A board asks the chief audit executive a simple question: "Who actually owns this risk?" If the answer is "the audit function found it, so we're handling it," governance has already broken. Governance is the structure that assigns that ownership before anyone has to ask.
Organizational governance is the combination of processes and structures the board uses to inform, direct, manage, and monitor the organization's activities toward its objectives. Three verbs matter. The board directs (sets objectives, appetite, and tone). Management manages (executes and controls). Everyone monitors (reports back so direction can be corrected).
Governance sits above risk management and control, not beside them. Risk management is how the organization identifies and responds to uncertainty around objectives. Control is the mechanism that keeps responses working. Governance decides who does each of those, with what authority, reporting to whom. That is what governance frameworks, principles, and models exist to set out.
KEY: Governance answers three questions: who decides, who does, and who checks. Any exam stem describing confusion about accountability is a governance question, even when the surface topic is a...
Common mistakes
- Treating internal audit as a risk owner. Audit assesses; management owns, decides responses, and accepts residual risk. "Internal audit accepted the risk" is always wrong.
- Calling the second line independent. Compliance and risk management report to the CEO. Only the third line reports functionally to the governing body.
- Letting management approve the audit plan. The CFO or CEO approving the plan or budget is a governance defect, not an efficiency.
Bottom line
- Governance is the processes and structures the board uses to inform, direct, manage, and monitor activities toward objectives.
- Board duties: set strategy and risk appetite, oversee management, approve the internal audit charter, plan, and budget, and appoint, remove, and compensate the CAE.
- Senior management owns risks and controls, decides risk responses, and reports upward; internal audit never owns risk or accepts residual risk.
- Internal audit reports functionally to the board (charter, plan, budget, CAE hiring and pay, results) and administratively to senior management.
Exam shortcut
Read every governance stem for the verb attached to the actor. "Approves the charter, plan, or CAE pay" must resolve to the board. "Owns, accepts, or decides the response to a risk" must resolve to management. "Assesses and reports" resolves to internal audit. Any mismatch is the defect being tested.
The full lesson (about 2,356 words, 16 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- 1
Browse all free CIA Part 1 lessons or jump into free CIA Part 1 practice questions.