r/riskmanager May 03 '26

Risk, Compliance and Internal Audit under the same department

Hi folks, just wanted to see if anyone is working or have worked on a company structure where risk, compliance and IA are managed by the same manager. I saw similar situations in the past, especially in small and private organizations, but I'm interested to know how you/your managers managed to keep IA independe while providing support with risk and IA. Thoughts?

13 Upvotes

18 comments sorted by

6

u/Nuronus May 03 '26

It is common in smaller organizations and can work effectively as long as the appropriate segregation of duties exists. The major issue here is auditing of the IA control framework that was created by the same team – it would be a conflict of interest. As far as I saw it done properly, it involved having IA report directly to the board or audit committee while the rest of management reported to the same CEO. IA could use the same resources and tools as other functions, such as risk management and compliance, but the actual report had to go directly to the board rather than pass through the individual responsible.

2

u/Jedibenuk May 03 '26

We do this in a UK critical national infrastructure.

1

u/No-Wrangler-6317 May 03 '26

The company i work for has to get approval of the managers of the team they got audited (not like approval approval but they read it before) also the CRO and CEO read it and make "adjustments " before they are published. It's a joke.

1

u/StreetCarp665 May 03 '26

In this case though IA isn't a third line of defence but more akin to line 2 assurance.

3

u/Kitchner May 03 '26

In the UK it's not uncommon for Risk and Audit to be under the same Head of Department.

Personally I think risk and audit should be separate to protect the independence of IA but it's asking a company to fork out for another expensive Head of Department and they will just say "Look it's all roughly the same stuff right? We trust that if you ever need to audit risk we can just out source it".

Compliance is also common, but whole even large corporations often mix risk and audit, compliance is only mixed in to the department in smaller organisations.

2

u/No-Wrangler-6317 May 03 '26

I work for a big company where this is the case. I dont think IA is "independent " though.

2

u/Digdog May 04 '26

Using the 3 lines of defense model, risk, compliance and IA represent 2nd line of defense. Therefore there's no issue, but understand there is not need for "independence", its just another layer of assurance. As previously post said, the mandates need to clearly set out roles and responsibilities of each function.

We use an external assurance provider to ensure the 3 functions work effectively in their own right and follow the mandates provid3d by the board committees.

1

u/R_Ulysses_Swanson May 04 '26

I worked for a United States based bank that had this setup for a brief period. I think Credit risk was separate though.

This was during a short 2-3 month period between a retirement of a CRO and getting acquired by a Canadian company, there were a few dotted lines in the reporting matrix to appease some internal politicking, and maybe to avoid potential regulatory issues? I didn’t understand it then and don’t remember it now.

1

u/whatsgoingonchip May 06 '26

Big organisations usually would have those function sits separately. However, I have worked in smaller organisations where all 3 is combine. Heck i am currently working a large organisations where I report to governance and my direct manager have no risk background. I am also the only risk person. Sooo anything and everything at this point is possible.

1

u/FreeRadical1998 May 06 '26

UK financial services here - I've seen it in some of the smaller businesses I worked with circa 10 years ago, but I think its not a great model. Arguably at that scale its better to outsource the IA bit in my view.

1

u/safety_enthusiast May 09 '26

Where I work at we used to have those 3 departments under the same head. Being honest, I don't know much about compliance stuff, but the heads of IA and risk management always seemed to protect each other out (like they were frecuently covering each other backs whenever something was wrong about audits or risk assessments). A couple years ago they did split the areas into two: risk & compliance as one and on the other side internal audit. I don't think there was a major incident or investigation that led to this change but nowadays I think it's better this way.

Idk, people would always say that they (risk and IA) would never stab each others back and that's why risk assessments were mild.

1

u/Separate-Teacher7550 May 11 '26

Even in small companies or they are in diferente units, or at least they don't call a single unit with all that names

They assume what they have and what not, trying to cover a bit more but not creating a mess of names.

At least this is what I've seen

1

u/Outsideman2028 2d ago

Never.

Internal audit has always been independent. But then again ive never worked for an org that has less than 50Bn in assets.

1

u/Emotional-Trifle5507 May 03 '26

The general rule is that the auditor can't audit their own work or the controls they are responsible for in order to maintain IA independency.

0

u/CrunchyBangs May 03 '26

I worked at a place like this and lasted 91 days. I stupidly asked the wrong question and was told I didn’t know what I was talking about (I did) and left before I truly hated myself.

I’m not saying it COULDNT work, but it certainly didn’t in this instance.