Audit & Risk

Managing risk is more about culture than process

Sandy Weill, the former CEO of Citi Group, called last week for US banks that were “too big to fail” to be broken up. He joined a growing chorus of regulators, politicians, academics and even other bankers worldwide who see the industry’s future in two distinct categories: high-risk, high-reward investment banking and safer retail banking.

in CEO Blog.

Article Image

But neither ring-fencing, as proposed by the UK’s Independent Commission on Banking last year, or full separation, which happened in the US in the 1930s under the Glass-Steagall Act, will meet their objectives unless risk management – and the cultural tone that enables it – are improved.

Attempts to improve risk management and internal control are evident. Since the financial crisis five years ago, the recruitment market for risk management and compliance staff has been relatively buoyant. But is it enough simply to create a bigger risk and control capability, or does the philosophy behind the management of risk need to be questioned?

The results of a recent survey reported in the Financial Times suggest that risk management in the largest banks and insurance firms is at least 20 years behind that of their peers in the aviation industry. Its conclusions are based on the reactions of those banks and insurers to scandals including Libor-fixing, money-laundering and IT failures. According to the study, their response was to install more “box-ticking” processes and ways to link staff bonuses to risk performance. While this is acknowledged to be a natural move, the survey’s authors contend that it is immature response, which encourages non-reporting by managers. It means that assurance functions and, ultimately, boards and risk and audit committees, are unlikely to know much about what’s actually happening.

The message here is that how the process is managed is as important as the process itself. And the “how” reflects the prevailing culture.

The causes of most incidents making the front pages are fundamentally cultural. Internal auditors in the financial sector can help boards to become more proactive in creating the right risk management culture. In future, their role must enable them not only to evaluate the quality and scope of controls through their work with managers, but also to encourage continuous improvement in how risk is perceived and managed from the top down through their engagement with boards. They must also maintain the regulators’ confidence through an effective dialogue. Internal audit needs to strike the right balance in its relationships with this tripartite group of stakeholders in order to gain enough influence to ensure that risk is managed appropriately over the long term.

So, whatever partitions are put in place to recognise the very different appetites for risk in retail and investment banking, internal audit is key to their success in creating and maintaining the right attitude to risk and rebuilding trust in the industry.

Ian Peters, CEO at the IIA.

The IIA: find out more

Visit the main IIA site

Jobs

Senior Auditor

Bedford
£30,851 - £33,661, Part-time, 18.5 hours per week, Quote ref: P000563

Careers advice

Moving up

Two former heads of internal audit explain what the role taught them and how it helped to prepare them for a seat on the board.

Every secondment counts

If you are offered a temporary work placement with another employer – perhaps even in a different function from internal audit – you’d be well advised to jump at the chance. So says Chris Monk, whose organisation, Uniac, and its staff have long reaped the benefits of secondments.

The inbetweeners

Historically a stopgap for internal auditors searching for a more permanent role, interim management is now more likely to be the consequence of a positive and actively chosen career path. Why has it become such a growth area? Barclay Simpson's Andy Whyte explains.

Training & Development

Challenging conversations are habit-forming

“Any challenging conversation needs to be handled with care because people need to be handled with care. Forget this at your peril,” says Adrian Thompson, chief internal auditor, Norfolk County Council.

Q&A

Our technical helpline provides valuable advice to members on a host of professional issues. Here are some of the questions you’ve submitted recently.

Erratum: Audit & Risk

In the November/December 2012 edition of Audit & Risk magazine, an error appeared in the listings of the IIA members who were successful in the June 2012 exams.

Tools

You asked us

Our technical helpline provides valuable advice to members on a host of professional issues. Here are some of the questions you’ve submitted recently.

A world of knowledge

The IIA is always working to produce guidance aimed at helping internal auditors to stay at the cutting edge of best practice. Pauline Scott, technical coordinator, reports on the technical team’s recent work to support members.

EQA FAQs

The institute’s technical manager, Chris Baker CMIIA, explains the value of an external quality assessment, what happens during the review process – and how best to prepare for one.