The seminar can be held online on the official International Business Academy platform. On completion of the training you will be given a link to the recording, which will be available for one month.
*dates are subject to additional confirmation
excluding VAT
* VAT of 16% will be added to the invoice
Programme goal:
Training managers and specialists in the principles of developing, implementing and continually improving an internal control system (ICS) in accordance with the international COSO IC IF-2013 framework. The programme aims to build practical skills in integrating the ICS into business processes, increasing the transparency of corporate governance and strengthening the risk management culture.
Objectives:
Skills developed:
Criteria for participation in the programme:
Target audience and the value of participation for each group:
Getting acquainted/ Introduction/ Course overview/ Participants introduce themselves
I. Component – Control environment
Introduction
Terminology on risks and the ICS. Brief information about COSO, the Enron case and the Big 5
What is new in COSO IC IF:2013
The relationship between COSO ERM & COSO IC IF
Risk management and internal control
Where is the boundary between risk management and the ICS? ICS objectives
Control environment
COSO IC IF:2013 principles 1-5. Explanations, examples
The Corporate Governance Code. HR policy. Organisational structure
Responsibility and authority, common mistakes in developing Regulations on units
Distribution of ICS functions in the company. ICS Policy. ICS Regulation
The relationship of the «control environment» component with ISO 9001 – how to build this ICS block correctly using the tools of ISO 9001
II. Component – Risk assessment
Risk assessment
COSO IC IF:2013 principles 6-9. Explanations, examples
The relationship of the «risk assessment» component with ISO 31000 – how to carry out this ICS block correctly using the tools of ISO 31000
«Myths» in the field of risk management and the ICS, and «debunking them»
System 1 and System 2 and the concept of «mental traps»
Setting objectives, defining the mission, vision and values
BSC – the Balanced Scorecard
Decision trees – as a tool for defining Strategy
Risk-based analysis of the company's strategy and KPIs
Risk identification
Mental traps at the risk identification stage
Group game on mental traps
Defining risk criteria
Risk appetite. Examples of calculating risk appetite
Examples of defining financial and non-financial indicators of the consequences of risk materialising
Identifying risk using methods from ISO 31000
Risk identification methods:
Risk analysis
Mental traps at the risk analysis stage. Group game on mental traps
Risk analysis. Examples of risk analysis and compiling the Risk Register
Risk evaluation
Mental traps at the risk evaluation stage
Group game on mental traps
Different options for evaluating risk (qualitative and quantitative)
Assessing and analysing the influence of risks on the decision being made
Ways of visualising the results of evaluation (Risk maps)
Practical group work: determining the level of risk
III. Component – Control activities
Control activities
COSO IC IF:2013 principles 10-12. Explanations, examples
Types and selection of control procedures
The organisational level of control procedures
Classification of types of control. Types and means of control
Timing of control. Characteristics of effective controls
The risk and control matrix. Examples of control procedures
Typical mistakes in control procedures
The relationship of the «control activities» component with ISO 27001 – how to carry out this ICS block correctly using the tools of ISO 27001
Developing control procedures in accordance with ISO 37001 and ISO 37301
IV. Component – Information and communication
Information and communication
COSO IC IF:2013 principles 13-15. Explanations, examples
ICS components and examples of communication channels for them
Information quality requirements and examples of them: accessibility; correctness; relevance; security; retainability; sufficiency; timeliness; reliability; verifiability
External and internal communication about objectives and responsibility for internal controls
Common mistakes and best practices
V. Component – Monitoring activities
Monitoring activities
COSO IC IF:2013 principles 16-17. Explanations, examples
Methodology and criteria for evaluating the ICS
The three lines of defence: problems and ways of solving them
Testing control procedures. Key risk indicators
Barriers to establishing the ICS in the company and ways of removing them
Ways of improving the risk management culture – recommendations and examples
Conducting internal audits of the ICS in accordance with ISO 9001, ISO 27001, ISO 37001 and ISO 37301
Questions
Course completion