Norman Marks, CRMA, CPA, was a chief audit executive and chief risk officer at major global corporations for more than 20 years. The views expressed in this blog are his personal views and may not represent those of The IIA.

Will the Updated COSO Internal Control Framework Create Problems for the External Auditors?

Posted on Jun 18, 2013

The talk around the updated Internal Control–Integrated Framework has been around how it will impact management teams. For example, have a look at a blurb on the AICPA’s Insights page: 3 Ways the New COSO Framework May Affect Your Business.  

continue reading...

NACD Provides Some Excellent Advice From a Prominent Director on Risk Oversight

Posted on May 31, 2013

I just listened to an excellent video presentation from NACD featuring Reatha Clark King talking about risk oversight by the board. I recommend this to boards, especially board chairs, governance committee members, as well as members of the audit and risk committees. It is also useful for executives, general counsel, and practitioners.

continue reading...

An Important Reminder From COSO

Posted on May 30, 2013

The updated COSO Internal Control–Integrated Framework can be used as a reminder that the root cause of most corporate problems comes either from issues relating to integrity or competence. In other words, the root cause is usually people.

continue reading...

Is Risk Management Part of Internal Control or Is It the Other Way Around?

Posted on May 27, 2013

There is a very clear relationship between internal control and risk management. Basically, internal controls provide reasonable assurance that risks to the achievement of organizational objectives are at acceptable levels. (The organizational objective when it comes to financial reporting is to provide financial satements that are free of material omission or error.) 

continue reading...

Excellent Advice on Risk Oversight

Posted on May 20, 2013

The National Association of Corporate Directors (NACD) has established an advisory council on risk oversight and published a report on its second meeting that contains notable comments. It is available athttp://www.nacdonline.org/Resources/Article.cfm?ItemNumber=6762

continue reading...

Deloitte Takes a Highly Intelligent Approach to Risk Management

Posted on May 3, 2013

Deloitte’s Risk Intelligence White Papers are a set of thought leadership that I have strongly recommended in the past — and continue to do so today. 

continue reading...

Gartner Points to Failures to Obtain Value From Technology

Posted on Apr 29, 2013

Gartner’s 2013 Global CIO Study points to issues I have previously aired: namely a failure to obtain full advantage from new and disruptive technology. This should be of concern to board, all executives, leaders of IT, and risk and assurance professionals.

continue reading...

The Important Risks That Are Overlooked but Should Come First

Posted on Apr 23, 2013

Survey after survey talk about the top 10 risks or such. For example, look at the 2013 Global Risk Management Survey by Aon. It raises some good points, including a refreshing observation that companies are paying more attention to risk management these days.

 

But I think this focus on a top 10, or even a top 50, misses some massive risks that are faced (IMHO) by a majority of organizations and, even if they are recognized, are often accepted instead of corrected. They need to be corrected if the organization is to survive let alone thrive.
continue reading...

Technology is Too Important to Leave to IT

Posted on Apr 18, 2013

 I have been reading an October 2012 publication by McKinsey, Evaluating technology on the boardroom  agenda (registration required – and well worth it). The title of this post is drawn from the piece. The full and important quote is:

Businesses are becoming increasingly digital and it’s not just a matter of process automation or resource-planning systems. Technology trends such as big data, cloud computing, mobility, and social media are giving rise to new marketing and operational capabilities. Indeed, technology has become too embedded in the fabric of the business—and too critical for competitive performance—to be left to the IT function alone.”
continue reading...

Does It Make Sense to Discuss GRC?

Posted on Apr 14, 2013

My good friend, Michael Rasmussen, is perhaps the father of the term GRC and styles himself as the GRC Pundit. He has an excellent web site that I wholeheartedly recommend and one of his latest posts is on the subject of 2013 GRC Drivers and Trends.

continue reading...