Rédigé par des étudiants ayant réussi Disponible immédiatement après paiement Lire en ligne ou en PDF Mauvais document ? Échangez-le gratuitement 4,6 TrustPilot
logo-home
Document preview thumbnail
Aperçu 4 sur 95 pages
Resume

Summary Internal Control & Risk Management| Jeffrey Ottevanger | KU Leuven | 2025/26

Document preview thumbnail
Aperçu 4 sur 95 pages

Summary of the Internal Control and Risk Management course at KU Leuven's Master of Business Engineering program (2025/2026). This part only covers the lectures from Jeffrey Ottevanger.

Aperçu du contenu

Summary risk management &
internal control 2025-2026
CHECK OOK GUESTLECTURE KUL AUDIT


Introduction
• Topics of next 7 weeks
1) Introduction to risk management
2) Strategic risk management
3) Governance & governing bodies
4) Designing risk management & challenges of ERM implementation
5) Risk assessment, cognitive biases and risk response
6) Looking closer at internal control
7) Internal audit

• Upon completion of this course you are able …
- To offer a comprehensive perspective on the different risks faced by an organization
- To integrate these different risks into a single unified analytical risk management
framework
- To explain the role of the internal audit function, senior management and the board of
directors in enterprise risk management and to explore the link with external audit
- To understand the role of risk management in strategic planning and strategy execution
- To offer insights in the world of internal control and to outline and apply risk
management and control frameworks (COSO, ISO)
- To develop analytical and integrative thinking in understanding and implementing risk
management as well as adequate control practices and techniques


Course outline
• Course material:
- Theory courses (slides will be made available)
- Documentary "The Smartest Guys in the Room”
- Special topics by Ludovic Deprez, partner at EY
- No recordings

• Evaluation:

- Final exam: written closed book exam; mutiple choice and open-ended questions
- Examples:
• Discuss the three lines (of defense)
• Discuss the role of corporate governance in ERM
• ….

,Lecture 1: introduction to risk management
& internal control
In this lecture we will look at:
- Who, what, why?
- What is risk
- What is (internal) control
- Development of Enterprise Risk Management (ERM)
- Corporate governance and regulatory context (external control)
- Control responsibilities



1. Who, what, why?
A brief history of ERM
• Ancient Civilizations: The concept of managing risk dates back to ancient civilizations.
The Babylonians developed the Code of Hammurabi around 1754 BC, which
included provisions for risk-sharing among traders. This can be seen as an early form
of insurance.
• Maritime Insurance: In ancient Greece and Rome, maritime loans were used to
finance shipping ventures. These loans included a form of insurance where the
lender would forgo repayment if the ship was lost at sea. This practice laid the
groundwork for modern marine insurance.
- Formed the foundation of Europe
- Insurance that if something was lost at sea to make sure you got some
compensation
• Medieval Guilds: During the Middle Ages, guilds in Europe provided mutual aid to
their members. These guilds would pool resources to support members in times of
need, such as illness or loss of property, which is an early example of risk pooling.
• Renaissance and Early Modern Period: The development of probability theory in the
17th century by mathematicians like Blaise Pascal and Pierre de Fermat (founding
fathers of insurance) provided a scientific basis for assessing and managing risk. This
period also saw the establishment of the first insurance companies, such as Lloyd's
of London in the late 17th century.
• Industrial Revolution: The Industrial Revolution brought about new risks associated
with industrialization and urbanization. This led to the development of more
formalized risk management practices, including the establishment of fire insurance
companies and the introduction of workplace safety regulations.
- Lack of risk management
• Financial crisis in the 20th & 21st century: further shaped ERM
• Today: ERM and internal controls have become an integral part of any organization.




The Deming Circle
Deming circle was designed to improve the quality of process of organizations
We are good at making plans and executing them but it mostly stops there. However it is
important to go further and check whether what you are doing is aligned with what is
wanted and act upon these differences.

,important to think about what risks you want to prioritize

Everyone makes mistake so you need to include checks to make sure you know when you are
making them and you can act upon them and readjust what you are doing

The latest scientific insights on risk management & internal controls highlight several important
trends and developments:

• Adoption of AI and technology: The integration of artificial intelligence (AI) in risk management offers
new opportunities but also brings unique challenges. Organizations need to be aware of the risks
associated with AI, such as bias and privacy issues.
• Geopolitical risks: Increasing geopolitical tensions, such as the situation between Russia and China,
have a significant impact on risk management. Companies are encouraged to reconsider their
dependence on external suppliers and focus more on regional or local solutions.
• Proactive risk management: There is a shift from reactive to proactive risk management. Companies
are increasingly taking measures before risks occur, especially in the areas of pandemics and
geopolitical tensions.
• Cybersecurity and data breaches: With the rise in cyberattacks, it is essential for companies to
implement effective cyber incident reporting and security measures. The European Union has
introduced various laws and guidelines to protect digital infrastructure.


AI is highly relevant for risk management due to its ability to enhance various aspects of the process.
Some key reasons:

• Real-time Risk Identification: AI can analyze vast amounts of data in real- time, helping organizations
identify emerging risks quickly.
 useful in detecting anomalies and potential threats in financial transactions, supply chain
operations, and cybersecurity
• Improved Decision-Making: AI-powered insights and risk scoring models provide more accurate and
data-driven decision-making.
 helps in assessing risk to make informed choices
• Efficiency and Automation: AI automates routine tasks such as risk assessments and compliance
reporting, significantly improving efficiency.
 allows risk managers to focus on more strategic activities
• Fraud Detection: AI's advanced algorithms can detect patterns and anomalies that may indicate
fraudulent activities.
 crucial in preventing financial losses and maintaining the integrity of operations
• Predictive Analytics: AI and machine learning models can predict future risks based on historical data
and trends.
 proactive approach helps organizations prepare for potential challenges before they occur.
• Enhanced Cybersecurity: AI helps in identifying and mitigating cybersecurity threats by analyzing
network traffic and detecting unusual patterns that may indicate a breach




Geopolitical risks are at this moment very relevant. Examples are…

, Examples of proactive risk management are:

• Scenario Planning: Organizations use scenario planning to anticipate various future events and
their potential impacts. By preparing for different scenarios, companies can develop
contingency plans to address potential risks.
• Employee Training and Awareness: Regular training programs ensure that employees are aware
of potential risks and know how to respond to them. This includes cybersecurity training to
prevent data breaches and safety training to reduce workplace accidents
• Diversification: Companies diversify their supply chains and investment portfolios to reduce
dependency on a single source. This helps mitigate risks associated with geopolitical tensions,
natural disasters, or market fluctuations.
• Technology and Automation: Leveraging technology and automation to monitor and manage
risks in real-time. For instance, using AI to detect anomalies in financial transactions or
employing automated systems to ensure compliance with regulations.



2. What is risk?
How to handle risk?

This course explores the practice of “enterprise risk management” (ERM), “internal control” (IC)
or “integrated risk and control management”– an established managerial outlook on managing
risk

1. Enterprise risk management: considers all the risks faced by the firm and attempts to
integrate these disparate risks into a single unified analytical framework
2. Integrated risk and control management: Traditionally, risk has been managed in the
compartments of financial risk, operating risk, credit risk, etc. Rather than allowing risk
to remain in such “silos,” ERM insists that these must be brought together into
one system of risk management.
3. “(Internal) Control”: control mechanisms are all those arrangements and procedures in
place to ensure that business objectives may be met



What is risk
DEFINITION
• Definition of risk (ISO Guide 73):
- “Risk is the effect of uncertainty on objectives”
- “risk is everything that threatens you from achieving your goals
• Links risk to objectives
• Effect may be negative, positive or a deviation from expectations
• Negative risk = opportunity

• Risk management is not about killing every possible risk because this will also kill
your business. But it’s about balancing risks and rewards

• Therefore, risk may be considered to be related to :
- A loss
- An opportunity
- The presence of an uncertainty for an organization

“All courses of action are risky, so prudence is not in avoiding
danger (it’s impossible), but calculating risk and acting decisively.

Infos sur le Document

Publié le
7 août 2026
Nombre de pages
95
Écrit en
2025/2026
Type
Resume
€7,06

Mauvais document ? Échangez-le gratuitement Dans les 14 jours suivant votre achat et avant le téléchargement, vous pouvez choisir un autre document. Vous pouvez simplement dépenser le montant à nouveau.
Rédigé par des étudiants ayant réussi
Disponible immédiatement après paiement
Lire en ligne ou en PDF

Vendu
1
Abonnés
0
Éléments
8
Dernière vente
6 mois de cela



Pourquoi les étudiants choisissent Stuvia

Créé par d'autres étudiants, vérifié par les avis

Une qualité sur laquelle compter : rédigé par des étudiants qui ont réussi et évalué par d'autres qui ont utilisé ce document.

Le document ne convient pas ? Choisis un autre document

Aucun souci ! Tu peux sélectionner directement un autre document qui correspond mieux à ce que tu cherches.

Paye comme tu veux, apprends aussitôt

Aucun abonnement, aucun engagement. Paye selon tes habitudes par carte de crédit et télécharge ton document PDF instantanément.

Student with book image

“Acheté, téléchargé et réussi. C'est aussi simple que ça.”

Alisha Student

Foire aux questions