【正文】
?? Develops risk management strategy ?? Promotes risk awareness ?? Provides risk management framework and reporting Operational Risk Typical Functions ?? Hands on risk management (including risk transfer) Internal Audit ?? Promotes risk awareness ?? Proactive risk advice and support ?? Centre of excellence on risk management and control ?? Facilitates improvements in risk management and control ?? Provides assurance ?? Provides independent opinions ?? Risk based audits ?? Focuses audits on areas of risk Integrating IA and operational risk Advantages: ?? Link risk profiling / reporting with audit process ?? Not promise objectivity ?? Easier to recruit and retain high quality staff ?? Avoid unnecessary duplication ?? Overlap between risk based audit and operational risk ?? Risk based audit prevention rather than cure Integrating IA and operational risk Disadvantages: ?? Cultural nonacceptance ?? Customer confusion ?? Priorities for resources ?? Handson risk management ?? Audit independence Risk reporting and corporate governance ‘ The directors should, at least annually, conduct a review at of the effectiveness of the group’s system of internal control and should report to shareholders that they have done so. The review should cover all controls, including financial, operational and pliance controls and risk management’ The Combined Code Principles of good governance and code of best practice Turnbull Some key points ?? Prime responsibility of management ?? Profit is the