance:
What’s the Difference?
Toby DeRoche
MBA, CIA, CCSA, CRMA, CICA, CFE
Senior Market Development Consultant
Housekeeping
This webinar and its material are the property of AuditNet® and its Webinar partners. Unauthorized
usage or recording of this webinar or any of its material is strictly forbidden.
 If you logged in with another individual’s confirmation email you will not receive CPE as the
confirmation login is linked to a specific individual
 This Webinar is not eligible for viewing in a group setting. You must be logged in with your unique
join link.
 We are recording the webinar and you will be provided access to that recording after the webinar.
Downloading or otherwise duplicating the webinar recording is expressly prohibited.
 If you have indicated you would like CPE you must answer all the polling questions to receive CPE
per NASBA.
 If you meet the NASBA criteria for earning CPE you will receive a link via email to download your
certificate. The official email for CPE will be issued via NoReply@gensend.io and it is important to
white list this address. It is from this email that your CPE credit will be sent. There is a processing
fee to have your CPE credit regenerated post event.
 Submit questions via the chat box on your screen and we will answer them either during or at the
conclusion.
 Please complete the evaluation questionnaire to help us continuously improve our Webinars.
Agile Auditing
29-8-2017
2
IMPORTANT INFORMATION
REGARDING CPE!
 SUBSCRIBERS/SITE LICENSE USERS - If you attend the Webinar and answer all the polling questions you will
receive an email with the link to download your CPE certificate. The official email for CPE will be issued via
NoReply@gensend.io and it is important to white list this address. It is from this email that your CPE credit will be
sent. There is a processing fee to have your CPE credit regenerated post event.
 NON-SUBSCRIBERS/NON-SITE LICENSE USERS - If you attend the Webinar and answer all the polling
questions and requested CPE you must pay to receive your CPE. No exceptions!
 We cannot manually generate a CPE certificate as these are handled by our 3rd party provider. We highly
recommend that you work with your IT department to identify and correct any email delivery issues prior to
attending the Webinar. Issues would include blocks or spam filters in your email system or a firewall that will
redirect or not allow delivery of this email from Gensend.io
 Anyone may register, attend and view the Webinar without fees if they opted out of receiving CPE.
 We are not responsible for any connection, audio or other computer related issues. You must have pop-ups
enabled on you computer otherwise you will not be able to answer the polling questions which occur approximately
every 20 minutes. We suggest that if you have any pressing issues to see to that you do so immediately after a
polling question.
Agile Auditing
The views expressed by the presenters do not necessarily represent the views,
positions, or opinions of AuditNet® LLC. These materials, and the oral
presentation accompanying them, are for educational purposes only and do not
constitute accounting or legal advice or create an accountant-client relationship.
While AuditNet® makes every effort to ensure information is accurate and
complete, AuditNet® makes no representations, guarantees, or warranties as to
the accuracy or completeness of the information provided via this presentation.
AuditNet® specifically disclaims all liability for any claims or damages that may
result from the information contained in this presentation, including any websites
maintained by third parties and linked to the AuditNet® website.
Any mention of commercial products is for information only; it does not imply
recommendation or endorsement by AuditNet® LLC
Agile Auditing
29-8-2017
3
Speaker Bio
 Toby DeRoche MBA, CIA, CCSA, CRMA, CICA, CFE
 Internal Audit with a Fortune 100 corporation for 4 years
 Audit consultant for Wolters Kluwer for 7 years
 Works with organizations that are looking for solutions to address their audit and compliance needs.
 Assisted several hundred internal audit departments create, perform, and supervise financial, operational, and
compliance audits to evaluate control frameworks, financial systems, and operating procedures.
GRC vs Combined Assurance
Presentation Overview
With more organizations exploring the concept of
Combined Assurance, there have been many questions
about how this relates to GRC.
In this presentation, we will explore both concepts and
discuss the differences between Combined Assurance and
GRC.
GRC vs Combined Assurance
29-8-2017
4
Agenda
Understand the concepts behind
Combined Assurance and GRC
Discuss pros and cons for both
Combined Assurance and GRC
GRC vs Combined Assurance
POLLING QUESTION
29-8-2017
5
Assurance Providers
Assurance
Audit
ERM
SOX
InfoSec
EHS
Legal
Numerous departments within
an organization contribute to
governance
GRC vs Combined Assurance
Understanding Combined Assurance
29-8-2017
6
Combined Assurance
 Prevent management from being overwhelmed by information
and reports and succumbing to “audit fatigue”
 Provide better organizational governance
 Benefits:
 One voice and taxonomy across all governance bodies and functions in the
organization
 Efficiency in collecting and reporting information
 Common view of risks and issues across the organization
 More effective governance, risk, and control oversight
GRC vs Combined Assurance
Coordination and Reliance
IIA Standard 2050:
 The chief audit executive should share
information, coordinate activities, and consider
relying upon the work of other internal and
external assurance and consulting service
providers to ensure proper coverage and
minimize duplication of efforts.
GRC vs Combined Assurance
29-8-2017
7
Coordination Approaches
 Integrated planning
 A comprehensive audit risk assessment process should consider:
 Current work planned by other assurance providers that can be
relied upon for audit coverage
 Past results from work completed by other assurance providers
 Integrated reporting
 Reporting on risk coverage and audit coverage
 Reporting on the control environment and issues found
 Comprehensive issue trending by multiple categorizations
GRC vs Combined Assurance
Overlapping Activities
GRC vs Combined Assurance
Audit planning
Risk
based
projects
Issue
categorization
Board
reporting
29-8-2017
8
Coordination Approaches
 Integrated planning
 A comprehensive audit risk assessment should consider:
 EHS risks
 InfoSec risks
 Legal risks
 Work planned by the other assurance providers can be relied
upon for audit coverage for these areas
 May need to use tools like a Risk Coverage Map
GRC vs Combined Assurance
Coordination Approaches
 Integrated planning
 CAE and other assurance groups should submit summaries of their
respective planned audit activities, staffing plan, and budget to senior
management and the board
 Combining this presentation helps stakeholders better understand the
scope of the work and planned audit coverage
GRC vs Combined Assurance
29-8-2017
9
Coordination Approaches
 Integrated reporting
 Co-presenting internal audit and other audit results will enable
management to focus and set priorities for the organization.
Reduces “audit fatigue”
GRC vs Combined Assurance
Coordination Approaches
 Audit activity alignment
 Align the structure of risk and control assessment
 Align documentation standards
 Align project and board reporting structure
 Align issue categorization
GRC vs Combined Assurance
29-8-2017
10
POLLING QUESTION
Leverage Technology
 Look for systems to integrate the audit effort
 Shared risk assessment tools
 Shared control monitoring tools
 Shared analytics tools
 Shared documentation tools
 Shared reporting tools for aggregation
GRC vs Combined Assurance
29-8-2017
11
Understanding GRC
What is GRC?
GRC is the process of integrating governance efforts, risk
management, and control implementation an organization puts in place
to ensure success.
GRC vs Combined Assurance
29-8-2017
12
What GRC is NOT?
 GRC is not software
 GRC solutions are not a magic bullet that creates governance
 Good GRC software should open communication lines across
departments
GRC vs Combined Assurance
GRC Goals
 Reduced costs
 Reduced redundant activities
 Streamline operations
 Capture better data more
efficiently
GRC vs Combined Assurance
Copied form OCEG Website
29-8-2017
13
GRC Challenges
 Hard to define
 Hard to achieve integration
 Hard to maintain consistency
GRC vs Combined Assurance
Copied form OCEG Website
Leverage Technology
 Look for systems to integrate the functions
 Shared strategic objectives
 Shared risk assessment tools
 Shared control monitoring tools
 Shared reporting tools for aggregation
 Shared data for analytics
 Allow integrated individuality
GRC vs Combined Assurance
29-8-2017
14
POLLING QUESTION
What’s the difference?
 GRC is an alignment of
business and risk functions
 GRC is typically a
management function
 GRC should include internal
audit
 Combined Assurance is an
alignment of audit functions
 Combined Assurance is an audit
function
 Combined Assurance is lead by
internal audit
29-8-2017
15
Questions?
AuditNet® and cRisk Academy
 If you would like forever access
to this webinar recording
 If you are watching the
recording, and would like to
obtain CPE credit for this
webinar
 Previous AuditNet® webinars
are also available on-demand
for CPE credit
http://criskacademy.com
http://ondemand.criskacademy.com
Use coupon code: 50OFF for a
discount on this webinar for one week
Agile Auditing

More Related Content

What's hot

Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)
Diane Christina
 
Control Self Assessment
Control Self AssessmentControl Self Assessment
Control Self Assessment
Manoj Agarwal
 
Riskpro - Operational Risk Management
Riskpro - Operational Risk ManagementRiskpro - Operational Risk Management
Riskpro - Operational Risk Management
Manoj Jain
 
Governance Culture & Incentives- Fundamentals of Operational Risk
Governance Culture & Incentives- Fundamentals of Operational RiskGovernance Culture & Incentives- Fundamentals of Operational Risk
Governance Culture & Incentives- Fundamentals of Operational Risk
Andrew Smart
 
Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...
Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...
Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...
Resolver Inc.
 
Model Risk Management : Best Practices
Model Risk Management : Best PracticesModel Risk Management : Best Practices
Model Risk Management : Best Practices
QuantUniversity
 
The Role of Risk Appetite in embedding the ORSA and linking with Business Str...
The Role of Risk Appetite in embedding the ORSA and linking with Business Str...The Role of Risk Appetite in embedding the ORSA and linking with Business Str...
The Role of Risk Appetite in embedding the ORSA and linking with Business Str...Susan Young
 
Chapter 5 risk_
Chapter 5 risk_Chapter 5 risk_
Chapter 5 risk_
Rione Drevale
 
Operational Risk Management Under Basel II & Basel III
Operational Risk Management Under Basel II & Basel IIIOperational Risk Management Under Basel II & Basel III
Operational Risk Management Under Basel II & Basel III
Eneni Oduwole
 
Risk Assessment PowerPoint Presentation Slides
Risk Assessment PowerPoint Presentation Slides Risk Assessment PowerPoint Presentation Slides
Risk Assessment PowerPoint Presentation Slides
SlideTeam
 
Operational risk management a strategic tool
Operational risk management   a strategic toolOperational risk management   a strategic tool
Operational risk management a strategic tool
Eneni Oduwole
 
operations risk management power point presentation.
operations risk management power point presentation.operations risk management power point presentation.
operations risk management power point presentation.Miyelani Shibambo
 
Cisa domain 4
Cisa domain 4Cisa domain 4
Cisa domain 4
ShivamSharma909
 
Advanced Risk Management - Elsam Management Consultants
Advanced Risk Management - Elsam Management ConsultantsAdvanced Risk Management - Elsam Management Consultants
Advanced Risk Management - Elsam Management Consultants
EMAC Consulting Group
 
Operational Risk Management - Understanding Your Risk Landscape
Operational Risk Management - Understanding Your Risk LandscapeOperational Risk Management - Understanding Your Risk Landscape
Operational Risk Management - Understanding Your Risk Landscape
Eneni Oduwole
 
COMBINED VALUE ASSURANCE PRESENTATION OF CAPITAL PROJECTS BY FRONT-END LOADIN...
COMBINED VALUE ASSURANCE PRESENTATION OF CAPITAL PROJECTS BY FRONT-END LOADIN...COMBINED VALUE ASSURANCE PRESENTATION OF CAPITAL PROJECTS BY FRONT-END LOADIN...
COMBINED VALUE ASSURANCE PRESENTATION OF CAPITAL PROJECTS BY FRONT-END LOADIN...
ANGUSMACLEOD21
 
Session 02 Risk Assessment Program for YSP_The Risk Assessment Process
Session 02 Risk Assessment Program for YSP_The Risk Assessment ProcessSession 02 Risk Assessment Program for YSP_The Risk Assessment Process
Session 02 Risk Assessment Program for YSP_The Risk Assessment Process
Muizz Anibire
 
Operational Risk Management under BASEL era
Operational Risk Management under BASEL eraOperational Risk Management under BASEL era
Operational Risk Management under BASEL era
Treat Risk
 

What's hot (20)

Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)Sharing Practice on Enterprise Risk Management (ERM)
Sharing Practice on Enterprise Risk Management (ERM)
 
Control Self Assessment
Control Self AssessmentControl Self Assessment
Control Self Assessment
 
Riskpro - Operational Risk Management
Riskpro - Operational Risk ManagementRiskpro - Operational Risk Management
Riskpro - Operational Risk Management
 
Governance Culture & Incentives- Fundamentals of Operational Risk
Governance Culture & Incentives- Fundamentals of Operational RiskGovernance Culture & Incentives- Fundamentals of Operational Risk
Governance Culture & Incentives- Fundamentals of Operational Risk
 
Risk Appetite
Risk AppetiteRisk Appetite
Risk Appetite
 
Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...
Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...
Why You Should Prioritize Third Party Risk Management (TPRM) in Today's Marke...
 
Model Risk Management : Best Practices
Model Risk Management : Best PracticesModel Risk Management : Best Practices
Model Risk Management : Best Practices
 
Irm Risk Appetite
Irm Risk AppetiteIrm Risk Appetite
Irm Risk Appetite
 
The Role of Risk Appetite in embedding the ORSA and linking with Business Str...
The Role of Risk Appetite in embedding the ORSA and linking with Business Str...The Role of Risk Appetite in embedding the ORSA and linking with Business Str...
The Role of Risk Appetite in embedding the ORSA and linking with Business Str...
 
Chapter 5 risk_
Chapter 5 risk_Chapter 5 risk_
Chapter 5 risk_
 
Operational Risk Management Under Basel II & Basel III
Operational Risk Management Under Basel II & Basel IIIOperational Risk Management Under Basel II & Basel III
Operational Risk Management Under Basel II & Basel III
 
Risk Assessment PowerPoint Presentation Slides
Risk Assessment PowerPoint Presentation Slides Risk Assessment PowerPoint Presentation Slides
Risk Assessment PowerPoint Presentation Slides
 
Operational risk management a strategic tool
Operational risk management   a strategic toolOperational risk management   a strategic tool
Operational risk management a strategic tool
 
operations risk management power point presentation.
operations risk management power point presentation.operations risk management power point presentation.
operations risk management power point presentation.
 
Cisa domain 4
Cisa domain 4Cisa domain 4
Cisa domain 4
 
Advanced Risk Management - Elsam Management Consultants
Advanced Risk Management - Elsam Management ConsultantsAdvanced Risk Management - Elsam Management Consultants
Advanced Risk Management - Elsam Management Consultants
 
Operational Risk Management - Understanding Your Risk Landscape
Operational Risk Management - Understanding Your Risk LandscapeOperational Risk Management - Understanding Your Risk Landscape
Operational Risk Management - Understanding Your Risk Landscape
 
COMBINED VALUE ASSURANCE PRESENTATION OF CAPITAL PROJECTS BY FRONT-END LOADIN...
COMBINED VALUE ASSURANCE PRESENTATION OF CAPITAL PROJECTS BY FRONT-END LOADIN...COMBINED VALUE ASSURANCE PRESENTATION OF CAPITAL PROJECTS BY FRONT-END LOADIN...
COMBINED VALUE ASSURANCE PRESENTATION OF CAPITAL PROJECTS BY FRONT-END LOADIN...
 
Session 02 Risk Assessment Program for YSP_The Risk Assessment Process
Session 02 Risk Assessment Program for YSP_The Risk Assessment ProcessSession 02 Risk Assessment Program for YSP_The Risk Assessment Process
Session 02 Risk Assessment Program for YSP_The Risk Assessment Process
 
Operational Risk Management under BASEL era
Operational Risk Management under BASEL eraOperational Risk Management under BASEL era
Operational Risk Management under BASEL era
 

Similar to What's the Difference between GRC and Combined Assurance?

Is Your Audit Department Highly Effective?
Is Your Audit Department Highly Effective?Is Your Audit Department Highly Effective?
Is Your Audit Department Highly Effective?
Jim Kaplan CIA CFE
 
How ERM and audit work together, a combined assurance approach
How ERM and audit work together, a combined assurance approach How ERM and audit work together, a combined assurance approach
How ERM and audit work together, a combined assurance approach
Jim Kaplan CIA CFE
 
Internal Auditing Basics
Internal Auditing BasicsInternal Auditing Basics
Internal Auditing Basics
Jim Kaplan CIA CFE
 
Right to Audit Clauses: What you need to know!
Right to Audit Clauses: What you need to know!Right to Audit Clauses: What you need to know!
Right to Audit Clauses: What you need to know!
Jim Kaplan CIA CFE
 
Future audit analytics
Future audit analyticsFuture audit analytics
Future audit analytics
Jim Kaplan CIA CFE
 
Fieldwork Webinar
Fieldwork WebinarFieldwork Webinar
Fieldwork Webinar
Jim Kaplan CIA CFE
 
How analytics should be used in controls testing instead of sampling
How analytics should be used in controls testing instead of samplingHow analytics should be used in controls testing instead of sampling
How analytics should be used in controls testing instead of sampling
Jim Kaplan CIA CFE
 
How analytics should be used in controls testing instead of sampling
How analytics should be used in controls testing instead of sampling How analytics should be used in controls testing instead of sampling
How analytics should be used in controls testing instead of sampling
Jim Kaplan CIA CFE
 
Touchstone Research for Internal Audit 2020 – A Look at the Now and Tomorrow ...
Touchstone Research for Internal Audit 2020 – A Look at the Now and Tomorrow ...Touchstone Research for Internal Audit 2020 – A Look at the Now and Tomorrow ...
Touchstone Research for Internal Audit 2020 – A Look at the Now and Tomorrow ...
Jim Kaplan CIA CFE
 
Are You a Smart CAAT or a Copy CAAT
Are You a Smart CAAT or a Copy CAATAre You a Smart CAAT or a Copy CAAT
Are You a Smart CAAT or a Copy CAAT
Jim Kaplan CIA CFE
 
Retrospective data analytics slides
Retrospective data analytics slidesRetrospective data analytics slides
Retrospective data analytics slides
Jim Kaplan CIA CFE
 
IT Fraud and Countermeasures
IT Fraud and CountermeasuresIT Fraud and Countermeasures
IT Fraud and Countermeasures
Jim Kaplan CIA CFE
 
When is a Duplicate not a Duplicate? Detecting Errors and Fraud
When is a Duplicate not a Duplicate? Detecting Errors and FraudWhen is a Duplicate not a Duplicate? Detecting Errors and Fraud
When is a Duplicate not a Duplicate? Detecting Errors and Fraud
Jim Kaplan CIA CFE
 
Agile auditing for financial services
Agile auditing for financial services  Agile auditing for financial services
Agile auditing for financial services
Jim Kaplan CIA CFE
 
Implementing and Auditing General Data Protection Regulation
Implementing and Auditing General Data Protection RegulationImplementing and Auditing General Data Protection Regulation
Implementing and Auditing General Data Protection Regulation
Jim Kaplan CIA CFE
 
Enhanced fraud detection with data analytics
Enhanced fraud detection with data analyticsEnhanced fraud detection with data analytics
Enhanced fraud detection with data analytics
Jim Kaplan CIA CFE
 
Focused agile audit planning using analytics
Focused agile audit planning using analyticsFocused agile audit planning using analytics
Focused agile audit planning using analytics
Jim Kaplan CIA CFE
 
Embracing Multigenerational Teams in Audit
Embracing Multigenerational Teams in AuditEmbracing Multigenerational Teams in Audit
Embracing Multigenerational Teams in Audit
Jim Kaplan CIA CFE
 
Structuring your organization for success with data analytics
Structuring your organization for success with data analytics Structuring your organization for success with data analytics
Structuring your organization for success with data analytics
Jim Kaplan CIA CFE
 
Internal Audit's Role in Ethics, Governance, & Culture
Internal Audit's Role in Ethics, Governance, & CultureInternal Audit's Role in Ethics, Governance, & Culture
Internal Audit's Role in Ethics, Governance, & Culture
Jim Kaplan CIA CFE
 

Similar to What's the Difference between GRC and Combined Assurance? (20)

Is Your Audit Department Highly Effective?
Is Your Audit Department Highly Effective?Is Your Audit Department Highly Effective?
Is Your Audit Department Highly Effective?
 
How ERM and audit work together, a combined assurance approach
How ERM and audit work together, a combined assurance approach How ERM and audit work together, a combined assurance approach
How ERM and audit work together, a combined assurance approach
 
Internal Auditing Basics
Internal Auditing BasicsInternal Auditing Basics
Internal Auditing Basics
 
Right to Audit Clauses: What you need to know!
Right to Audit Clauses: What you need to know!Right to Audit Clauses: What you need to know!
Right to Audit Clauses: What you need to know!
 
Future audit analytics
Future audit analyticsFuture audit analytics
Future audit analytics
 
Fieldwork Webinar
Fieldwork WebinarFieldwork Webinar
Fieldwork Webinar
 
How analytics should be used in controls testing instead of sampling
How analytics should be used in controls testing instead of samplingHow analytics should be used in controls testing instead of sampling
How analytics should be used in controls testing instead of sampling
 
How analytics should be used in controls testing instead of sampling
How analytics should be used in controls testing instead of sampling How analytics should be used in controls testing instead of sampling
How analytics should be used in controls testing instead of sampling
 
Touchstone Research for Internal Audit 2020 – A Look at the Now and Tomorrow ...
Touchstone Research for Internal Audit 2020 – A Look at the Now and Tomorrow ...Touchstone Research for Internal Audit 2020 – A Look at the Now and Tomorrow ...
Touchstone Research for Internal Audit 2020 – A Look at the Now and Tomorrow ...
 
Are You a Smart CAAT or a Copy CAAT
Are You a Smart CAAT or a Copy CAATAre You a Smart CAAT or a Copy CAAT
Are You a Smart CAAT or a Copy CAAT
 
Retrospective data analytics slides
Retrospective data analytics slidesRetrospective data analytics slides
Retrospective data analytics slides
 
IT Fraud and Countermeasures
IT Fraud and CountermeasuresIT Fraud and Countermeasures
IT Fraud and Countermeasures
 
When is a Duplicate not a Duplicate? Detecting Errors and Fraud
When is a Duplicate not a Duplicate? Detecting Errors and FraudWhen is a Duplicate not a Duplicate? Detecting Errors and Fraud
When is a Duplicate not a Duplicate? Detecting Errors and Fraud
 
Agile auditing for financial services
Agile auditing for financial services  Agile auditing for financial services
Agile auditing for financial services
 
Implementing and Auditing General Data Protection Regulation
Implementing and Auditing General Data Protection RegulationImplementing and Auditing General Data Protection Regulation
Implementing and Auditing General Data Protection Regulation
 
Enhanced fraud detection with data analytics
Enhanced fraud detection with data analyticsEnhanced fraud detection with data analytics
Enhanced fraud detection with data analytics
 
Focused agile audit planning using analytics
Focused agile audit planning using analyticsFocused agile audit planning using analytics
Focused agile audit planning using analytics
 
Embracing Multigenerational Teams in Audit
Embracing Multigenerational Teams in AuditEmbracing Multigenerational Teams in Audit
Embracing Multigenerational Teams in Audit
 
Structuring your organization for success with data analytics
Structuring your organization for success with data analytics Structuring your organization for success with data analytics
Structuring your organization for success with data analytics
 
Internal Audit's Role in Ethics, Governance, & Culture
Internal Audit's Role in Ethics, Governance, & CultureInternal Audit's Role in Ethics, Governance, & Culture
Internal Audit's Role in Ethics, Governance, & Culture
 

More from Jim Kaplan CIA CFE

mplementing and Auditing GDPR Series (10 of 10)
mplementing and Auditing GDPR Series (10 of 10) mplementing and Auditing GDPR Series (10 of 10)
mplementing and Auditing GDPR Series (10 of 10)
Jim Kaplan CIA CFE
 
Implementing and Auditing GDPR Series (9 of 10)
Implementing and Auditing GDPR Series (9 of 10) Implementing and Auditing GDPR Series (9 of 10)
Implementing and Auditing GDPR Series (9 of 10)
Jim Kaplan CIA CFE
 
How to detect fraud like a pro detective slides
How to detect fraud like a pro detective slides How to detect fraud like a pro detective slides
How to detect fraud like a pro detective slides
Jim Kaplan CIA CFE
 
Implementing and Auditing GDPR Series (8 of 10)
Implementing and Auditing GDPR Series (8 of 10) Implementing and Auditing GDPR Series (8 of 10)
Implementing and Auditing GDPR Series (8 of 10)
Jim Kaplan CIA CFE
 
How to get auditors performing basic analytics using excel
How to get auditors performing basic analytics using excel How to get auditors performing basic analytics using excel
How to get auditors performing basic analytics using excel
Jim Kaplan CIA CFE
 
Tracking down outliers
Tracking down outliersTracking down outliers
Tracking down outliers
Jim Kaplan CIA CFE
 
CyberSecurity Update Slides
CyberSecurity Update SlidesCyberSecurity Update Slides
CyberSecurity Update Slides
Jim Kaplan CIA CFE
 
General Data Protection Regulation Webinar 6
General Data Protection Regulation Webinar 6 General Data Protection Regulation Webinar 6
General Data Protection Regulation Webinar 6
Jim Kaplan CIA CFE
 
General Data Protection Regulation for Auditors 5 of 10
General Data Protection Regulation for Auditors 5 of 10General Data Protection Regulation for Auditors 5 of 10
General Data Protection Regulation for Auditors 5 of 10
Jim Kaplan CIA CFE
 
Ethics and the Internal Auditor
Ethics and the Internal AuditorEthics and the Internal Auditor
Ethics and the Internal Auditor
Jim Kaplan CIA CFE
 
GDPR Series Session 4
GDPR Series Session 4GDPR Series Session 4
GDPR Series Session 4
Jim Kaplan CIA CFE
 
Cybersecurity Slides
Cybersecurity  SlidesCybersecurity  Slides
Cybersecurity Slides
Jim Kaplan CIA CFE
 
Implementing and Auditing GDPR Series (3 of 10)
Implementing and Auditing GDPR Series (3 of 10) Implementing and Auditing GDPR Series (3 of 10)
Implementing and Auditing GDPR Series (3 of 10)
Jim Kaplan CIA CFE
 
Ethics for internal auditors
Ethics for internal auditorsEthics for internal auditors
Ethics for internal auditors
Jim Kaplan CIA CFE
 
Implementing and Auditing GDPR Series (2 of 10)
Implementing and Auditing GDPR Series (2 of 10) Implementing and Auditing GDPR Series (2 of 10)
Implementing and Auditing GDPR Series (2 of 10)
Jim Kaplan CIA CFE
 
Implementing and Auditing General Data Protection Regulation
Implementing and Auditing General Data Protection Regulation Implementing and Auditing General Data Protection Regulation
Implementing and Auditing General Data Protection Regulation
Jim Kaplan CIA CFE
 
Cybersecurity update 12
Cybersecurity update 12Cybersecurity update 12
Cybersecurity update 12
Jim Kaplan CIA CFE
 
How to use ai apps to unleash the power of your audit program
How to use ai apps to unleash the power of your audit program How to use ai apps to unleash the power of your audit program
How to use ai apps to unleash the power of your audit program
Jim Kaplan CIA CFE
 
Driving More Value With Automated Analytics
Driving More Value With Automated AnalyticsDriving More Value With Automated Analytics
Driving More Value With Automated Analytics
Jim Kaplan CIA CFE
 
Ethics for Internal Auditors
Ethics for  Internal AuditorsEthics for  Internal Auditors
Ethics for Internal Auditors
Jim Kaplan CIA CFE
 

More from Jim Kaplan CIA CFE (20)

mplementing and Auditing GDPR Series (10 of 10)
mplementing and Auditing GDPR Series (10 of 10) mplementing and Auditing GDPR Series (10 of 10)
mplementing and Auditing GDPR Series (10 of 10)
 
Implementing and Auditing GDPR Series (9 of 10)
Implementing and Auditing GDPR Series (9 of 10) Implementing and Auditing GDPR Series (9 of 10)
Implementing and Auditing GDPR Series (9 of 10)
 
How to detect fraud like a pro detective slides
How to detect fraud like a pro detective slides How to detect fraud like a pro detective slides
How to detect fraud like a pro detective slides
 
Implementing and Auditing GDPR Series (8 of 10)
Implementing and Auditing GDPR Series (8 of 10) Implementing and Auditing GDPR Series (8 of 10)
Implementing and Auditing GDPR Series (8 of 10)
 
How to get auditors performing basic analytics using excel
How to get auditors performing basic analytics using excel How to get auditors performing basic analytics using excel
How to get auditors performing basic analytics using excel
 
Tracking down outliers
Tracking down outliersTracking down outliers
Tracking down outliers
 
CyberSecurity Update Slides
CyberSecurity Update SlidesCyberSecurity Update Slides
CyberSecurity Update Slides
 
General Data Protection Regulation Webinar 6
General Data Protection Regulation Webinar 6 General Data Protection Regulation Webinar 6
General Data Protection Regulation Webinar 6
 
General Data Protection Regulation for Auditors 5 of 10
General Data Protection Regulation for Auditors 5 of 10General Data Protection Regulation for Auditors 5 of 10
General Data Protection Regulation for Auditors 5 of 10
 
Ethics and the Internal Auditor
Ethics and the Internal AuditorEthics and the Internal Auditor
Ethics and the Internal Auditor
 
GDPR Series Session 4
GDPR Series Session 4GDPR Series Session 4
GDPR Series Session 4
 
Cybersecurity Slides
Cybersecurity  SlidesCybersecurity  Slides
Cybersecurity Slides
 
Implementing and Auditing GDPR Series (3 of 10)
Implementing and Auditing GDPR Series (3 of 10) Implementing and Auditing GDPR Series (3 of 10)
Implementing and Auditing GDPR Series (3 of 10)
 
Ethics for internal auditors
Ethics for internal auditorsEthics for internal auditors
Ethics for internal auditors
 
Implementing and Auditing GDPR Series (2 of 10)
Implementing and Auditing GDPR Series (2 of 10) Implementing and Auditing GDPR Series (2 of 10)
Implementing and Auditing GDPR Series (2 of 10)
 
Implementing and Auditing General Data Protection Regulation
Implementing and Auditing General Data Protection Regulation Implementing and Auditing General Data Protection Regulation
Implementing and Auditing General Data Protection Regulation
 
Cybersecurity update 12
Cybersecurity update 12Cybersecurity update 12
Cybersecurity update 12
 
How to use ai apps to unleash the power of your audit program
How to use ai apps to unleash the power of your audit program How to use ai apps to unleash the power of your audit program
How to use ai apps to unleash the power of your audit program
 
Driving More Value With Automated Analytics
Driving More Value With Automated AnalyticsDriving More Value With Automated Analytics
Driving More Value With Automated Analytics
 
Ethics for Internal Auditors
Ethics for  Internal AuditorsEthics for  Internal Auditors
Ethics for Internal Auditors
 

Recently uploaded

Cree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBdCree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
creerey
 
Business Valuation Principles for Entrepreneurs
Business Valuation Principles for EntrepreneursBusiness Valuation Principles for Entrepreneurs
Business Valuation Principles for Entrepreneurs
Ben Wann
 
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s DholeraTata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
Avirahi City Dholera
 
Enterprise Excellence is Inclusive Excellence.pdf
Enterprise Excellence is Inclusive Excellence.pdfEnterprise Excellence is Inclusive Excellence.pdf
Enterprise Excellence is Inclusive Excellence.pdf
KaiNexus
 
ikea_woodgreen_petscharity_cat-alogue_digital.pdf
ikea_woodgreen_petscharity_cat-alogue_digital.pdfikea_woodgreen_petscharity_cat-alogue_digital.pdf
ikea_woodgreen_petscharity_cat-alogue_digital.pdf
agatadrynko
 
ikea_woodgreen_petscharity_dog-alogue_digital.pdf
ikea_woodgreen_petscharity_dog-alogue_digital.pdfikea_woodgreen_petscharity_dog-alogue_digital.pdf
ikea_woodgreen_petscharity_dog-alogue_digital.pdf
agatadrynko
 
The-McKinsey-7S-Framework. strategic management
The-McKinsey-7S-Framework. strategic managementThe-McKinsey-7S-Framework. strategic management
The-McKinsey-7S-Framework. strategic management
Bojamma2
 
Putting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptxPutting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptx
Cynthia Clay
 
Meas_Dylan_DMBS_PB1_2024-05XX_Revised.pdf
Meas_Dylan_DMBS_PB1_2024-05XX_Revised.pdfMeas_Dylan_DMBS_PB1_2024-05XX_Revised.pdf
Meas_Dylan_DMBS_PB1_2024-05XX_Revised.pdf
dylandmeas
 
Digital Transformation and IT Strategy Toolkit and Templates
Digital Transformation and IT Strategy Toolkit and TemplatesDigital Transformation and IT Strategy Toolkit and Templates
Digital Transformation and IT Strategy Toolkit and Templates
Aurelien Domont, MBA
 
The Parable of the Pipeline a book every new businessman or business student ...
The Parable of the Pipeline a book every new businessman or business student ...The Parable of the Pipeline a book every new businessman or business student ...
The Parable of the Pipeline a book every new businessman or business student ...
awaisafdar
 
Affordable Stationery Printing Services in Jaipur | Navpack n Print
Affordable Stationery Printing Services in Jaipur | Navpack n PrintAffordable Stationery Printing Services in Jaipur | Navpack n Print
Affordable Stationery Printing Services in Jaipur | Navpack n Print
Navpack & Print
 
Memorandum Of Association Constitution of Company.ppt
Memorandum Of Association Constitution of Company.pptMemorandum Of Association Constitution of Company.ppt
Memorandum Of Association Constitution of Company.ppt
seri bangash
 
ENTREPRENEURSHIP TRAINING.ppt for graduating class (1).ppt
ENTREPRENEURSHIP TRAINING.ppt for graduating class (1).pptENTREPRENEURSHIP TRAINING.ppt for graduating class (1).ppt
ENTREPRENEURSHIP TRAINING.ppt for graduating class (1).ppt
zechu97
 
April 2024 Nostalgia Products Newsletter
April 2024 Nostalgia Products NewsletterApril 2024 Nostalgia Products Newsletter
April 2024 Nostalgia Products Newsletter
NathanBaughman3
 
Introduction to Amazon company 111111111111
Introduction to Amazon company 111111111111Introduction to Amazon company 111111111111
Introduction to Amazon company 111111111111
zoyaansari11365
 
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdf
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdfSearch Disrupted Google’s Leaked Documents Rock the SEO World.pdf
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdf
Arihant Webtech Pvt. Ltd
 
VAT Registration Outlined In UAE: Benefits and Requirements
VAT Registration Outlined In UAE: Benefits and RequirementsVAT Registration Outlined In UAE: Benefits and Requirements
VAT Registration Outlined In UAE: Benefits and Requirements
uae taxgpt
 
The effects of customers service quality and online reviews on customer loyal...
The effects of customers service quality and online reviews on customer loyal...The effects of customers service quality and online reviews on customer loyal...
The effects of customers service quality and online reviews on customer loyal...
balatucanapplelovely
 
Premium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern BusinessesPremium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern Businesses
SynapseIndia
 

Recently uploaded (20)

Cree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBdCree_Rey_BrandIdentityKit.PDF_PersonalBd
Cree_Rey_BrandIdentityKit.PDF_PersonalBd
 
Business Valuation Principles for Entrepreneurs
Business Valuation Principles for EntrepreneursBusiness Valuation Principles for Entrepreneurs
Business Valuation Principles for Entrepreneurs
 
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s DholeraTata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
Tata Group Dials Taiwan for Its Chipmaking Ambition in Gujarat’s Dholera
 
Enterprise Excellence is Inclusive Excellence.pdf
Enterprise Excellence is Inclusive Excellence.pdfEnterprise Excellence is Inclusive Excellence.pdf
Enterprise Excellence is Inclusive Excellence.pdf
 
ikea_woodgreen_petscharity_cat-alogue_digital.pdf
ikea_woodgreen_petscharity_cat-alogue_digital.pdfikea_woodgreen_petscharity_cat-alogue_digital.pdf
ikea_woodgreen_petscharity_cat-alogue_digital.pdf
 
ikea_woodgreen_petscharity_dog-alogue_digital.pdf
ikea_woodgreen_petscharity_dog-alogue_digital.pdfikea_woodgreen_petscharity_dog-alogue_digital.pdf
ikea_woodgreen_petscharity_dog-alogue_digital.pdf
 
The-McKinsey-7S-Framework. strategic management
The-McKinsey-7S-Framework. strategic managementThe-McKinsey-7S-Framework. strategic management
The-McKinsey-7S-Framework. strategic management
 
Putting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptxPutting the SPARK into Virtual Training.pptx
Putting the SPARK into Virtual Training.pptx
 
Meas_Dylan_DMBS_PB1_2024-05XX_Revised.pdf
Meas_Dylan_DMBS_PB1_2024-05XX_Revised.pdfMeas_Dylan_DMBS_PB1_2024-05XX_Revised.pdf
Meas_Dylan_DMBS_PB1_2024-05XX_Revised.pdf
 
Digital Transformation and IT Strategy Toolkit and Templates
Digital Transformation and IT Strategy Toolkit and TemplatesDigital Transformation and IT Strategy Toolkit and Templates
Digital Transformation and IT Strategy Toolkit and Templates
 
The Parable of the Pipeline a book every new businessman or business student ...
The Parable of the Pipeline a book every new businessman or business student ...The Parable of the Pipeline a book every new businessman or business student ...
The Parable of the Pipeline a book every new businessman or business student ...
 
Affordable Stationery Printing Services in Jaipur | Navpack n Print
Affordable Stationery Printing Services in Jaipur | Navpack n PrintAffordable Stationery Printing Services in Jaipur | Navpack n Print
Affordable Stationery Printing Services in Jaipur | Navpack n Print
 
Memorandum Of Association Constitution of Company.ppt
Memorandum Of Association Constitution of Company.pptMemorandum Of Association Constitution of Company.ppt
Memorandum Of Association Constitution of Company.ppt
 
ENTREPRENEURSHIP TRAINING.ppt for graduating class (1).ppt
ENTREPRENEURSHIP TRAINING.ppt for graduating class (1).pptENTREPRENEURSHIP TRAINING.ppt for graduating class (1).ppt
ENTREPRENEURSHIP TRAINING.ppt for graduating class (1).ppt
 
April 2024 Nostalgia Products Newsletter
April 2024 Nostalgia Products NewsletterApril 2024 Nostalgia Products Newsletter
April 2024 Nostalgia Products Newsletter
 
Introduction to Amazon company 111111111111
Introduction to Amazon company 111111111111Introduction to Amazon company 111111111111
Introduction to Amazon company 111111111111
 
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdf
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdfSearch Disrupted Google’s Leaked Documents Rock the SEO World.pdf
Search Disrupted Google’s Leaked Documents Rock the SEO World.pdf
 
VAT Registration Outlined In UAE: Benefits and Requirements
VAT Registration Outlined In UAE: Benefits and RequirementsVAT Registration Outlined In UAE: Benefits and Requirements
VAT Registration Outlined In UAE: Benefits and Requirements
 
The effects of customers service quality and online reviews on customer loyal...
The effects of customers service quality and online reviews on customer loyal...The effects of customers service quality and online reviews on customer loyal...
The effects of customers service quality and online reviews on customer loyal...
 
Premium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern BusinessesPremium MEAN Stack Development Solutions for Modern Businesses
Premium MEAN Stack Development Solutions for Modern Businesses
 

What's the Difference between GRC and Combined Assurance?

  • 1. 29-8-2017 1 GRC and Combined Assurance: What’s the Difference? Toby DeRoche MBA, CIA, CCSA, CRMA, CICA, CFE Senior Market Development Consultant Housekeeping This webinar and its material are the property of AuditNet® and its Webinar partners. Unauthorized usage or recording of this webinar or any of its material is strictly forbidden.  If you logged in with another individual’s confirmation email you will not receive CPE as the confirmation login is linked to a specific individual  This Webinar is not eligible for viewing in a group setting. You must be logged in with your unique join link.  We are recording the webinar and you will be provided access to that recording after the webinar. Downloading or otherwise duplicating the webinar recording is expressly prohibited.  If you have indicated you would like CPE you must answer all the polling questions to receive CPE per NASBA.  If you meet the NASBA criteria for earning CPE you will receive a link via email to download your certificate. The official email for CPE will be issued via NoReply@gensend.io and it is important to white list this address. It is from this email that your CPE credit will be sent. There is a processing fee to have your CPE credit regenerated post event.  Submit questions via the chat box on your screen and we will answer them either during or at the conclusion.  Please complete the evaluation questionnaire to help us continuously improve our Webinars. Agile Auditing
  • 2. 29-8-2017 2 IMPORTANT INFORMATION REGARDING CPE!  SUBSCRIBERS/SITE LICENSE USERS - If you attend the Webinar and answer all the polling questions you will receive an email with the link to download your CPE certificate. The official email for CPE will be issued via NoReply@gensend.io and it is important to white list this address. It is from this email that your CPE credit will be sent. There is a processing fee to have your CPE credit regenerated post event.  NON-SUBSCRIBERS/NON-SITE LICENSE USERS - If you attend the Webinar and answer all the polling questions and requested CPE you must pay to receive your CPE. No exceptions!  We cannot manually generate a CPE certificate as these are handled by our 3rd party provider. We highly recommend that you work with your IT department to identify and correct any email delivery issues prior to attending the Webinar. Issues would include blocks or spam filters in your email system or a firewall that will redirect or not allow delivery of this email from Gensend.io  Anyone may register, attend and view the Webinar without fees if they opted out of receiving CPE.  We are not responsible for any connection, audio or other computer related issues. You must have pop-ups enabled on you computer otherwise you will not be able to answer the polling questions which occur approximately every 20 minutes. We suggest that if you have any pressing issues to see to that you do so immediately after a polling question. Agile Auditing The views expressed by the presenters do not necessarily represent the views, positions, or opinions of AuditNet® LLC. These materials, and the oral presentation accompanying them, are for educational purposes only and do not constitute accounting or legal advice or create an accountant-client relationship. While AuditNet® makes every effort to ensure information is accurate and complete, AuditNet® makes no representations, guarantees, or warranties as to the accuracy or completeness of the information provided via this presentation. AuditNet® specifically disclaims all liability for any claims or damages that may result from the information contained in this presentation, including any websites maintained by third parties and linked to the AuditNet® website. Any mention of commercial products is for information only; it does not imply recommendation or endorsement by AuditNet® LLC Agile Auditing
  • 3. 29-8-2017 3 Speaker Bio  Toby DeRoche MBA, CIA, CCSA, CRMA, CICA, CFE  Internal Audit with a Fortune 100 corporation for 4 years  Audit consultant for Wolters Kluwer for 7 years  Works with organizations that are looking for solutions to address their audit and compliance needs.  Assisted several hundred internal audit departments create, perform, and supervise financial, operational, and compliance audits to evaluate control frameworks, financial systems, and operating procedures. GRC vs Combined Assurance Presentation Overview With more organizations exploring the concept of Combined Assurance, there have been many questions about how this relates to GRC. In this presentation, we will explore both concepts and discuss the differences between Combined Assurance and GRC. GRC vs Combined Assurance
  • 4. 29-8-2017 4 Agenda Understand the concepts behind Combined Assurance and GRC Discuss pros and cons for both Combined Assurance and GRC GRC vs Combined Assurance POLLING QUESTION
  • 5. 29-8-2017 5 Assurance Providers Assurance Audit ERM SOX InfoSec EHS Legal Numerous departments within an organization contribute to governance GRC vs Combined Assurance Understanding Combined Assurance
  • 6. 29-8-2017 6 Combined Assurance  Prevent management from being overwhelmed by information and reports and succumbing to “audit fatigue”  Provide better organizational governance  Benefits:  One voice and taxonomy across all governance bodies and functions in the organization  Efficiency in collecting and reporting information  Common view of risks and issues across the organization  More effective governance, risk, and control oversight GRC vs Combined Assurance Coordination and Reliance IIA Standard 2050:  The chief audit executive should share information, coordinate activities, and consider relying upon the work of other internal and external assurance and consulting service providers to ensure proper coverage and minimize duplication of efforts. GRC vs Combined Assurance
  • 7. 29-8-2017 7 Coordination Approaches  Integrated planning  A comprehensive audit risk assessment process should consider:  Current work planned by other assurance providers that can be relied upon for audit coverage  Past results from work completed by other assurance providers  Integrated reporting  Reporting on risk coverage and audit coverage  Reporting on the control environment and issues found  Comprehensive issue trending by multiple categorizations GRC vs Combined Assurance Overlapping Activities GRC vs Combined Assurance Audit planning Risk based projects Issue categorization Board reporting
  • 8. 29-8-2017 8 Coordination Approaches  Integrated planning  A comprehensive audit risk assessment should consider:  EHS risks  InfoSec risks  Legal risks  Work planned by the other assurance providers can be relied upon for audit coverage for these areas  May need to use tools like a Risk Coverage Map GRC vs Combined Assurance Coordination Approaches  Integrated planning  CAE and other assurance groups should submit summaries of their respective planned audit activities, staffing plan, and budget to senior management and the board  Combining this presentation helps stakeholders better understand the scope of the work and planned audit coverage GRC vs Combined Assurance
  • 9. 29-8-2017 9 Coordination Approaches  Integrated reporting  Co-presenting internal audit and other audit results will enable management to focus and set priorities for the organization. Reduces “audit fatigue” GRC vs Combined Assurance Coordination Approaches  Audit activity alignment  Align the structure of risk and control assessment  Align documentation standards  Align project and board reporting structure  Align issue categorization GRC vs Combined Assurance
  • 10. 29-8-2017 10 POLLING QUESTION Leverage Technology  Look for systems to integrate the audit effort  Shared risk assessment tools  Shared control monitoring tools  Shared analytics tools  Shared documentation tools  Shared reporting tools for aggregation GRC vs Combined Assurance
  • 11. 29-8-2017 11 Understanding GRC What is GRC? GRC is the process of integrating governance efforts, risk management, and control implementation an organization puts in place to ensure success. GRC vs Combined Assurance
  • 12. 29-8-2017 12 What GRC is NOT?  GRC is not software  GRC solutions are not a magic bullet that creates governance  Good GRC software should open communication lines across departments GRC vs Combined Assurance GRC Goals  Reduced costs  Reduced redundant activities  Streamline operations  Capture better data more efficiently GRC vs Combined Assurance Copied form OCEG Website
  • 13. 29-8-2017 13 GRC Challenges  Hard to define  Hard to achieve integration  Hard to maintain consistency GRC vs Combined Assurance Copied form OCEG Website Leverage Technology  Look for systems to integrate the functions  Shared strategic objectives  Shared risk assessment tools  Shared control monitoring tools  Shared reporting tools for aggregation  Shared data for analytics  Allow integrated individuality GRC vs Combined Assurance
  • 14. 29-8-2017 14 POLLING QUESTION What’s the difference?  GRC is an alignment of business and risk functions  GRC is typically a management function  GRC should include internal audit  Combined Assurance is an alignment of audit functions  Combined Assurance is an audit function  Combined Assurance is lead by internal audit
  • 15. 29-8-2017 15 Questions? AuditNet® and cRisk Academy  If you would like forever access to this webinar recording  If you are watching the recording, and would like to obtain CPE credit for this webinar  Previous AuditNet® webinars are also available on-demand for CPE credit http://criskacademy.com http://ondemand.criskacademy.com Use coupon code: 50OFF for a discount on this webinar for one week Agile Auditing