SBM · Advanced Level

Risk Management and Internal Control

Comprehensive enterprise risk management. ERM frameworks: COSO ERM (2017 Update) — five components: Governance and Culture; Strategy and Objective-Setting; Performance; Review and Revision; Information, Communication, and Reporting. Categories of risk: STRATEGIC (business model viability, competitive position, M&A integration); OPERATIONAL (process failures, supply chain, IT, fraud, people); FINANCIAL (currency, interest rate, credit, liquidity, capital structure); COMPLIANCE/LEGAL (regulatory, litigation); REPUTATIONAL (stakeholder confidence, brand damage); CYBER (data breaches, ransomware, system disruption — increasingly material). Risk identification techniques: brainstorming, scenario analysis, risk registers, risk workshops, external benchmarking. Risk assessment: likelihood × impact matrices; quantitative analysis (Value at Risk, Expected Loss, sensitivity); qualitative scoring. Risk response strategies: AVOID (eliminate); REDUCE (mitigate); TRANSFER (insurance, contracts, hedging); ACCEPT (within risk appetite); EXPLOIT (positive risks/opportunities). Financial risk management — DERIVATIVES: FUTURES (exchange-traded; standardised; daily margining; mark-to-market); FORWARDS (OTC; customisable; counterparty risk); OPTIONS (right not obligation; premium paid; calls and puts); SWAPS (exchange of cash flows — interest rate swaps; currency swaps); FRAs (Forward Rate Agreements — single-period interest rate hedging). Worked examples for each instrument: FX hedging via forward, futures, money market, options; interest rate hedging via FRA, futures, swap, options (caps, floors, collars). Risk appetite and risk culture: tone at the top; embedding risk awareness; risk culture indicators. Internal control frameworks: COSO Internal Control (2013); ISO 31000; UK Corporate Governance Code requirements (board responsibility for internal controls and risk management; annual effectiveness review). Internal audit role: independence; reporting to audit committee; risk-based audit plan; coordination with external audit; assurance on key controls.

65 min read

Learning Objectives

  • Apply COSO ERM 2017 framework to enterprise risk management
  • Identify and categorise strategic, operational, financial, compliance, reputational, and cyber risks
  • Apply risk assessment techniques (likelihood × impact, VaR, sensitivity)
  • Apply risk response strategies (avoid, reduce, transfer, accept, exploit)
  • Use financial derivatives for hedging — futures, forwards, options, swaps, FRAs
  • Construct hedging strategies for currency and interest rate risk with worked examples
  • Discuss risk appetite, risk culture, and tone at the top
  • Apply internal control frameworks (COSO IC 2013, ISO 31000) and discuss internal audit role

Enterprise Risk Management (ERM) Frameworks

Enterprise Risk Management (ERM) is the comprehensive approach to identifying, assessing, managing, and monitoring risks across the organisation in pursuit of strategic objectives.

COSO ERM (2017 Update — "Enterprise Risk Management: Integrating with Strategy and Performance"):

Five components, 20 principles. Replaced the 2004 cube model with a more strategy-integrated framework.

1. GOVERNANCE AND CULTURE:

  • Exercises board oversight
  • Establishes operating structures
  • Defines desired culture
  • Demonstrates commitment to core values
  • Attracts, develops, retains capable individuals

2. STRATEGY AND OBJECTIVE-SETTING:

  • Analyses business context
  • Defines RISK APPETITE (level of risk willing to accept)
  • Evaluates alternative strategies
  • Formulates business objectives aligned with strategy

3. PERFORMANCE:

  • Identifies risk
  • Assesses severity of risk (likelihood × impact)
  • Prioritises risk
  • Implements risk responses
  • Develops portfolio view of risks

4. REVIEW AND REVISION:

  • Assesses substantial change
  • Reviews risk and performance
  • Pursues improvement in ERM

5. INFORMATION, COMMUNICATION, AND REPORTING:

  • Leverages information and technology
  • Communicates risk information
  • Reports on risk, culture, and performance

ISO 31000 Risk Management Guidelines:

  • International standard providing principles and guidelines
  • Risk management process: scope/context, risk assessment (identify, analyse, evaluate), risk treatment, monitoring, communication
  • Less prescriptive than COSO; broader applicability
  • Often used alongside COSO

UK Corporate Governance Code requirements:

  • Board responsibility for risk management and internal controls
  • Determine NATURE AND EXTENT of principal risks willing to take
  • Maintain SOUND RISK MANAGEMENT AND INTERNAL CONTROL SYSTEMS
  • ANNUAL REVIEW of effectiveness
  • Reporting in annual report on:
    • Principal risks and how managed/mitigated
    • Risk management and internal control systems effectiveness
    • VIABILITY STATEMENT (longer-term, typically 3-5 years)
    • GOING CONCERN STATEMENT (12 months)

Three Lines Model (formerly "Three Lines of Defence"):

Updated by IIA in 2020 — moves from "lines of defence" to broader value-creating model:

  1. FIRST LINE: management — owns and manages risks; daily operations; primary risk-takers
  2. SECOND LINE: risk management, compliance, controls — provides expertise and challenge; supports first line; sets policies/frameworks
  3. THIRD LINE: internal audit — independent assurance to governing body

Plus:

  • EXTERNAL ASSURANCE PROVIDERS (auditors, regulators)
  • GOVERNING BODY (board) — accountability for organisational outcomes

Categories of risk:

1. STRATEGIC risk:

  • Risks affecting business model viability
  • Competitive position
  • M&A integration risk
  • Major capital investment decisions
  • Macroeconomic, geopolitical changes
  • Disruptive technology / business models

2. OPERATIONAL risk:

  • Process failures
  • Supply chain disruption (Covid-19 lessons)
  • IT failures and outages
  • Fraud (employee, vendor, customer)
  • People risks (key person, talent retention)
  • Health and safety
  • Quality issues

3. FINANCIAL risk:

  • CURRENCY (transaction, translation, economic exposure)
  • INTEREST RATE
  • CREDIT (customers, counterparties)
  • LIQUIDITY (short-term funding)
  • CAPITAL STRUCTURE (gearing, refinancing)
  • Commodity price (for raw materials/energy)

4. COMPLIANCE/LEGAL risk:

  • Regulatory breaches and fines
  • Litigation
  • Data protection (GDPR)
  • Anti-bribery and corruption (UK Bribery Act 2010)
  • Money laundering (POCA 2002, MLR 2017)
  • Industry-specific regulation

5. REPUTATIONAL risk:

  • Loss of stakeholder confidence (customers, investors, employees)
  • Brand damage
  • Often consequence of other risks materialising
  • Social media amplification (rapid spread)
  • Difficult to insure or quantify
  • ESG-related reputational risk increasing

6. CYBER risk (increasingly material):

  • Data breaches (personal/sensitive information)
  • Ransomware attacks
  • System disruption / denial of service
  • Industrial espionage
  • Insider threats
  • Supply chain cyber risk (third-party vulnerabilities)
  • Major incidents: Colonial Pipeline (2021); SolarWinds (2020); MOVEit (2023)
  • UK consequences: ICO fines (up to 4% of global turnover under GDPR); reputational; operational

7. CLIMATE/ESG risk:

  • PHYSICAL risk (storms, flooding, sea level rise)
  • TRANSITION risk (policy, technology, market shifts)
  • LIABILITY risk (climate litigation)
  • IFRS S2 disclosure requirements
  • UK SECR mandatory for large companies

Risk Assessment and Response

Risk identification techniques:

  • BRAINSTORMING workshops with cross-functional teams
  • SCENARIO ANALYSIS (what could go wrong?)
  • RISK REGISTERS — systematic catalogue of identified risks
  • EXTERNAL BENCHMARKING (industry risk reports, peer companies)
  • HISTORICAL ANALYSIS (past incidents, near-misses)
  • PROCESS MAPPING (identify control weaknesses)
  • EXPERT JUDGEMENT (industry specialists)
  • EMPLOYEE FEEDBACK / whistleblowing channels

Risk assessment — likelihood × impact:

Low impactMedium impactHigh impactCritical impact
High likelihood Medium High VERY HIGH EXTREME
Medium likelihood Low-Medium Medium High VERY HIGH
Low likelihood Low Low-Medium Medium High
Very low likelihood Low Low Low-Medium Medium

Quantitative risk measures:

  • Expected Loss = Probability × Impact (£ amount)
  • Value at Risk (VaR): maximum loss expected over a defined period at given confidence level (e.g., 95% confidence over 1 day)
  • VaR widely used in financial services; criticised for understating tail risk (extreme events beyond confidence level)
  • Conditional VaR (CVaR / Expected Shortfall): average loss given that VaR exceeded — captures tail better
  • Sensitivity analysis: how does outcome change with single variable
  • Scenario analysis: multiple variables changing together
  • Stress testing: extreme but plausible scenarios
  • Monte Carlo simulation: probability distribution of outcomes

Inherent vs residual risk:

  • Inherent risk: BEFORE any controls or mitigations
  • Residual risk: AFTER controls and mitigations
  • Difference = effectiveness of controls
  • Risk appetite typically expressed in terms of residual risk

Risk response strategies (the "4 Ts" or "5 Ts"):

1. AVOID / TERMINATE:

  • Eliminate the risk by not undertaking the activity
  • Withdraw from market, exit business line, decline transaction
  • Most appropriate for: high-impact, high-likelihood risks beyond capability
  • Cost: forgone opportunity

2. REDUCE / TREAT:

  • Mitigate likelihood and/or impact
  • Internal controls; redundancies; diversification
  • Most common approach
  • Examples: backup systems, training, security measures, supply chain diversification

3. TRANSFER / SHARE:

  • Pass risk to third party
  • INSURANCE (most common transfer mechanism)
  • HEDGING via derivatives (financial risks)
  • Contracts (force majeure, indemnities, warranties)
  • Outsourcing (operational risk to provider)
  • Joint ventures (share risk)
  • Note: counterparty risk replaces original risk

4. ACCEPT / TOLERATE:

  • Accept risk as cost of doing business
  • Within risk appetite
  • Often appropriate for low-impact or low-likelihood risks
  • Reserves/contingencies for accepted risks

5. EXPLOIT / EMBRACE (positive risks):

  • For UPSIDE risks (opportunities)
  • Take advantage of favourable circumstances
  • Examples: new market entry, M&A opportunity, technology adoption
  • "Risk-reward" rather than "risk-loss"

Risk appetite and risk tolerance:

  • Risk appetite: amount and type of risk the organisation is WILLING to take to achieve objectives
  • Risk tolerance: acceptable level of variation around risk appetite (the "boundaries")
  • Risk capacity: maximum risk the organisation could absorb without failing

Examples of risk appetite statements:

  • "Conservative on financial risks (gearing < 2.0x net debt/EBITDA); willing to accept moderate operational risk in pursuit of strategic objectives; zero tolerance for unethical behaviour or major safety incidents"
  • Tested against actual exposures via dashboards and reports

Risk culture:

  • "How we do things around here" relating to risk
  • Critical to ERM effectiveness — most risk management failures linked to culture, not framework gaps
  • Indicators of strong risk culture:
    • Tone at the top (board, CEO modelling behaviour)
    • Open communication about risk (no shoot-the-messenger)
    • Risk considered in all decisions
    • Whistleblowing channels effective
    • Aligned incentives (no excessive risk-taking through bonuses)
    • Risk specialists respected and influential
    • Lessons learned from incidents

Currency Risk Hedging — Forwards, Futures, Money Market, Options

Currency risk types:

  • Transaction risk: currency movements affecting specific cash flows from contracts (most commonly hedged)
  • Translation risk: foreign subsidiaries' financial statements translated to parent currency (consolidation impact)
  • Economic risk: long-term competitive position affected by currency movements

Natural hedges (preferred where possible):

  • Match foreign currency revenues with foreign currency costs (operating in same currency)
  • Borrow in foreign currency where assets/cash flows in that currency
  • Multi-currency invoicing
  • Pricing flexibility in foreign markets

FOUR main hedging instruments for transaction risk:

1. FORWARD CONTRACT (most common):

  • OTC contract — agreement to exchange currencies at pre-agreed rate at future date
  • CUSTOMISABLE (any amount, any date)
  • NO upfront cost (but creates obligation)
  • Forward rate determined by interest rate parity (covered interest rate parity)
  • OBLIGATION to transact — cannot benefit from favourable movements
  • Counterparty risk (typically bank — usually low)

Worked example — forward contract:

UK exporter sells £1m of goods to US customer; payment $1.3m due in 3 months. Spot $1.30/£; 3-month forward $1.31/£.

  • Without hedge: receives $1.3m in 3 months. If spot at maturity is $1.40/£: receives £928,571 (loss vs expected £1m)
  • With forward hedge: lock in $1.31/£. Receive $1.3m → £992,366. Effectively guaranteed regardless of future spot
  • Trade-off: certainty vs potential gain if dollar strengthens

2. CURRENCY FUTURES:

  • EXCHANGE-TRADED standardised contracts
  • Fixed contract sizes, expiry dates, currencies
  • DAILY MARGIN settlement (mark-to-market)
  • Counterparty risk minimal (clearing house)
  • NO custom amounts — basis risk if exposure doesn't exactly match contract size
  • Position can be CLOSED out before maturity

Comparison: forward vs futures:

ForwardFutures
Market OTC (over-the-counter) Exchange-traded
Customisation Any amount, date, currency Standardised
Counterparty risk Bank (typically minor) Clearing house (minimal)
Margin requirements Generally none Initial + daily variation margin
Liquidity Less liquid; harder to unwind Liquid market; can close out anytime
Cost Spread embedded in rate Commission + spread

3. MONEY MARKET HEDGE:

Replicates forward contract using deposits and loans in different currencies.

For RECEIPT in foreign currency (e.g., UK exporter receiving $):

  1. Borrow $ today (PV of $ to be received)
  2. Convert $ borrowed to £ at spot rate
  3. Place £ on deposit (earn interest)
  4. At maturity: foreign currency received used to repay $ loan
  5. £ deposit + interest = guaranteed £ receipt

For PAYMENT in foreign currency (e.g., UK importer paying $):

  1. Calculate PV of $ payment due
  2. Convert £ to $ at spot rate
  3. Place $ on deposit (earns interest)
  4. At maturity: $ deposit matures, used to make $ payment
  5. £ used at outset = guaranteed £ cost

Worked example — money market hedge for $1.3m receipt in 3 months:

  • Spot: $1.30/£; UK 3-month rate: 5%; US 3-month rate: 4%
  • PV of $1.3m: $1.3m / (1 + 0.04 × 3/12) = $1.287m
  • Borrow $1.287m today; convert to £: $1.287m / 1.30 = £990,000
  • Deposit £990,000 at UK 5%: matures at £990,000 × (1 + 0.05 × 3/12) = £1,002,375
  • At maturity: receive $1.3m from customer; repay $ loan ($1.287m × 1.01 = $1.3m)
  • Net £ guaranteed: £1,002,375

Compare to forward hedge: £992,366. Money market hedge slightly better here due to interest rate differential — but should be approximately equal (covered interest rate parity).

4. CURRENCY OPTIONS:

  • RIGHT but not OBLIGATION to exchange currencies at strike rate
  • PREMIUM paid upfront
  • CALL option: right to BUY foreign currency at strike (importer hedge)
  • PUT option: right to SELL foreign currency at strike (exporter hedge)
  • EXERCISE only if favourable; else let expire (protected with downside; participate in upside)
  • Insurance-like product

Currency options — when valuable:

  • UNCERTAIN underlying transaction (may not occur — bid for tender, contingent contract)
  • Want to PARTICIPATE in favourable movements
  • Higher cost than forward (premium paid)
  • Common for capital projects with uncertain outcomes

Worked example — currency options for $1.3m receipt:

  • UK exporter buys put option on $/£ at strike $1.30, expiry 3 months
  • Premium: 1% of contract value = £8,000
  • Scenario A: spot at maturity $1.40/£ (£ stronger; $ weaker)
    • Exercise put: receive £1.0m at $1.30 strike
    • Net (after premium): £1.0m − £8,000 = £992,000
  • Scenario B: spot at maturity $1.20/£ (£ weaker; $ stronger)
    • Don't exercise put — sell at favourable spot
    • Receive: $1.3m / $1.20 = £1,083,333
    • Net: £1,083,333 − £8,000 premium = £1,075,333

Compared to forward hedge (£992,366 in both scenarios): option costs more in unfavourable scenario but participates in favourable.

Currency swap:

  • Exchange of principal and/or interest payments in different currencies
  • Often used for long-term hedging or arbitrage between markets
  • Example: UK company needs $ funding; US company needs £ funding — they swap interest/principal
  • Exploits comparative advantages in respective home markets

Interest Rate Risk Hedging — FRAs, Futures, Swaps, Options

Interest rate risk:

  • Borrowers face risk of rates RISING (variable rate debt)
  • Lenders/depositors face risk of rates FALLING
  • Major impact on financial costs and asset values

Gap analysis:

  • Identify mismatches between rate-sensitive assets and liabilities
  • Net position determines exposure direction
  • Used by banks extensively (ALM — asset-liability management)

1. FORWARD RATE AGREEMENT (FRA):

  • OTC agreement fixing the INTEREST RATE for a future deposit/loan
  • SINGLE PERIOD only (e.g., 3 months starting in 6 months)
  • NO actual lending/borrowing — cash settlement only
  • Notional principal × rate differential × period = settlement amount

FRA notation:

  • "3v9 FRA" = 3-month period starting in 3 months (3-month rate covering months 4-9... actually means: starts in 3 months, ends in 9 months — so 6-month rate)
  • Common form: "X v Y FRA" where X = start month, Y = end month, period = Y − X
  • "3v6" = 3-month rate, starting in 3 months
  • "6v12" = 6-month rate, starting in 6 months

FRA worked example:

Company plans to borrow £10m for 3 months in 6 months' time. Worried about rates rising. Buys 6v9 FRA at 5%.

  • If rate at start of borrowing is 6%: bank pays company (1% × £10m × 3/12) = £25,000
  • Company effectively pays 5% on actual loan
  • If rate is 4%: company pays bank £25,000; effectively pays 5%
  • Actual loan rate locked at 5%

2. INTEREST RATE FUTURES:

  • EXCHANGE-TRADED futures on short-term interest rates (e.g., 3-month sterling)
  • Standardised contracts, daily margining
  • Quoted as 100 minus interest rate (so price RISES as rates FALL)
  • BUYER expects rates to fall (price up); SELLER expects rates to rise (price down)
  • Borrower hedge: SELL futures (profit if rates rise)
  • Investor/lender hedge: BUY futures (profit if rates fall)

3. INTEREST RATE SWAPS (IRS):

  • OTC agreement to exchange streams of interest payments
  • "Plain vanilla": exchange FIXED rate for FLOATING rate (or vice versa)
  • SAME currency, same notional principal — only interest exchanged
  • Multi-period — typically 2-30 years
  • Most common interest rate hedging instrument

IRS uses:

  • Convert floating-rate debt to fixed (lock in cost — most common)
  • Convert fixed-rate debt to floating (benefit if rates fall)
  • Asset-liability matching for banks
  • Comparative advantage exploitation

IRS worked example:

Company has £100m floating-rate debt at SONIA + 2%. Worried about rates rising. Enters IRS:

  • Pay 5% fixed; receive SONIA (over notional £100m, 5 years)
  • Net effect: floating-rate debt becomes effectively fixed
    • Pay SONIA + 2% on debt
    • Pay 5% fixed under swap; receive SONIA under swap
    • Net: 2% (margin) + 5% (fixed) = 7% effective fixed cost
  • If SONIA rises to 6%: still pay 7% effective vs 8% if hadn't swapped
  • If SONIA falls to 3%: pay 7% effective vs 5% if hadn't swapped (lose benefit but had certainty)

Comparative advantage in swaps:

  • One party has comparative advantage in fixed market; other in floating
  • Each borrows in their advantageous market; swap with each other
  • Both achieve their preferred rate type at lower cost than direct
  • Common rationale (though heavily disputed in academic literature)

4. INTEREST RATE OPTIONS:

(a) Caps:

  • SET MAXIMUM interest rate on borrowing
  • Series of options on interest rates ("caplets")
  • If market rate exceeds cap rate: option pays out
  • If below cap: rate floats below cap rate
  • Ideal for borrowers wanting protection but participation in low rates

(b) Floors:

  • SET MINIMUM interest rate
  • Used by depositors/investors
  • If market rate falls below floor: option pays out

(c) Collars (combined cap + floor):

  • Buy cap (limit max) + sell floor (limit min)
  • Premium of sold floor offsets cost of bought cap (often zero-cost collar)
  • Limits both upside and downside
  • Borrower's rate stays within "collar" range

Worked example — interest rate cap:

Company has £50m floating-rate debt at SONIA + 1.5%. Buys 5-year cap at 5% strike. Premium: £500,000 upfront.

  • If SONIA rises to 6% in year 3: cap pays out 1% × £50m = £500k for that year
  • Effective rate: SONIA + 1.5% on debt = 7.5%; less cap payout = 6.5%
  • If SONIA stays at 4%: cap doesn't pay; rate is 5.5%
  • Premium of £500k amortised across years
  • Maximum rate: 5% + 1.5% margin = 6.5%

Hedging strategy choice:

ConcernLikely choice
Single future cash flow; certainty desired; cost-conscious Forward contract
Liquid market; flexible position management Futures
Customisable amounts; bank relationship OTC forward / FRA
Long-term interest rate exposure Interest rate swap
Want protection AND participation in upside Options (premium paid)
Cost-conscious option; willing to limit upside Collar
Uncertain transaction (may not occur) Options (let expire if unneeded)

Hedge effectiveness considerations:

  • BASIS RISK: when hedging instrument doesn't perfectly track underlying (different maturity, different reference rate)
  • OVER-HEDGING / UNDER-HEDGING: amount mismatch
  • TIMING MISMATCHES: hedge expiry vs exposure
  • COUNTERPARTY RISK: especially for OTC products
  • HEDGE ACCOUNTING (IFRS 9): documentation and effectiveness testing required for hedge accounting treatment

Hedging policy framework:

  • Defined hedge ratios (e.g., 50-80% of forecast exposures)
  • Time horizons (typically 12-24 months for transactions)
  • Approved instruments (sometimes excluding speculative instruments)
  • Authorisation levels
  • Reporting to board/audit committee
  • Counterparty diversification

Internal Control Frameworks

Internal control = process designed by management to provide reasonable assurance about:

  1. Effectiveness and efficiency of operations
  2. Reliability of financial reporting
  3. Compliance with laws and regulations

COSO Internal Control — Integrated Framework (2013):

Five components, 17 principles. The reference framework for internal control globally.

1. CONTROL ENVIRONMENT:

  • Demonstrates commitment to integrity and ethical values
  • Board oversight; independence
  • Establishes structures, reporting lines, authorities
  • Demonstrates commitment to competence
  • Holds individuals accountable

2. RISK ASSESSMENT:

  • Specifies suitable objectives
  • Identifies and analyses risks to achievement
  • Considers fraud risk
  • Identifies significant changes affecting internal control

3. CONTROL ACTIVITIES:

  • Selects and develops control activities
  • Selects and develops general IT controls
  • Deploys through policies and procedures
  • Includes: authorisations, segregation of duties, reconciliations, physical controls, performance reviews

4. INFORMATION AND COMMUNICATION:

  • Uses relevant, quality information
  • Communicates internally
  • Communicates externally

5. MONITORING ACTIVITIES:

  • Conducts ongoing and/or separate evaluations
  • Communicates internal control deficiencies

Types of controls:

By timing:

  • PREVENTIVE: stop errors/fraud before occurrence (authorisations, access controls)
  • DETECTIVE: identify after occurrence (reconciliations, audits, review)
  • CORRECTIVE: remedy after detection (backup procedures, error correction)

By execution:

  • MANUAL: human action required
  • AUTOMATED: built into systems (often more reliable)
  • HYBRID: combination

By level:

  • ENTITY-LEVEL: pervasive controls (governance, ethics, IT general)
  • PROCESS-LEVEL: specific to business processes (revenue, payables, payroll)
  • TRANSACTION-LEVEL: specific transaction controls

Key control activities:

  • Segregation of duties: divide responsibilities (initiator, approver, recorder, custodian)
  • Authorisations: appropriate approvals at right level
  • Reconciliations: regular comparison (bank accounts, control accounts)
  • Physical controls: secure access to assets
  • Independent verification: review by separate person
  • Performance reviews: variances investigation
  • IT general controls: change management, access, backup, business continuity
  • IT application controls: input validation, processing controls, output controls

UK Corporate Governance Code (2024):

  • BOARD RESPONSIBILITY for risk management and internal control systems
  • MAINTAIN sound systems
  • ANNUAL REVIEW of effectiveness
  • REPORTING in annual report on:
    • Principal risks
    • How risks managed/mitigated
    • Effectiveness of controls
    • 2024 update introduces new MATERIAL CONTROLS DECLARATION

Material Controls Declaration (UK Corporate Governance Code 2024 — effective 1 January 2026):

  • BOARD must declare effectiveness of MATERIAL CONTROLS
  • "Material controls" = controls over MATERIAL RISKS and MATERIAL DISCLOSURES
  • UK move toward US SOX-equivalent (but less prescriptive)
  • Significant compliance challenge for premium-listed companies

UK SOX (delayed/uncertain):

  • Originally proposed in 2021 White Paper "Restoring Trust in Audit and Corporate Governance"
  • Would require CEO/CFO certifications of effectiveness of internal controls over financial reporting (ICFR)
  • Government has SCALED BACK proposals — Material Controls Declaration is partial substitute
  • Audit Reform Bill timing uncertain

INTERNAL AUDIT — third line:

Role and value:

  • INDEPENDENT, OBJECTIVE assurance and consulting
  • Designed to add value and improve operations
  • Helps organisation accomplish objectives by evaluating and improving:
    • Risk management processes
    • Control effectiveness
    • Governance processes

Independence and reporting:

  • FUNCTIONALLY reports to AUDIT COMMITTEE (board level)
  • ADMINISTRATIVELY may report to CEO or CFO
  • Chief Audit Executive (CAE) — head of internal audit
  • Charter approved by audit committee
  • Cannot be involved in operations they audit

Internal audit activities:

  • Risk-based annual plan
  • Operational audits (process effectiveness)
  • Financial audits (controls over reporting)
  • Compliance audits (regulatory adherence)
  • IT audits (controls, security, projects)
  • Investigations (fraud, allegations)
  • Consulting engagements (advisory; non-assurance)

Coordination with external audit:

  • External auditor may use internal audit work (ISA 610)
  • Subject to assessment of objectivity and competence
  • Reduces external audit time and cost
  • Internal audit cannot replace external audit

Outsourced vs in-house internal audit:

  • OUTSOURCED: specialist firm; expertise; flexibility; some independence concerns
  • IN-HOUSE: deeper organisational knowledge; consistent presence; cost (smaller companies)
  • CO-SOURCED: hybrid — common in larger organisations (in-house core team + specialist external for specific reviews)

IIA International Standards (Standards for Professional Practice of Internal Auditing):

  • Attribute Standards: requirements for IA activity (independence, competence)
  • Performance Standards: nature of internal audit activities (planning, performing, reporting)
  • Quality Assurance and Improvement Programme (QAIP) required
  • External Quality Assessment every 5 years

Common control deficiencies (from FRC reports):

  • Segregation of duties weaknesses (especially smaller entities)
  • IT general controls (access management, change controls)
  • Bank reconciliation not done timely
  • Inadequate review of journal entries
  • Weak controls over expense reimbursement
  • Inadequate controls in subsidiaries (group context)
  • Cyber security gaps
  • Spreadsheet controls (key reports built in Excel)

Examiner Focus

SBM risk management questions typically combine ERM framework discussion with quantitative hedging calculations. Show ability to: (1) categorise risks systematically (strategic, operational, financial, compliance, reputational, cyber); (2) apply COSO ERM components; (3) calculate hedging outcomes for different instruments; (4) recommend strategies with rationale; (5) consider implementation issues.

Common Pitfall

Common error: confusing futures (exchange-traded, standardised, margined) with forwards (OTC, customisable, no margin). Both lock rates but with different mechanics. For exam: forwards preferred for one-off custom amounts; futures for ongoing positions in liquid markets.

Study Tip

Money market hedge replicates forward via deposits and loans. For RECEIPT: borrow foreign currency now (PV); convert to home; deposit home. For PAYMENT: convert home now; deposit foreign; pays at maturity. Should give similar result to forward (covered interest rate parity). Useful when forwards unavailable or comparing rates.

Examiner Focus

IRS converts floating to fixed (most common use). Pay fixed; receive floating. Net effect: floating debt + fixed swap rate − floating swap = effectively fixed rate. Convert £20m at SONIA + 2% via swap paying 5% fixed: effective rate = 5% + 2% margin = 7%.

Watch Out

Currency options vs forwards: options have UPFRONT PREMIUM (1-3% typical) but flexibility to let expire if favourable. Forward locks rate at no upfront cost but obliges transaction. For CONFIRMED transactions: forward usually better. For UNCERTAIN transactions (tender bids, contingent contracts): options preserve choice.

Study Tip

COSO ERM 2017 five components: Governance and Culture; Strategy and Objective-Setting (includes risk appetite); Performance (identify, assess, prioritise, respond); Review and Revision; Information, Communication, and Reporting. UK Corporate Governance Code 2024 introduces Material Controls Declaration (effective 2026) — UK move toward SOX-equivalent.

Study Tip

Three Lines Model (IIA 2020 update): First line — management owns risks. Second line — risk/compliance/controls support. Third line — internal audit independent assurance. Internal audit functionally reports to AUDIT COMMITTEE (board level), administratively to CEO/CFO. Cannot replace external audit. Risk-based annual plan; charter approved by audit committee.

Written Practice

Risk Management and Internal Control: Applied Requirement

Prepare a short advisory section that combines analysis, conclusion, and next actions.

32 mins · 18 marks

A client has asked for a concise integrated advisory note for a finance director on risk management and internal control. Use the key rules, calculations, risks, and professional judgement from this topic to structure your answer.

Answer Prompts

  • Identify the issue and explain why it matters in the scenario.
  • Apply the relevant technical rule, calculation, or framework.
  • State the commercial, ethical, tax, reporting, or assurance implication.
  • Conclude with a clear recommendation or exam-ready judgement.

Marking Focus

  • Application to facts rather than textbook recall
  • Clear structure and answer-first communication
  • Balanced judgement where there is uncertainty
  • Commercially sensible conclusion

Key Definitions

Enterprise Risk Management (ERM)

Comprehensive approach to identifying, assessing, managing, and monitoring risks across the organisation in pursuit of strategic objectives. Integrates with strategy and performance.

COSO ERM (2017 Update)

Reference framework for ERM. Five components: (1) Governance and Culture; (2) Strategy and Objective-Setting; (3) Performance; (4) Review and Revision; (5) Information, Communication, and Reporting. 20 principles. Strategy-integrated approach (replaced 2004 cube model).

Three Lines Model

IIA framework (updated 2020). FIRST LINE: management — owns/manages risks. SECOND LINE: risk, compliance, controls — provides expertise/challenge. THIRD LINE: internal audit — independent assurance. Plus external assurance and governing body. Replaced "three lines of defence".

Risk appetite

Amount and type of risk the organisation is WILLING to take to achieve objectives. Distinct from RISK TOLERANCE (acceptable variation around appetite) and RISK CAPACITY (maximum risk before failure). Set by board; cascades through organisation.

Inherent vs residual risk

INHERENT: risk before controls/mitigations. RESIDUAL: risk after controls/mitigations. Difference = effectiveness of controls. Risk appetite typically expressed in residual terms.

Value at Risk (VaR)

Maximum loss expected over defined period at given confidence level (e.g., 95% confidence over 1 day). Widely used in financial services. Criticised for understating tail risk. CVaR (Conditional VaR / Expected Shortfall) captures tail better.

4 Ts of risk response

TERMINATE/AVOID (eliminate by not undertaking); TREAT/REDUCE (mitigate likelihood/impact); TRANSFER/SHARE (insurance, contracts, hedging); TOLERATE/ACCEPT (within appetite). Plus EXPLOIT for upside risks (opportunities).

Forward contract

OTC agreement to exchange currencies (or commodities) at pre-agreed rate at future date. CUSTOMISABLE; no upfront cost; obligation; counterparty risk (typically bank). Most common FX hedging instrument for transaction risk.

Currency futures

EXCHANGE-TRADED standardised contracts. Fixed contract sizes, expiry dates. DAILY MARGINING. Counterparty risk minimal (clearing house). Less custom than forwards but more liquid. Position can be closed before maturity.

Money market hedge

Replicates forward using deposits and loans. For receipt: borrow foreign currency now (PV); convert to home currency; deposit. For payment: convert home now; deposit foreign; pays at maturity. Useful when forwards unavailable or to compare with forward rates (covered interest rate parity).

Currency option

RIGHT but not OBLIGATION to exchange currencies at strike rate. Premium paid upfront. Calls (right to buy) and puts (right to sell). Exercise only if favourable; let expire if not. Insurance-like — protected with downside; participate in upside. Higher cost than forwards.

Forward Rate Agreement (FRA)

OTC agreement fixing INTEREST RATE for future deposit/loan. SINGLE PERIOD only. NO actual lending — cash settlement on rate differential. Notation "XvY": X = months to start; Y = months to end; rate covers period (Y−X). E.g., 3v9 = 6-month rate starting in 3 months.

Interest Rate Swap (IRS)

OTC agreement to exchange streams of interest payments. Plain vanilla: FIXED for FLOATING (or vice versa). Same currency, same notional. Multi-period (typically 2-30 years). Most common interest rate hedging instrument. Used to convert floating to fixed (lock cost).

Interest rate cap

Sets MAXIMUM interest rate on borrowing. Series of options ("caplets"). If market rate exceeds cap: option pays out. If below: floats freely. Borrower pays premium upfront. Protects against rate rises while participating in low rates.

Collar

Combined CAP + sold FLOOR. Premium of sold floor offsets cost of bought cap (often "zero-cost collar"). Limits both upside and downside. Borrower's rate stays within "collar" range.

COSO Internal Control (2013)

Reference framework for internal control. Five components: (1) Control Environment; (2) Risk Assessment; (3) Control Activities; (4) Information and Communication; (5) Monitoring Activities. 17 principles. Three objectives: operations effectiveness, reporting reliability, compliance.

Material Controls Declaration (UK CGC 2024)

Effective 1 January 2026. Board must DECLARE effectiveness of MATERIAL CONTROLS — those over material risks and material disclosures. Move toward US SOX-equivalent for UK premium-listed. Significant compliance challenge.

Internal audit

INDEPENDENT, OBJECTIVE assurance and consulting. Functionally reports to AUDIT COMMITTEE (board); administratively to CEO/CFO. Helps organisation by evaluating risk management, controls, governance. Risk-based annual plan. Cannot replace external audit.

Key Formulas

Worked Examples

Key Takeaways

  • COSO ERM (2017 Update) five components: Governance and Culture; Strategy and Objective-Setting (includes risk appetite); Performance; Review and Revision; Information, Communication, and Reporting. Strategy-integrated approach. ISO 31000 alternative. Three Lines Model (IIA 2020): management, risk/compliance, internal audit.
  • Risk categories: strategic (business model, M&A); operational (process, supply chain, IT, fraud); financial (currency, interest rate, credit, liquidity, capital structure); compliance/legal (regulatory, GDPR); reputational; cyber (increasingly material); climate/ESG (IFRS S2, UK SECR).
  • Risk assessment: likelihood × impact matrices; quantitative (Expected Loss, VaR, CVaR, sensitivity, scenario, Monte Carlo). Inherent risk less controls = residual risk. Risk appetite (board-set) vs risk tolerance vs risk capacity.
  • 4 Ts of risk response: Terminate (avoid); Treat (reduce); Transfer (insurance, hedging, contracts, outsourcing); Tolerate (accept). Plus Exploit for upside risks (opportunities). Cost-benefit analysis essential. Risk culture critical to effectiveness.
  • Currency hedging instruments: FORWARD (OTC, customisable, no upfront, obligation); FUTURES (exchange-traded, standardised, daily margin); MONEY MARKET HEDGE (replicate via deposits/loans); OPTIONS (right not obligation, premium upfront — for upside participation or uncertain transactions).
  • Interest rate hedging: FRA (single-period, cash-settled, "XvY" notation); FUTURES (price = 100 − rate; borrower SELLS); IRS (most common — convert floating to fixed; multi-period; pay fixed + receive floating); OPTIONS (caps, floors, collars). Collar = bought cap + sold floor; zero-cost when premiums equal.
  • Hedging strategy choice depends on: nature of exposure (single vs ongoing); certainty preference; cost; flexibility; counterparty acceptance; documentation/IFRS 9 hedge accounting requirements. Forwards/IRS most common. Options when upside participation important.
  • COSO Internal Control (2013) five components: Control Environment; Risk Assessment; Control Activities; Information and Communication; Monitoring Activities. 17 principles. Three objectives: operations, reporting, compliance. Types: preventive/detective/corrective; manual/automated; entity/process/transaction level.
  • UK Corporate Governance Code 2024: board responsibility for risk and controls; annual effectiveness review; principal risks reporting; viability statement; Material Controls Declaration (effective 2026 — UK SOX-lite). Three Lines Model (IIA): first line management owns risks; second line risk/compliance support; third line internal audit independent assurance.
  • Internal audit: INDEPENDENT, OBJECTIVE assurance and consulting. Functionally reports to AUDIT COMMITTEE (board level); administratively to CEO/CFO. Cannot replace external audit. Risk-based annual plan; charter approved by audit committee; coordination with external audit (ISA 610). IIA International Standards govern professional practice.

Practice Questions

Question 1 of 8

COSO ERM (2017 Update) framework has five components, including:

Question 2 of 8

A UK exporter expecting to receive $2m in 3 months hedges with a forward contract at $1.31/£. The hedge:

Question 3 of 8

A money market hedge for a future foreign currency RECEIPT involves:

Question 4 of 8

A "3v9 FRA" (Forward Rate Agreement) covers:

Question 5 of 8

An Interest Rate Swap (IRS) where company pays 5% fixed and receives SONIA on £20m floating-rate debt at SONIA + 2% effectively converts the cost to:

Question 6 of 8

An interest rate COLLAR (zero-cost) involves:

Question 7 of 8

In the COSO ERM 2017 framework, "Risk Appetite" is most appropriately set:

Question 8 of 8

The UK Corporate Governance Code 2024 introduces a "Material Controls Declaration" — effective 1 January 2026. This requires:

Source and Version

Syllabus: ICAEW ACA Advanced Level 2026 · Reviewed: 2026-05-04

ICAEW ACA syllabusLocal syllabus coverage review