Tools and Insights for Internal Governance and Risk Management


The following tools were published on KnowledgeLeader this week:

Internal Use of Inventory Policy

The purpose of this policy is to establish guidelines for the purchase of a company’s products for internal use. Under this policy, the process for internal orders states that when initiating an order for a sales force unit, internal use unit, giveaway unit or expensed unit, the requester must fill out an internal purchase order. 

Production Equipment Security Policy

Govern the security of your organization’s production equipment used in an internet-facing environment with the best-practice procedures in this policy. This policy is designed to minimize potential exposure to a company from the loss of sensitive or company confidential data, intellectual property, damage to public image, etc., which may follow from unauthorized use of company resources. 

New Restaurant Openings Project Management Audit Report

Assess your organization’s project management capabilities for the new restaurant openings (NRO) process with this audit report sample. In this sample, current project management reports detailing the NRO project and portfolio status can be optimized to align more clearly with and support the organizational management and oversight structure.

Chief Risk Officer Job Description

This tool contains three sample job descriptions that outline the responsibilities, key selection criteria and general information for the role of the chief risk officer (CRO). The CRO is responsible for ensuring that the organization is in complete compliance with government regulations and guidelines. 

IT Governance Audit Work Program

Organizations looking to conduct an IT governance audit can use the best-practice steps in this work program sample. Sample steps include determining if an IT steering committee or similar governing body is in place to support the IT strategy committee’s higher-level deliberations and evaluating the methods used to establish cost transparency for IT projects and IT services.

SOX Training Guide: Remediation Efforts and Needs

We’ve designed this guide to help companies train SOX project teams on how to identify and communicate deficiencies noted during the testing process. According to this sample, an important part of complying with Sarbanes-Oxley (SOX) Section 404 is ensuring that control deficiencies are accurately communicated to appropriate personnel and properly tracked. 

Common Fraud Scenarios Guide

This tool contains three guides that can be used by auditors to identify and mitigate common fraud schemes. In these samples, we provide a common understanding of the potential fraud schemes and scenarios that a company has included in its entity-level fraud risk assessment. 


KnowledgeLeader has also published several publications this week.

Executive Perspectives on Top Risks for 2024 and a Decade Later

Protiviti and NC State University’s ERM Initiative are pleased to provide our 12th annual report focusing on the top risks currently on the minds of 1,143 directors and senior executives around the globe. This report reflects their views on the extent to which a broad collection of risks is likely to affect their organizations over the next year (2024) and a decade later (2034).

Executive Perspectives on Top Risks for 2024: Manufacturing and Distribution Industry Group Results

In an ever-evolving and rapidly changing business landscape for manufacturing and distribution organizations, executives and boards are challenged to navigate myriad risks, particularly as their businesses continue to play catch-up on numerous fronts in areas such as innovation and digital transformation.  Read more about the top risks and concerns for the manufacturing and distribution industry in 2024 in this industry group report. 

Auditor Changes Roundup: Q3 2023

Hong Kong-based Ark Pro CPA & Co (formerly HKCM CPA & Co) was the leader in net SEC audit client gains in the third quarter of 2023. The firm gained five new clients during Q3, all previously audited by fellow Hong Kong firm Centurion ZD CPA & Co. In this article, Audit Analytics takes a closer look at the SEC audit client gains in the third quarter of 2023. 

Recommended Resources 

This list of recommended resources from the web may be of interest to you. Click each link to learn more. 

  1. Using Technology to Boost Audit Quality
  2. HR, Health Thyself: A Comprehensive and Collaborative HR “Physical”
  3. SEC Brought 91 Cases Against Companies in FY ’23