Every few years a board asks internal audit to “own risk management for a while,” and every few years a chief audit executive discovers what that costs. The function that builds the enterprise risk register cannot audit it; the function that sets the risk appetite cannot give assurance that management stays within it; the function that facilitates every risk workshop becomes the reason the business never learned to run its own. The opposite failure is quieter and more common: internal audit treats ERM as someone else’s department, audits it once every five years as a documentation exercise, and never tells the board whether the risk picture it receives each quarter is true. Between those two lies the actual role, which the IIA has described since 2004 and rewrote for the Three Lines Model in 2020: assurance over risk management as its core, advice with safeguards where the organization needs it, and a short list of things it must never do.
This guide sets out that role in usable form: the roles table with the safeguard for every legitimate advisory role, the charter language that makes the boundaries enforceable, a five-level ERM maturity rubric across six dimensions, a fifteen-row ERM audit work program, an annual ERM assurance calendar, a worked maturity assessment with two findings at the site’s running example company, and the failures that recur. It was rewritten in September 2026 to reflect the Global Internal Audit Standards, the Three Lines Model, and COSO’s Enterprise Risk Management framework (2017), and it sits alongside the site’s guides on risk appetite, the RCSA process, and the risk register, which cover the instruments this guide audits.
In this guide
- What ERM is, and what internal audit is auditing when it audits it
- The roles table: core, legitimate with safeguards, and never
- Making the safeguards real: charter language and practice
- The ERM maturity rubric
- Auditing ERM: a work program
- The annual ERM assurance calendar
- Worked example: the maturity assessment at MidState Beverage
- Reporting to the board on risk management
- Common failures
- Adapting: small companies, financial services, and the facilitation question
What ERM is, and what internal audit is auditing when it audits it
Enterprise risk management is the set of practices by which an organization identifies the risks to its objectives, decides how much of each it will accept, responds to them, and reports on them, across the whole enterprise rather than one function at a time. COSO’s 2017 framework organizes it into five components (governance and culture; strategy and objective-setting; performance; review and revision; information, communication, and reporting) and twenty principles, and its main departure from the 2004 version was to tie risk to strategy: the framework asks how risk is considered when strategy is chosen, not only how risks to a chosen strategy are managed. ISO 31000:2018 covers similar ground with a principles-framework-process structure and is the reference in many non-US organizations. Neither is a checklist; both are descriptions of what a mature organization does, and an audit against either is an audit of practice, not of documents.
What internal audit audits, therefore, is not whether a risk register exists but whether the organization’s risk management changes decisions. The evidence of that is specific: a strategy paper that shows the risk analysis behind the option chosen; a risk appetite statement with metrics that have breached and produced a response; a risk register whose ratings moved after an event and whose owners can say what they did; a board that receives a risk report and minutes a decision on it. The COSO 17 principles guide covers the internal control framework that ERM sits on top of, and the distinction matters for scoping: an audit of controls over a process is not an audit of ERM, and an audit of ERM that only tests the register has audited a document.
The roles table: core, legitimate with safeguards, and never
The IIA’s 2004 position paper drew the picture as a fan: core assurance roles in the center, legitimate consulting roles with safeguards around them, and roles internal audit should not undertake at the edge. The 2020 Three Lines Model and the Global Internal Audit Standards keep the substance and change the vocabulary: the third line provides independent assurance over the first and second lines’ management of risk, may provide advice, and must not assume management responsibilities. The table below is the fan, updated, with the safeguard that makes each middle-column role legitimate written next to it, because the safeguard is the part functions forget.
| Core assurance roles (do these) | Legitimate advisory roles | Safeguard that keeps the advisory role legitimate | Roles internal audit must not take |
|---|---|---|---|
| Give assurance on the design and operation of the ERM framework and process | Facilitate risk identification and assessment workshops | Management owns the outputs and signs them; audit records that it facilitated, and does not rate the risks itself; audit does not assure the workshop outputs in the same cycle | Set the risk appetite |
| Give assurance that key risks are correctly identified and evaluated by management | Coach management on responding to risks | Advice is documented as advice; the decision and the response are management’s; audit tests the response later as management’s | Decide the response to a risk, or implement it |
| Give assurance that key risks are managed within appetite | Coordinate ERM activities across functions where no second line exists | Time-limited, with a plan to transfer to management; the audit committee approves the arrangement and the end date; disclosed in the charter | Own the risk management process, or manage risks on management’s behalf |
| Evaluate the reporting of key risks to the board and executives | Consolidate risk reporting where management asks for help building it | Audit builds the format, management supplies and owns the content; audit does not present the risk report as its own view | Take accountability for risk management, in the charter or in fact |
| Review the management of key risks, including the effectiveness of controls and responses | Maintain and develop the ERM framework as a consulting engagement | Framework design is advisory; management adopts and owns it; audit does not audit its own design for at least one full cycle, or another party does | Provide assurance on risks it managed or on a framework it designed within the cooling-off period |
| Report on the maturity of ERM to the board | Champion the establishment of ERM in an organization that lacks it | Championing is advocacy, not ownership: audit makes the case to the board, and the board assigns ownership to a manager | Be the risk management function |
The test for whether a role has drifted from the middle column to the right one is a single question: if this risk materializes, who will the board hold accountable? If the answer is internal audit, the function has taken a management responsibility. A second test is time: a “temporary” coordination role that is entering its third year is not temporary, and the audit committee should be told that the third line has become the second.
Making the safeguards real: charter language and practice
Safeguards that live in a position paper protect nobody. They protect the function when they are in the audit charter, agreed by the audit committee, and applied in the engagement letters. The clauses below are model language; the Domain III guide covers the Standards’ independence requirements they implement.
Charter clause on risk management roles. Internal audit provides independent assurance on the effectiveness of the organization’s risk management, including whether significant risks are identified, evaluated, and managed within the board’s appetite, and whether risk reporting to the board is reliable. Internal audit may provide advisory services in support of risk management, including facilitation of risk assessments and advice on the design of the risk management framework, provided that management retains responsibility for identifying, assessing, and responding to risks, and for the risk management framework and its outputs. Internal audit will not set risk appetite, decide or implement risk responses, or assume ownership of the risk management process. Where internal audit provides advisory services on the design of the risk management framework, it will not provide assurance on that design for a period of [twelve months] or until [another party] has done so, and the audit committee will be informed.
Engagement letter clause for a facilitated risk assessment. Internal audit will facilitate the workshop and document the risks, ratings, and responses identified by the participants. The risks, ratings, and responses are management’s and will be approved by [executive]. Internal audit will not rate risks or determine responses. The outputs will be assured by internal audit in a subsequent engagement no earlier than [date], and the facilitation will be disclosed in that engagement’s report.
In practice the safeguards show up as small disciplines. The facilitator writes what the room said, in the room’s words, and the ratings column is filled in by the risk owners after the session, not by the auditor tidying up. Advisory work carries a different report template, unrated, with a limitations paragraph that says it is not assurance; the report template set has that memo format. And the annual plan states which ERM work is assurance and which is advisory, so the coverage map the committee sees is honest.
The ERM maturity rubric
A maturity rubric turns “how good is our ERM” into a scored answer the board can track over years. The one below uses five levels across six dimensions; the descriptors are written as observable facts, so that two assessors would score the same organization the same way, and each cell is something an auditor can inspect or trace. Score each dimension separately and never average them, because an organization at level 4 on reporting and level 1 on appetite has a reporting framework, not a risk management one.
| Dimension | 1 Initial | 2 Developing | 3 Defined | 4 Managed | 5 Optimized |
|---|---|---|---|---|---|
| Governance and ownership | No policy; risk discussed ad hoc; nobody owns the process | Policy drafted; a coordinator named part-time; board receives an annual list | Approved policy; named risk owners for every top risk; a risk committee with a charter that meets quarterly | Board-level oversight with minuted decisions; second-line function independent of the business; roles enforced | Risk governance integrated with strategy and performance governance; board challenges the risk profile, not just receives it |
| Risk identification and assessment | Risks listed from memory; no criteria | Register exists; ratings inconsistent across units; refreshed annually | Common scale with impact and likelihood criteria; refreshed quarterly; RCSAs in major units | Ratings challenged by the second line; emerging risks and scenarios assessed; ratings move after events | Assessment uses data (loss, KRI, external) alongside judgment; interdependencies between risks assessed |
| Appetite and tolerance | None stated | A qualitative statement exists; not cascaded | Appetite by risk category with some measurable limits; breaches reported | Measurable limits for all major categories; breaches escalated and decided; appetite reviewed annually with strategy | Appetite drives capital, budget, and product decisions, and the trail shows it |
| Response and control | Responses implicit; controls undocumented | Responses recorded in the register; owners named; completion untracked | Responses tracked with dates; control effectiveness assessed by owners | Response effectiveness tested by the second line or audit; residual risk compared to appetite | Responses optimized for cost against residual risk; insurance, controls, and acceptance chosen deliberately |
| Monitoring and reporting | No regular reporting | Annual register presented to the board | Quarterly risk report with top risks, changes, and actions; some KRIs | KRIs with thresholds for major risks; exception-based reporting; decisions minuted | Near-real-time indicators where data allows; reporting integrated with performance reporting |
| Integration with strategy and decisions | Risk not considered in planning | Risk section added to major proposals after the decision | Risk assessment required before major decisions; strategic risks in the register | Strategy options evaluated against appetite; risk analysis visible in the strategy paper | Risk-adjusted metrics used in performance evaluation and incentives |
Scoring rules that keep the rubric honest: a level is achieved only when every descriptor in the cell is evidenced, not most of them; the evidence is a document, a minute, a trace, or an observation, never an interview alone; and the score is accompanied by the two or three facts that placed it, so that next year’s assessor can see what would have to change to move up. Report the six scores as a profile, with last year’s beside them, and resist the single composite number the board will ask for.
Auditing ERM: a work program
An ERM audit is an audit of the framework’s design and use, distinct from the process audits that test controls over individual risks. The program below runs 250 to 350 hours for a mid-size organization and follows the site’s work program conventions. It produces the maturity profile as one output and findings as another; the two are reported together.
| # | Area | Objective | Procedure | Evidence | Hours |
|---|---|---|---|---|---|
| 1 | Governance | ERM is approved, owned, and overseen | Inspect the ERM policy, its approval date, and the risk committee charter; read four quarters of board and committee minutes for risk decisions; confirm the second-line owner’s reporting line and independence | Policy; charters; minutes; org chart | 16 |
| 2 | Governance | Roles are defined and followed | Compare documented roles for the first, second, and third lines with what interviews and artifacts show; identify any management responsibility held by the second or third line | Role descriptions; interviews; charter | 12 |
| 3 | Identification | The risk universe is complete | Compare the register with the strategy, the audit universe, external loss and incident data, regulatory correspondence, and peer disclosures; list candidate risks absent from the register and ask why | Register; strategy; incident log; peer filings | 24 |
| 4 | Assessment | Ratings are consistent and evidence-based | Test 25 risk ratings against the criteria; compare ratings across units for the same risk; for 10 risks with events in the period, check whether ratings changed | Register history; criteria; events | 24 |
| 5 | Assessment | Second-line challenge operates | Inspect challenge records for 25 register entries; interview three risk owners on the challenge they received | Challenge log; interviews | 12 |
| 6 | Appetite | Appetite is stated, measurable, cascaded, and enforced | Inspect the appetite statement; map each category to a metric and a limit; test all breaches in four quarters to escalation and decision; trace appetite into two budget or product decisions | Appetite statement; breach reports; decision papers | 24 |
| 7 | Response | Responses exist, are owned, and are completed | For 25 top-risk responses, inspect the owner, date, and status; test 15 completed responses to evidence; compare residual ratings to appetite | Register; response evidence | 24 |
| 8 | Response | Controls over top risks are effective (coordination with process audits) | For the ten highest risks, map the controls relied on to the audit plan’s coverage and to the last test result; identify controls relied on that have never been tested | RCM; audit plan; prior reports | 16 |
| 9 | Monitoring | KRIs are leading, thresholded, and acted on | Inspect the indicator set for the top risks; trace all breaches in four quarters to decisions; identify top risks with no indicator | KRI reports; minutes | 16 |
| 10 | Reporting | Board risk reporting is complete, accurate, and produces decisions | Inspect four quarterly reports against the register and events; trace five reported items to decisions; test the accuracy of three reported metrics to source | Reports; minutes; source data | 20 |
| 11 | Strategy integration | Risk informs strategic decisions | For the three largest decisions in the period (acquisition, product, capital project), inspect the decision paper for risk analysis against appetite; interview the decision owner | Decision papers; interviews | 20 |
| 12 | Emerging risk | Emerging and scenario risks are assessed | Inspect the emerging-risk process and the last two scenario exercises; trace outputs to register changes or decisions | Scenario records; register changes | 12 |
| 13 | Culture | Risk culture supports the framework | Read the whistleblowing and incident statistics; test whether reported near misses and issues were welcomed or penalized in three cases; review incentive design for risk adjustment | Statistics; case files; incentive plans | 16 |
| 14 | Maturity | Score the six dimensions | Apply the rubric with the evidence gathered in 1 to 13; record the facts behind each score | Rubric workpaper | 12 |
| 15 | Use test | Risk management changes decisions | Across the year, identify five decisions that were different because of risk information, with evidence; where fewer than three exist, report it | Traces; interviews | 16 |
| — | Planning, reporting, review | 50 |
The annual ERM assurance calendar
Assurance over ERM is not one engagement every four years. It is a set of activities across the year whose sum lets the CAE say something to the board each year about risk management, which the Standards expect the CAE to be able to do. The calendar below is for a function with a modest budget; the ERM framework audit itself runs on a two- to three-year cycle, and the other lines run annually.
| Activity | Timing | Hours | Output |
|---|---|---|---|
| ERM framework audit (the program above) | Every 2 to 3 years, Q1 | 250–350 | Maturity profile; findings; opinion on the framework |
| Annual risk-report reliability test | Q4, before the year-end board report | 30 | Three reported metrics and five reported risks traced to source; exceptions reported to the CAE and, if material, the committee |
| Appetite breach review | Quarterly, 4 hours each | 16 | Breaches traced to decisions; unresolved breaches escalated in the CAE’s quarterly report |
| Top-risk coverage map | With the annual plan | 20 | Each top risk mapped to assurance obtained (audit, second line, external) and to gaps; feeds the plan; see the annual plan template |
| Post-event review | Within 60 days of any major loss or near miss | 20–40 each | Whether the risk was on the register, rated correctly, with a response that operated; changes to the framework |
| Advisory: facilitation or framework advice | As requested, within safeguards | Variable | Advisory memo, unrated; disclosed in the plan and the charter |
| CAE’s annual statement on risk management | Year-end | 16 | One page: what assurance was obtained, the maturity profile, the open findings, the CAE’s view |
Worked example: the maturity assessment at MidState Beverage
MidState Beverage is the site’s running example: a three-state distributor with 12 depots, 300 routes, two acquired distributors not yet integrated, a lean finance team, and a six-person internal audit function whose FY27 plan included an ERM framework assessment for the first time. The company has no second-line risk function; the CFO’s office maintains a risk register that the board sees annually. The assessment ran 220 hours in Q2 and produced the profile below.
| Dimension | Score | Facts that placed it |
|---|---|---|
| Governance and ownership | 2 | A one-page risk policy approved in 2023; the controller maintains the register alongside other duties; the board sees it once a year and the minutes record “noted” for three consecutive years |
| Risk identification and assessment | 2 | Register of 31 risks with high/medium/low ratings and no criteria; no rating changed after the FY26 Dayton cash loss or after the two acquisitions; the acquisitions themselves are not on the register as an integration risk |
| Appetite and tolerance | 1 | No appetite statement; the credit policy and the fleet safety policy contain the only limits, and neither is described as appetite |
| Response and control | 3 | Each register entry names an owner and a response; 9 of 12 responses tested were in place; the controls behind the top risks are tested by internal audit through the process audits |
| Monitoring and reporting | 2 | No KRIs; the annual register is the only report; the monthly operations pack contains route shortage and breakage metrics that function as indicators but are not connected to the register |
| Integration with strategy and decisions | 1 | The two acquisitions were approved on financial papers with no risk section; the ERP replacement decision pending in FY28 has no risk analysis attached |
Two findings came out of the assessment, both rated Medium under the severity scale, because the immediate exposure sat in the process controls that were separately tested rather than in the framework. The first: the board approves strategic decisions without a risk analysis against any stated appetite, evidenced by the two acquisition papers and the ERP replacement proposal, with the cause that no appetite exists to analyze against and no step in the board paper template asks for it. Agreed action: the CFO to draft a risk appetite statement for board approval by Q4, and the corporate secretary to add a mandatory risk section to the board paper template, with the ERP replacement paper as the first to use it. The second: the risk register does not reflect events or changes in the business, evidenced by the unchanged ratings after the Dayton loss and the absence of integration risk, with the cause that the register is refreshed annually by one person with no challenge. Agreed action: quarterly refresh by the executive team with the operations pack metrics connected to the register entries, and the register presented to the board quarterly with changes highlighted.
The CAE declined the CFO’s request that internal audit draft the appetite statement, offered to facilitate the executive workshop that would produce it under the safeguards above, and wrote both the request and the answer into the report. The profile went to the audit committee with a note that scores of 1 and 2 were expected for a company of MidState’s size and history, that the response dimension at 3 reflected process controls tested elsewhere, and that the assessment would be repeated in FY29 against the same rubric.
The top-risk coverage map, worked
The coverage map is the artifact that connects the ERM audit to the annual plan, and it is the one the audit committee understands fastest. For each top risk on the register it records what assurance exists from each line and when it was last obtained, and the gap column is the plan’s input. MidState’s map for its six highest-rated risks, after the assessment, looked like this.
| Top risk (register) | First-line control evidence | Second line | Internal audit, last test | External | Gap and plan response |
|---|---|---|---|---|---|
| Route cash diversion | Depot settlement controls; HQ reconciliation since May | None | FY27-01 route cash audit, Unsatisfactory, five findings, validation in progress | External audit substantive work on cash | Covered; validation of the two High findings due Q3 |
| Acquisition integration failure | Integration lead’s monthly certifications | None | FY27-02 integration engagement, Q3 | None | Not on the register until the assessment; added; engagement scheduled |
| ERP obsolescence and replacement | IT roadmap; vendor support contract to FY28 | None | ITGC coverage annually; no review of the replacement program | None | Gap: pre-implementation review added to the FY28 plan; risk section required in the board paper |
| Product loss and shrink at depots | Cycle counts; breakage sign-offs | None | FY27 warehouse inventory engagement, Q2 | External audit inventory counts at year-end | Covered; cycle-count module finding open |
| Fleet and DOT compliance | Fleet manager’s compliance tracker | None | FY27 advisory only, unrated | Insurer’s annual fleet review | Gap: no assurance; a rated engagement added to FY28 |
| Key-person dependency in finance | None documented | None | Observed in the close engagement; no finding raised | None | Gap: raised as an observation to the CFO; succession plan requested; re-assessed at the quarterly refresh |
Three answers to “will internal audit run ERM for us?”
When the board asks. “No, and here is what I can do instead. If internal audit owns risk management, nobody independent can tell you whether it works, and that is the one thing you most need to know. I will help you assign it to an executive, facilitate the first cycles so it starts well, and audit it once it is theirs. The charter clause I am proposing says exactly that, with a date.”
When the CFO asks for the appetite statement to be drafted. “I will facilitate the session where the executive team writes it, and I will bring the structure and the questions. The numbers in it have to be yours, because you are the ones who will be held to them, and because I will be the one testing whether you stayed inside them.”
When the request is to keep coordinating “just until the risk manager is hired.” “Agreed, with three conditions: the audit committee approves it with an end date, the plan shows the hours as advisory rather than assurance, and I do not audit the risk register until a full cycle after the hand-over. If the hire slips past the date, I come back to the committee rather than extend quietly.”
Reporting to the board on risk management
Boards receive risk reports from management and assurance on those reports from internal audit, and the two should not be confused. Management’s report says what the risks are; internal audit’s says whether that report can be believed and whether the process behind it works. The CAE’s annual statement on risk management is one page: the assurance activities performed (from the calendar), the maturity profile with movement, the open findings on the framework, the top risks where assurance coverage is thin, and the CAE’s view in one paragraph, written in the plainest language available. A board that receives that page each year can track whether risk management is improving; one that receives only management’s register cannot. Where the organization has a risk committee of the board, the CAE presents the statement there and the audit committee receives it; where it does not, the audit committee is the forum, and the CAE should say so, because the absence of a risk committee is itself a governance observation in an organization of any size. The Domain IV guide covers the CAE’s broader reporting obligations that the statement sits within.
Common failures
| Failure | What it looks like | Why it matters | Fix |
|---|---|---|---|
| Audit owns ERM | The CAE maintains the register, runs the workshops, and presents the risk report | No independent assurance exists over the organization’s most important governance process | Board assigns ownership to a manager; audit facilitates under safeguards and exits on a date |
| Auditing the document | The ERM audit tests whether the register exists, has owners, and was refreshed | A complete register that changes no decisions passes | Use test (procedure 15) and strategy integration (procedure 11) in every ERM audit |
| Composite maturity score | “ERM maturity is 3.2” | A 5 in reporting hides a 1 in appetite | Six-dimension profile, no averaging, facts behind each score |
| Facilitation without safeguards | Audit facilitates, rates the risks “to save time,” and assures the register the same year | Independence gone in fact, whatever the charter says | Engagement letter clause; management enters ratings; cooling-off before assurance |
| Appetite that cannot breach | A qualitative statement with no metrics, or metrics nobody measures | Nothing can be enforced; the board cannot know whether management stayed within it | Metrics and limits for every category; breach reporting tested quarterly |
| Ratings that never move | The same high/medium/low profile for five years through two losses and an acquisition | The register is a document, not an assessment | Compare ratings to events in every ERM audit; report the non-movement |
| Coverage assumed | Top risks reported as “covered by controls” with no test of those controls in years | The board’s comfort rests on untested controls | Top-risk coverage map with the last test date, feeding the plan |
| No post-event review | A major loss occurs; the register is updated; nobody asks why the framework missed it | The framework does not learn | Post-event review within 60 days, reported to the committee |
Adapting: small companies, financial services, and the facilitation question
In a small company with no second line, internal audit is usually the only function that knows what ERM is, and the pressure to run it is strong. The right answer is the championing role: make the case to the board, help it assign ownership to an executive, facilitate the first two cycles under written safeguards with an exit date, and audit the third. The small-company internal audit guide covers the charter language for a function that has to do this. In financial services the second line exists, is regulated, and reports to a CRO; the third line’s ERM role is the assurance column of the table almost entirely, with a specific regulatory expectation that internal audit assess the risk management framework’s effectiveness and the independence of the risk function, which the financial services guide sets out by regulator. The operational risk guide and the GRC framework guide cover the adjacent frameworks that an ERM audit touches. On facilitation, the decision rule is the one from the roles table: if the board would hold internal audit accountable for the outcome, do not do it; if management would sign the output and be accountable for it, facilitate, disclose, and wait before assuring.
The Risk Library holds the risk-stripe guides an ERM audit’s coverage map points at, and every guide on the site is indexed at All Guides.
Related guides
- Risk appetite statements — writing appetite that can be measured and breached
- The RCSA process — the first line’s self-assessment
- The risk register — anatomy, a worked example, and how to keep it alive
- Internal audit risk assessment — the annual assessment that produces the coverage map
- GIAS Domain III: governing — independence and the board’s role
- COSO’s 17 principles — the internal control framework beneath ERM
- Operational risk — the framework for the largest risk stripe
- Building a GRC framework — how ERM, compliance, and assurance fit together
- Creating an internal audit charter — where the safeguards live
Leave a Reply