Risk assessment in risk-oriented audits by internal audit units | Vestnik Tomskogo gosudarstvennogo universiteta. Ekonomika – Tomsk State University Journal of Economics. 2022. № 57. DOI: 10.17223/19988648/57/9

Risk assessment in risk-oriented audits by internal audit units

The article combines the principles of risk management with the objectives of internal audit, defines and clarifies the concepts of risk management. Undoubtedly, external audit has a great influence on the formation of internal audit. This influence has both positive qualities, such as the use of the experience of highly qualified specialists from external audit, and a negative impact, due to the fact that external audit is primarily aimed at the confirmation of the financial statements of an organization, but in general does not consider business processes implemented in organizations, their effectiveness and adequacy to achieve organizations’ objectives, risks inherent in business processes. The article identifies the most important reason preventing the implementation of risk management principles in the Russian internal audit practice. The correlation of risk elements, which are sufficient for risk identification and risk level assessment within internal audit using a risk-oriented approach, has been disclosed. Based on the analysis of the essence of each risk element (risk source, event, consequence), their isolated role in assessing the likelihood of risk realization and the significance of the consequences, determining the necessity of risk management measures, has been determined. Using practical experience, the authors propose an algorithm of risk level assessment carried out within internal audit implementation. Possible qualitative and quantitative characteristics of determination of risk probability and materiality are considered. As part of the determination of the average likelihood of negative consequences’ occurrence, specific criteria of event likelihood assessment based on the history of similar events’ occurrence and the forecast assessment of likelihood of similar events’ occurrence are identified. Examples of determining the likelihood for each event within a group of events and the likelihood of occurrence of consequences in several groups of events are presented. Criteria for assessing the likelihood of risk realization are determined by establishing the set of events, whose simultaneous occurrence realizes the risk. Examples of financial and non-financial consequences and criteria for their assessment are given. In order to determine the elements of risk during internal audits, the essence of analytical procedures performed with the use of deductive and inductive methods is disclosed. At present, large Russian companies are taking certain steps to implement the principles of Industry 4.0 in their business processes. This trend has not passed unnoticed for internal audit; for example, principles of continuous audit and automated analysis of databases are being implemented. However, the implementation often ignores the main condition that this article discusses; without it implementation attempts will only lead to an irrational use of organizational resources. Contribution of the authors: the authors contributed equally to this article. The authors declare no conflicts of interests.

Download file
Counter downloads: 24

Keywords

risk source, risk event, consequences of risk implementation, significant risks, extrapolation, risk level

Authors

NameOrganizationE-mail
Zemtsov Taras A.Gazprom Transgaz Tomskzetaan@mail.ru
Sorokin Maksim A.NalogInfopaiytchne@mail.ru
Всего: 2

References

ГОСТР 51897-2011. Руководство ИСО 73:2009. Национальный стандарт Российской Федерации. Менеджмент риска. Термины и определения: утв. приказом Росстандарта от 16.11.2011 № 548-ст // Доступ из справ.-правовой системы «Консультант+».
ГОСТ Р 58771-2019. Национальный стандарт Российской Федерации. Менеджмент риска. Технологии оценки риска: утв. приказом Росстандарта от 17.12.2019 № 1405-ст // Доступ из справ.-правовой системы «Консультант+».
ГОСТ Р ИСО 31000-2019. Национальный стандарт Российской Федерации. Менеджмент риска. Принципы и руководство: утв. приказом Росстандарта от 10.12.2019 № 1379-ст // Доступ из справ.-правовой системы «Консультант+».
Дролова Е.Ю., Зайкова И.В., Мезенцева Э.А. Проблемы перевода англоязычных международных стандартов менеджмента качества // Вестник Иркутского государственного технического университета. 2015. С. 255-259.
О введении в действие международных стандартов аудита на территории Российской Федерации и о признании утратившими силу некоторых приказов Министерства финансов Российской Федерации: приказ Минфина России от 09.01.2019 № 2н // Доступ из справ.-правовой системы «Консультант+».
Организация и осуществление экономическим субъектом внутреннего контроля совершаемых фактов хозяйственной жизни, ведения бухгалтерского учета и составления бухгалтерской (финансовой) отчетности: Информация Минфина России № ПЗ-11/2013 // Доступ из справ.-правовой системы «Консультант+».
Об утверждении требований к организации системы внутреннего контроля, а также форм и форматов документов, представляемых организациями при раскрытии информации о системе внутреннего контроля: утв. приказом ФНС России от 25.05.2021 № ЕД-7-23/518@ // Доступ из справ.-правовой системы «Консультант+».
Сорокин М.А., Земцов Т.А. Риск-ориентированный аудит : учеб.-метод. пособие. Томск : КФУ ИЭМ НИ ТГУ, 2019. 80 с.
Земцов Т.А., Сорокин М.А. Планирование внутренних риск ориентированных проверок // Аудит. 2019. № 5. С. 19-24.
 Risk assessment in risk-oriented audits by internal audit units | Vestnik Tomskogo gosudarstvennogo universiteta. Ekonomika – Tomsk State University Journal of Economics. 2022. № 57. DOI: 10.17223/19988648/57/9

Risk assessment in risk-oriented audits by internal audit units | Vestnik Tomskogo gosudarstvennogo universiteta. Ekonomika – Tomsk State University Journal of Economics. 2022. № 57. DOI: 10.17223/19988648/57/9

Download full-text version
Counter downloads: 329