At Tamarind Foods, a central risk team of three people maintains the corporate risk register, and everyone else treats risk as solely that team's responsibility, with operational managers saying risk is not their concern. The internal auditor is evaluating the design of the risk management process. How should the auditor interpret this arrangement?
- AThe design is sound because concentrating risk management in one specialist team ensures consistency and gives the board a single accountable point of contact.
- BThe design is acceptable as long as the central risk team reports functionally to the board rather than to operational management.
- CThe auditor should personally take ownership of embedding risk management into daily operations so that the identified weakness is corrected.
- DThe design is flawed because risk management should be embedded across the organisation's processes and functions, with ownership resting with the managers who run each activity. Correct
Why A is wrong: A dedicated team can aid coordination, which makes this tempting, but concentrating ownership in one small team leaves the people who actually run the activities disengaged from the risks they create, so the design is not sound.
Why B is wrong: Reporting lines matter for a risk function, which makes this plausible, but changing to whom the team reports does nothing to embed risk ownership across operations, so it does not cure the design flaw.
Why C is wrong: Wanting to fix the weakness is understandable, but building and running the risk process is a management responsibility under the Three Lines Model, and taking it on would impair internal audit's independence.
Why D is correct: Effective risk management is embedded throughout the organisation rather than delegated to a single team; the managers who own the processes must own the associated risks, so treating it as one team's job is a genuine design weakness.