Role of the Internal Audit Function in Enterprise Risk Management
This statement defines enterprise risk management as a coordinated set of activities, rather than a single function, and identifies five categories of ERM activities: identify, assess, manage, monitor, and report.
The internal audit function contributes to these activities by providing objective assurance and advice, while other functions and roles also support the organization’s assurance and advisory efforts. Through coordination, collaboration, and appropriate reliance, these functions can improve the alignment, consistency, and quality of information provided to the board and senior management.
The chief audit executive and the internal audit function are uniquely positioned to help integrate organizationwide assurance and advice. With appropriate safeguards, the CAE may supervise other functions and roles that also provide assurance services.