Risk management internal audit: testing whether the risk register is a live control or a document that is updated before meetings

Auditing risk management is uncomfortable because the subject has no obvious records, and auditors often settle for confirming that a risk register exists. That test is useless: every organisation has one, and most are updated the week before the meeting that reviews them. The audit that finds something asks a harder question. Does the register describe the risks the business actually faces, does each entry have an owner who knows they own it, did the treatment happen, and can you point to a decision that went differently because of the register. If the answer to the last one is no, the register is documentation rather than management.

Test the register against reality, from both ends

Work outward from the register: pick three entries and find the evidence of the treatment they name. Then work inward from reality: take the last few incidents, complaints, near misses and unplanned costs, and look for them in the register beforehand. The second direction is where the finding is. A register that contains no entry resembling the thing that actually went wrong last quarter is not identifying risk, it is recording the risks that were easy to write down, and that is a systemic weakness rather than a documentation gap.

Ownership that the owner knows about

Every entry names an owner. The test is to ask that person, without warning, what they own and what they have done about it. The frequent answer, that they were not aware it was assigned to them, is a legitimate and useful finding because it explains why treatments do not progress. Ownership also needs authority: assigning a risk to someone who cannot authorise the spending or the change needed to treat it produces a permanently amber line that everyone learns to ignore.

Treatment, acceptance and the difference between them

A risk is treated, transferred, avoided or accepted, and acceptance is a legitimate answer when it is a decision rather than a default. The audit test is whether accepted risks were accepted by someone with the authority to accept them, on a date, with the reasoning recorded. Risks that drift into acceptance because nothing was done are the ones that surface later as a surprise to the board, and they are visible in an audit because the score never changes and no action has a completion date.

Review that changes something

The final test is the review cycle. Are risks reviewed at the frequency the procedure states, do scores move when circumstances move, and did any review lead to a changed decision. A register in which no score has changed in two years is either describing a static business or is not being reviewed, and the surrounding evidence, such as new products, new sites or new suppliers, usually settles which. This is the one part of the audit where the absence of change is itself the evidence.

Questions people ask about risk management internal audit

Is internal audit allowed to audit risk management if it also helps run it?

Not without compromising independence. If the audit function facilitates the risk process, someone else has to audit it, and that split needs to be visible in the audit programme rather than assumed.

What sample size works for a risk register audit?

Depth beats breadth. Three or four entries traced fully to their treatment evidence, plus a reverse test from recent incidents, finds far more than ticking every line for completeness.

Should risk appetite be audited?

If it is stated, yes, by testing whether decisions are consistent with it. If it is not stated, the finding is that acceptance decisions have no criterion, which is more useful than an argument about wording.

What does a good outcome look like?

A register that has recently changed for a reason you can trace to an event, owners who describe their entries without looking them up, and at least one decision that visibly went a different way because of it.

Sources

Related answers

Start Capanix ProKeep the findings, not the binder