Risk and control monitoring
The risks to an organization are ever-changing, and so is the risk profile. Risks encountered a year before may not be relevant anymore, and the controls recently implemented for the latest risk may have already become outdated. A risk practitioner should continuously monitor, benchmark, and improve the control environment to meet organizational objectives. The monitoring of controls can be done through self-assessments or independent third-party audits. Exceptions to controls should be reported, followed up, and addressed with corrective actions. In the following section, we will review some techniques that the risk practitioner can implement with the help of risk owners for effective risk and control monitoring.
Types of control assessments
Before we jump into the techniques for control assessment, let’s briefly review what this term means. Control assessment is the process of evaluating and examining the effectiveness and adequacy of internal...