Menú principal

Raising the Awareness of the SAIs on the Enterprise Risk Management (ERM) of the auditees and using the ERM approach in developing risk-based annual audit plans

Background and objectives

Background

Today, as technology develops and institutions focus on being more innovative, not only do the risks heighten, but it also becomes normal to live with prolonged uncertainties. This difficult pandemic process we are living in has made us understand better than ever how important risk management is.

In recent years, enterprise risk management has increasingly attracted the attention of organizations. In this context, organizations are increasingly making use of frameworks related to enterprise risk management such as COSO's Enterprise Risk Management Framework-2017, COBIT 2019, ISO 31000 (2018) to improve their performance in an uncertain world. International risk management frameworks aim to identify the risks faced by entities in the public or private sector, including cyber-risks, and to manage these risks to be able to reach their objectives and carry out their activities efficiently.

As a result of this trend, some credit rating companies like S&P have invented new products for analyzing and evaluating companies’ ERM to let their customers “shift from a “cost/benefit” line of thought to a “risk/reward” approach.” This is just one of the proofs that risk management is an increasingly attractive implementation adopted by many entities in this highly complex world.

The issue of how this trend, which has been rising in the last few years, will be reflected in the field of audit is very important for the SAIs to remain relevant. As we all know, audits are implemented by taking risks into account. However, enterprise risks should not be limited just to the execution of audits; they should also be taken into account when making annual audit plans or choosing among alternative audit topics. There are various approaches on how to do this, and some SAIs, including the Turkish Court of Audits (TCA), have specific approaches and practices in this regard. Moreover, ERM evaluation, conducted stand-alone or in conjunction with an audit, might be another element of external audit practices on which the TCA has been working for a few years.

With this project, it is primarily planned to perform a due diligence on determining the maturity level of the risk management of the audited institutions and understanding the level of knowledge of the SAIs on the enterprise risks of the audited institutions. Following this analysis, it is considered to form a basis for building up methodologies to develop risk based- annual audit plans and evaluate the risk management of auditees. 

 

Objective

The aim of this Project Group is to determine the level of awareness of SAIs on risk management of auditees and to lay the groundwork for the development of methodology for developing a risk based- annual audit plans and evaluating risk management of auditees by good understanding of the auditees’ risk management structure. 

In this regard, the project is planned to be run in two phases. In the first phase, a survey is going to be designed to understand risk management structures of the auditees. After applying the survey to selected sector/entities, the results will be compiled and then reported to the EUROSAI community with the aim of raising awareness among SAIs on the ERM and forming a base for further works regarding reflection of the ERM in the annual audit plans and evaluation of auditees’ ERM. 

This project is unique as it is innovative, stipulates further developments such as developing methodologies in different areas, and it aims to capture a rising trend all over the world by SAIs to be able stay relevant.

Documentation

Filters

Reset filters
Search filters
Apply filters
Close
Category
Category
Reset filters
Search filters
Apply filters
Reset filters
Search filters
Apply filters
Close
Reset filters
Search filters
Apply filters
Showing results 1 to 3 of 3.
  • Project Group Documents
    2026 January 09

    ToR EUROSAI Project Group on "Raising the Awareness of the SAIs on the Enterprise Risk Management (ERM) of the auditees and using the ERM approach in developing risk-based annual audit plans"

    ToR EUROSAI Project Group on "Raising the Awareness of the SAIs on the Enterprise Risk Management (ERM) of the auditees and using the ERM approach in developing risk-based annual audit plans"

    Go to detail
  • Project Group Documents
    2026 January 09

    Project Closure

    Project Closure of the EUROSAI Project Group “Raising the Awareness of the SAIs on the Enterprise Risk Management (ERM) of the auditees and using the ERM approach in developing risk-based annual audit plans”.

    Go to detail
  • Project Group Documents
    2026 January 09

    Survey Assessment Report

    Survey Assessment Report

    Go to detail
Showing results 1 to 3 of 3.
METAINFO
Project Group