• Português
  • English
  • Português
  • English
  • Home
  • Courses
  • Services
    • Compliance
    • Privacy
    • Due Diligence
    • DPO – Data Protection Officer
    • ESG Program
    • ISO – Certification
    • AML – Anti-Money Laundering
  • Integrity program
  • P&B Blog
  • P&B News
  • Events
  • About Us
  • Contact Us
Menu
  • Home
  • Courses
  • Services
    • Compliance
    • Privacy
    • Due Diligence
    • DPO – Data Protection Officer
    • ESG Program
    • ISO – Certification
    • AML – Anti-Money Laundering
  • Integrity program
  • P&B Blog
  • P&B News
  • Events
  • About Us
  • Contact Us
Compliance

INTEGRITY RISK ANALYSIS – BENEFITS TO BUSINESS

Henrique Starck

  • 10/03/2022

P&B Compliance lawyer Henrique Starck writes a short article on “Compliance Risk Assessment”. It is a procedure for organizations that value the managerial efficiency of their business, ethics and, above all, their state of compliance with regulations.


The Compliance Risk Assessment – ​​CRA is a necessary accomplishment for organizations that value the managerial efficiency of their business, ethics and, above all, their state of compliance with regulations.

CRA is a process used to discover an organization’s inherent compliance risks. Carrying out risk mapping aims to eliminate uncertainties and unpredictability that hinder the management of an organization, regardless of the sector and its size.

Risk mapping is an instrument for validating Business Compliance, as it is responsible for categorizing an organization’s integrity risks, such as: corruption, internal fraud, bidding fraud, conflict of interest, money laundering, regulatory non-compliance, competition unfair, insider trading, violations in labor, tax, environmental, etc.

The CRA is one of the main pillars of a Compliance Program and one of the requirements to be considered by the authorities when evaluating the effectiveness of a company’s integrity measures, especially to reduce sanctions.

A Compliance risk analysis provides organizations with expertise on how to direct their efforts and investments to solve highly relevant problems, especially those related to the organization’s financial health or image.

It is an attraction that allows the company to attract new business, improve its environment and quality of work, detect fraud to reduce losses due to illicit acts, in addition to facilitating participation in public contracts, approval of credits, financing, etc.

Despite the benefits, a poorly executed Compliance Risk Assessment makes it difficult for the organization to have productivity, financial peace of mind, control over its operational productivity and, above all, forecast integrity risks.

There are several risk assessment standards on the market, such as COSO (Committee of Sponsoring Organizations of the Treadway Commission) and ISO 30000 (Risk Management). By default, the risk methodology is divided into 7 steps:

Step 1 – Know your organization: The maker of a CRA needs to know your organization in depth. You need to understand the history, culture, customers and suppliers, operational activity, leadership, employee profile, etc.

2nd Step – Know the jurisdiction pertaining to the organization: It is necessary to understand which laws apply to the organization to understand the possible risks, as well as it is necessary to agree with the top management about what risks the organization expects management. For study purposes, we cite the Anti-Corruption Act, FCPA, UKBA, Money Laundering Act, Defense and Competition Act, Code of Conduct, etc.

3rd Step – Elaboration of the risk grid: A prior risk matrix must be prepared that classifies the probability of occurrence of the risk and its impact on the organization. The classification must interpret the risks as inherent, disregarding the existing mitigating controls.

4th Step – Conducting interviews: Identify the areas affected in the processes assigned to risks and select your managers for interviews. The chosen management must criticize the classification of inherent risks and point out the existing mitigation measures for each risk. Afterwards, the interviewer must agree with the interviewee on the new risk classification applying the existing controls, so that the residual risk matrix is ​​prepared.

5th Step – Action Plan: It is necessary to create an action plan in order to establish and implement new controls or ways to improve existing ones, in order to mitigate the residual risks found.

6th Step – Elaboration of the target Risk Matrix: Create a matrix that graphically represents the impact and probability classification of desirable risks. Desirable risks are those that the organization intends to be able to accept after improving its controls. It is recommended that the graphic risk matrices be placed side by side, to better visualize the evolution of controls.

7th Step – Monitoring: It is necessary to monitor the execution of the action plan so that residual risks become target/desirable risks by the organization.


P&B Compliance is a highly qualified consultancy specializing in the design and implementation of Corporate Integrity Projects. The vast experience and professionalism of its staff guarantees vast knowledge of national and international standards and risks, improving its methodology for preparing an integrity risk analysis. P&B Compliance remains available for any questions and clarifications on the subject.

Loading...

Mais publicações do P&B Explica

LGPD
NON-COMPLIANT ATTITUDES WITHIN THE SCOPE OF LGPD
18/02/2022
AML
,
Compliance
PREVENTION OF MONEY LAUNDERING IN THE BRAZILIAN ART MARKET
22/02/2022
Compliance
ESG: FAR BEYOND FINANCIAL CAPITAL
28/05/2021

Networks

Contact us

+55 (11) 3846 – 9432
contato@compliancepb.com.br
Whatsapp
P&B training platform
Address

Rua Funchal, nº263 – 1º andar
Vila Olímpia – SP
CEP 04551-060

Privacy policy

Networks

Contact us

+55 (11) 3846 – 9432
contato@compliancepb.com.br
Whatsapp
P&B training platform
Address

Rua Funchal, nº263
1º. andar – cj 13, São Paulo
CEP 04551-060

Privacy policy

Solved by Adaking Studio & Reticencias Creative Design Studio

P&B Compliance
Gerenciar Consentimento de Cookies
Usamos cookies para otimizar nosso site e nosso serviço.
Funcional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferências
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Estatísticas
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage vendors Read more about these purposes
Preferências
{title} {title} {title}