SlideShare a Scribd company logo
1 of 22
Download to read offline
Why process is
critical to
minimizing risk.
James Goldsbury,
Senior Manager, PwC
Risk
Donna Outram,
Account Executive,
Promapp
Business Process
Mapping
Linking risks, controls and
assurance
February 2018
www.pwc.co.nz
PwC
Agenda
1. Todays presenter
2. What is a business process?
3. Risk and control and why does it matter?
4. Leveraging the four lines of defense
3
February 2018Business Process Mapping
PwC
Today’s Presenter
James Goldsbury – Senior Manager, PwC - Risk Assurance
4
February 2018Business Process Mapping
• James has over 9 years of experience advising on
risk and control within both NZ and USA.
• He has worked with large and small organisations
to assist them in documenting their business
processes as part of broader change / system
implementation projects
• He focusing on ensuring that risks within
business processes are fully understood and that
controls and assurance activities are embedded
within process map
• Most recently he has performed this for clients
implementing new ERP and payroll system and off-
shoring back office processes.
PwC
‘A set of linked activities that in combination provide a definable and
valuable output to either internal or external customers”
So, what is a business process?
5
Customer
inquiry or
sales activity
Prepare and
send quote
Update
customer
details – log
order
Check
product
availability
Deliver
product
Bill the
customer
Process
payment or
pass to
credit
control
Business processes comprise a set of sequential sub-processes or activities, with alternative paths
depending on certain conditions, performed to achieve a given objective or produce given outputs.
PwC
What is not a process?
A process is not a job description - instead of following a staff member through their job, a process
follows an input through the organisation
A process is not a departmental procedure manual - though the manual might provide useful
information for creating a process map
A process is not a department – even when it has the same name as a department
And, most importantly, a process is not a plan, program, or policy; processes should support plans,
programs, and policies
Most processes were not “designed” in the first place.
Like a foot path, somebody did it once and it was
eventually paved or “automated”…
6
PwC 7
February 2018Business Process Mapping
What is a risk?
A risk is….
“ The possibility of an act or
event occurring that would
have an adverse effect on
the organisation and
impact its ability to meet its
objectives
PwC
What is a control?
8
February 2018Business Process Mapping
”“ A control is an activity put
in place to mitigate a risk
PwC
So – a business process seems simple enough,
what are the challenges / pitfalls in documenting
them?
9
February 2018Business Process Mapping
• We see a high level of variation between organisations in the level of documentation
for their core business processes
• Documentation often captures ‘what is meant to happen’ – What, When, How?
But,
• Documentation often doesn’t capture the checks / balances (controls)
• Doesn’t consider what could go wrong, and what happens when things go wrong
Therefore, it doesn’t give management a clear view of the risk associated with the process.
PwC
So what – why does this matter?
10
PwC
So what – why does this matter?
11
Investigations into events similar to these often identify that:
• The process ‘as designed’ was not followed
• There was a lack of awareness of what the process was
• Management didn’t understand the risks associated with failure within the process
• There were insufficient controls embedded within the process to manage the risk
• Management didn’t understand what level of assurance they had (or needed)
over the controls
PwC
How can business process mapping protect you?
The Four Lines of Defence
12
PwC
Embedding the Four Lines of Defence within
Process Documentation
13
• RACM to support business process maps
• Controls mapped to risks
PwC
Embedding the Four Lines of Defence within
Process Documentation
14
Customer
inquiry or
sales
activity
Prepare
and send
quote
Update
customer
details –
log order
Check
product
availability
Deliver
product
Bill the
customer
Process
payment
or pass to
credit
control
Have we identified all the risks associated with the process?
For Example:
• Customer master file data is not accurate
• Sales orders are not completely and accurately recorded
• Cash receipts are not completely and accurately recorded
PwC
Embedding the Four Lines of Defence within
Process Documentation
15
Customer
inquiry or
sales
activity
Prepare
and send
quote
Update
customer
details –
log order
Check
product
availability
Deliver
product
Bill the
customer
Process
payment
or pass to
credit
control
What controls are in place to manage these risks?
For Example:
• All changes to customer master file are reviewed
• Sales orders must be authorised inline with delegations
• A reconciliation of cash receipts is performed on a daily basis
PwC
Embedding the Four Lines of Defence within
Process Documentation
16
Customer
inquiry or
sales
activity
Prepare
and send
quote
Update
customer
details –
log order
Check
product
availability
Deliver
product
Bill the
customer
Process
payment
or pass to
credit
control
How do we get comfort that these controls are in-place and operating?
PwC
Linking Process Objectives, Risks and Controls
17
Risk
Invalid, unauthorised
or otherwise
inaccurate payments
are made.
Key control
Vendor details entered into
FMIS are checked against the
application request form and
approved by a person
independent of the initial entry
prior to being finalised.
Not all invoices are
added to the FMIS.
Only staff within the Accounts
Payable team are able to load
new vendors. FMIS prevents
the user who entered customer
details from approving them.
A report is reviewed to identify
new vendors loaded into the
system that have yet to be
approved. Aged open invoices
are escalated for approval.
Assurance
Management self assertion
Internal Audit of Revenue
process.
External Audit
PwC
Leveraging Promapp to document risk and control
18
PwC
Leveraging Promapp to document risk and control
19
PwC
Final thoughts / key takeaways
20
1. Most organisations fail to understand and document the risks and controls within
their processes
2. This leads to a lack of understanding of the underlying risks associated within
business processes – potentially leaving an organisation at risk of significant damage
3. The four lines of defence provides a model by which management can ensure that the
risks associated within each process are appropriately managed and assured.
Thank you
This publication has been prepared for general guidance on matters of interest only, and does
not constitute professional advice. You should not act upon the information contained in this
publication without obtaining specific professional advice. No representation or warranty
(express or implied) is given as to the accuracy or completeness of the information contained
in this publication, and, to the extent permitted by law, [insert legal name of the PwC firm], its
members, employees and agents do not accept or assume any liability, responsibility or duty of
care for any consequences of you or anyone else acting, or refraining to act, in reliance on the
information contained in this publication or for any decision based on it.
© 2018 PwC. All rights reserved. In this document, “PwC” refers to [insert legal name of the
PwC firm] which is a member firm of PricewaterhouseCoopers International Limited, each
member firm of which is a separate legal entity.
Questions?
www.promapp.com

More Related Content

Similar to Why process is critical to minimizing risk

Spire Brief - Risk Consulting
Spire Brief - Risk ConsultingSpire Brief - Risk Consulting
Spire Brief - Risk Consulting
Prashant Jain
 
PwC Global PPM survey - the case for doing things differently
PwC Global PPM survey - the case for doing things differentlyPwC Global PPM survey - the case for doing things differently
PwC Global PPM survey - the case for doing things differently
Association for Project Management
 
Assessing risks and internal controls training
Assessing  risks and internal controls   trainingAssessing  risks and internal controls   training
Assessing risks and internal controls training
shifataraislam
 
Operational Risk Management - A Gateway to managing the risk profile of your...
Operational Risk Management -  A Gateway to managing the risk profile of your...Operational Risk Management -  A Gateway to managing the risk profile of your...
Operational Risk Management - A Gateway to managing the risk profile of your...
Eneni Oduwole
 

Similar to Why process is critical to minimizing risk (20)

Reducing regulatory capital by instigating risk management system and operati...
Reducing regulatory capital by instigating risk management system and operati...Reducing regulatory capital by instigating risk management system and operati...
Reducing regulatory capital by instigating risk management system and operati...
 
Reducing Regulatory Capital
Reducing Regulatory CapitalReducing Regulatory Capital
Reducing Regulatory Capital
 
How to Drive Value from Operational Risk Data - Part 2
How to Drive Value from Operational Risk Data - Part 2How to Drive Value from Operational Risk Data - Part 2
How to Drive Value from Operational Risk Data - Part 2
 
SAP Governance, Risk and Compliance (GRC)
SAP Governance, Risk and Compliance (GRC)SAP Governance, Risk and Compliance (GRC)
SAP Governance, Risk and Compliance (GRC)
 
Spire Brief - Risk Consulting
Spire Brief - Risk ConsultingSpire Brief - Risk Consulting
Spire Brief - Risk Consulting
 
Nextcard Case Essay
Nextcard Case EssayNextcard Case Essay
Nextcard Case Essay
 
conferences.aicpa.org
conferences.aicpa.orgconferences.aicpa.org
conferences.aicpa.org
 
The Business Of Law
The Business Of LawThe Business Of Law
The Business Of Law
 
10 reasons businesses fail!
10 reasons businesses fail!10 reasons businesses fail!
10 reasons businesses fail!
 
IIA Facilitated Risk Workshop
IIA Facilitated Risk Workshop IIA Facilitated Risk Workshop
IIA Facilitated Risk Workshop
 
Transform Data to Insight
Transform Data to InsightTransform Data to Insight
Transform Data to Insight
 
bu
bubu
bu
 
Building an Effective Customer Experience within the ETA Risk Guidelines
Building an Effective Customer Experience within the ETA Risk GuidelinesBuilding an Effective Customer Experience within the ETA Risk Guidelines
Building an Effective Customer Experience within the ETA Risk Guidelines
 
Enterprise governance risk_compliance_fcm slides
Enterprise governance risk_compliance_fcm slidesEnterprise governance risk_compliance_fcm slides
Enterprise governance risk_compliance_fcm slides
 
PwC Global PPM survey - the case for doing things differently
PwC Global PPM survey - the case for doing things differentlyPwC Global PPM survey - the case for doing things differently
PwC Global PPM survey - the case for doing things differently
 
110430 bcm presentation v0.1 mj
110430 bcm presentation v0.1 mj110430 bcm presentation v0.1 mj
110430 bcm presentation v0.1 mj
 
Assessing risks and internal controls training
Assessing  risks and internal controls   trainingAssessing  risks and internal controls   training
Assessing risks and internal controls training
 
Chris Gould - BCM case
Chris Gould - BCM caseChris Gould - BCM case
Chris Gould - BCM case
 
Operational Risk Management - A Gateway to managing the risk profile of your...
Operational Risk Management -  A Gateway to managing the risk profile of your...Operational Risk Management -  A Gateway to managing the risk profile of your...
Operational Risk Management - A Gateway to managing the risk profile of your...
 
2.0 The Course Forward
2.0 The Course Forward2.0 The Course Forward
2.0 The Course Forward
 

More from Promapp Solutions

More from Promapp Solutions (20)

Promapp webinar how to drive engagement in process
Promapp webinar how to drive engagement in processPromapp webinar how to drive engagement in process
Promapp webinar how to drive engagement in process
 
Promapp how to get sufficient resourcing
Promapp how to get sufficient resourcingPromapp how to get sufficient resourcing
Promapp how to get sufficient resourcing
 
How to get leadership buy in promapp
How to get leadership buy in promappHow to get leadership buy in promapp
How to get leadership buy in promapp
 
Marlborough District Council presentation
Marlborough District Council presentationMarlborough District Council presentation
Marlborough District Council presentation
 
Promapp CONNECT photos
Promapp CONNECT photosPromapp CONNECT photos
Promapp CONNECT photos
 
Promapp CONNECT 2018
Promapp CONNECT 2018Promapp CONNECT 2018
Promapp CONNECT 2018
 
Michigan State University presentation
Michigan State University presentationMichigan State University presentation
Michigan State University presentation
 
Matt Spears presentation
Matt Spears presentationMatt Spears presentation
Matt Spears presentation
 
RPA and BPM: Making the connection
RPA and BPM: Making the connectionRPA and BPM: Making the connection
RPA and BPM: Making the connection
 
Nurturing improvement with Ravensdown
Nurturing improvement with RavensdownNurturing improvement with Ravensdown
Nurturing improvement with Ravensdown
 
Queenstown Lakes District Council presentation
Queenstown Lakes District Council presentationQueenstown Lakes District Council presentation
Queenstown Lakes District Council presentation
 
Medifab presentation
Medifab presentationMedifab presentation
Medifab presentation
 
Central Coast Council presentation
Central Coast Council presentationCentral Coast Council presentation
Central Coast Council presentation
 
Bayside City Council presentation
Bayside City Council presentationBayside City Council presentation
Bayside City Council presentation
 
Affinity Education presentation
Affinity Education presentationAffinity Education presentation
Affinity Education presentation
 
CONNECT top takeaways
CONNECT top takeawaysCONNECT top takeaways
CONNECT top takeaways
 
Promapp CONNECT Global trends
Promapp CONNECT Global trends Promapp CONNECT Global trends
Promapp CONNECT Global trends
 
Promapp webinar Understand the role of process in digital transformation.
Promapp webinar Understand the role of process in digital transformation.Promapp webinar Understand the role of process in digital transformation.
Promapp webinar Understand the role of process in digital transformation.
 
Australian council drives process ownership and success
Australian council drives process ownership and successAustralian council drives process ownership and success
Australian council drives process ownership and success
 
A fresh approach to bpm drives engagement
A fresh approach to bpm drives engagementA fresh approach to bpm drives engagement
A fresh approach to bpm drives engagement
 

Recently uploaded

Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
lizamodels9
 
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
lizamodels9
 
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
lizamodels9
 
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Anamikakaur10
 
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
dlhescort
 
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
amitlee9823
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
Abortion pills in Kuwait Cytotec pills in Kuwait
 

Recently uploaded (20)

Falcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investorsFalcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investors
 
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
 
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
Russian Call Girls In Rajiv Chowk Gurgaon ❤️8448577510 ⊹Best Escorts Service ...
 
Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1
 
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLBAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
 
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
 
Falcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business GrowthFalcon Invoice Discounting: Empowering Your Business Growth
Falcon Invoice Discounting: Empowering Your Business Growth
 
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
👉Chandigarh Call Girls 👉9878799926👉Just Call👉Chandigarh Call Girl In Chandiga...
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
 
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best ServicesMysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
Mysore Call Girls 8617370543 WhatsApp Number 24x7 Best Services
 
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
Call Now ☎️🔝 9332606886🔝 Call Girls ❤ Service In Bhilwara Female Escorts Serv...
 
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
 
RSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors DataRSA Conference Exhibitor List 2024 - Exhibitors Data
RSA Conference Exhibitor List 2024 - Exhibitors Data
 
Business Model Canvas (BMC)- A new venture concept
Business Model Canvas (BMC)-  A new venture conceptBusiness Model Canvas (BMC)-  A new venture concept
Business Model Canvas (BMC)- A new venture concept
 
Falcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to ProsperityFalcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to Prosperity
 
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 98765-12871 Top Class Call Girl Service Available
 
Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024Marel Q1 2024 Investor Presentation from May 8, 2024
Marel Q1 2024 Investor Presentation from May 8, 2024
 
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Nelamangala Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
 
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabiunwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
unwanted pregnancy Kit [+918133066128] Abortion Pills IN Dubai UAE Abudhabi
 

Why process is critical to minimizing risk

  • 1. Why process is critical to minimizing risk. James Goldsbury, Senior Manager, PwC Risk Donna Outram, Account Executive, Promapp
  • 2. Business Process Mapping Linking risks, controls and assurance February 2018 www.pwc.co.nz
  • 3. PwC Agenda 1. Todays presenter 2. What is a business process? 3. Risk and control and why does it matter? 4. Leveraging the four lines of defense 3 February 2018Business Process Mapping
  • 4. PwC Today’s Presenter James Goldsbury – Senior Manager, PwC - Risk Assurance 4 February 2018Business Process Mapping • James has over 9 years of experience advising on risk and control within both NZ and USA. • He has worked with large and small organisations to assist them in documenting their business processes as part of broader change / system implementation projects • He focusing on ensuring that risks within business processes are fully understood and that controls and assurance activities are embedded within process map • Most recently he has performed this for clients implementing new ERP and payroll system and off- shoring back office processes.
  • 5. PwC ‘A set of linked activities that in combination provide a definable and valuable output to either internal or external customers” So, what is a business process? 5 Customer inquiry or sales activity Prepare and send quote Update customer details – log order Check product availability Deliver product Bill the customer Process payment or pass to credit control Business processes comprise a set of sequential sub-processes or activities, with alternative paths depending on certain conditions, performed to achieve a given objective or produce given outputs.
  • 6. PwC What is not a process? A process is not a job description - instead of following a staff member through their job, a process follows an input through the organisation A process is not a departmental procedure manual - though the manual might provide useful information for creating a process map A process is not a department – even when it has the same name as a department And, most importantly, a process is not a plan, program, or policy; processes should support plans, programs, and policies Most processes were not “designed” in the first place. Like a foot path, somebody did it once and it was eventually paved or “automated”… 6
  • 7. PwC 7 February 2018Business Process Mapping What is a risk? A risk is…. “ The possibility of an act or event occurring that would have an adverse effect on the organisation and impact its ability to meet its objectives
  • 8. PwC What is a control? 8 February 2018Business Process Mapping ”“ A control is an activity put in place to mitigate a risk
  • 9. PwC So – a business process seems simple enough, what are the challenges / pitfalls in documenting them? 9 February 2018Business Process Mapping • We see a high level of variation between organisations in the level of documentation for their core business processes • Documentation often captures ‘what is meant to happen’ – What, When, How? But, • Documentation often doesn’t capture the checks / balances (controls) • Doesn’t consider what could go wrong, and what happens when things go wrong Therefore, it doesn’t give management a clear view of the risk associated with the process.
  • 10. PwC So what – why does this matter? 10
  • 11. PwC So what – why does this matter? 11 Investigations into events similar to these often identify that: • The process ‘as designed’ was not followed • There was a lack of awareness of what the process was • Management didn’t understand the risks associated with failure within the process • There were insufficient controls embedded within the process to manage the risk • Management didn’t understand what level of assurance they had (or needed) over the controls
  • 12. PwC How can business process mapping protect you? The Four Lines of Defence 12
  • 13. PwC Embedding the Four Lines of Defence within Process Documentation 13 • RACM to support business process maps • Controls mapped to risks
  • 14. PwC Embedding the Four Lines of Defence within Process Documentation 14 Customer inquiry or sales activity Prepare and send quote Update customer details – log order Check product availability Deliver product Bill the customer Process payment or pass to credit control Have we identified all the risks associated with the process? For Example: • Customer master file data is not accurate • Sales orders are not completely and accurately recorded • Cash receipts are not completely and accurately recorded
  • 15. PwC Embedding the Four Lines of Defence within Process Documentation 15 Customer inquiry or sales activity Prepare and send quote Update customer details – log order Check product availability Deliver product Bill the customer Process payment or pass to credit control What controls are in place to manage these risks? For Example: • All changes to customer master file are reviewed • Sales orders must be authorised inline with delegations • A reconciliation of cash receipts is performed on a daily basis
  • 16. PwC Embedding the Four Lines of Defence within Process Documentation 16 Customer inquiry or sales activity Prepare and send quote Update customer details – log order Check product availability Deliver product Bill the customer Process payment or pass to credit control How do we get comfort that these controls are in-place and operating?
  • 17. PwC Linking Process Objectives, Risks and Controls 17 Risk Invalid, unauthorised or otherwise inaccurate payments are made. Key control Vendor details entered into FMIS are checked against the application request form and approved by a person independent of the initial entry prior to being finalised. Not all invoices are added to the FMIS. Only staff within the Accounts Payable team are able to load new vendors. FMIS prevents the user who entered customer details from approving them. A report is reviewed to identify new vendors loaded into the system that have yet to be approved. Aged open invoices are escalated for approval. Assurance Management self assertion Internal Audit of Revenue process. External Audit
  • 18. PwC Leveraging Promapp to document risk and control 18
  • 19. PwC Leveraging Promapp to document risk and control 19
  • 20. PwC Final thoughts / key takeaways 20 1. Most organisations fail to understand and document the risks and controls within their processes 2. This leads to a lack of understanding of the underlying risks associated within business processes – potentially leaving an organisation at risk of significant damage 3. The four lines of defence provides a model by which management can ensure that the risks associated within each process are appropriately managed and assured.
  • 21. Thank you This publication has been prepared for general guidance on matters of interest only, and does not constitute professional advice. You should not act upon the information contained in this publication without obtaining specific professional advice. No representation or warranty (express or implied) is given as to the accuracy or completeness of the information contained in this publication, and, to the extent permitted by law, [insert legal name of the PwC firm], its members, employees and agents do not accept or assume any liability, responsibility or duty of care for any consequences of you or anyone else acting, or refraining to act, in reliance on the information contained in this publication or for any decision based on it. © 2018 PwC. All rights reserved. In this document, “PwC” refers to [insert legal name of the PwC firm] which is a member firm of PricewaterhouseCoopers International Limited, each member firm of which is a separate legal entity.