Kultuuriministeerium · 22. märts 2023
Sisu (failidest)
Public Integrity Indicators
Effectiveness of internal control and risk management mechanisms
for safeguarding public integrity
Principle 10 (Risk Management) of the OECD Recommendation of the
Council on Public Integrity
2
Effectiveness of internal control and risk management
mechanisms for safeguarding public integrity
Internal control and risk management mechanisms are essential for safeguarding public integrity in the
public sector. Policies and regulations are needed to establish direction and minimum standards, and
some coordination and monitoring functions are needed at the central government level to ensure
coherence and provide oversight. Ultimately, outcomes depend on practices in budget organisations.
The indicators focus on what matters most for the public integrity system and do not cover all areas
relevant for the general effectiveness of public sector organisations or the internal control and risk
management framework. Reporting arrangements are assessed, but specific whistle-blower
procedures are examined in the indicators for Principles 4 and 8.
Indicators Values
1. Regulatory framework for internal control. X/12
2. Regulatory framework for internal audit (IA). X/10
3. Risk management framework. X/5
4. Coverage of functions to implement internal control and internal audit. X/7
5. Reporting on internal control and internal audit. X/11
6. Internal audit and risk-based approaches in practice. X/11
7. Use of integrity risk management in budget organisations in practice. X/10
8. National budget organisations covered by internal audit. %
9. National budget organisations audited in the past five years. %
10. Adoption rate for internal audit recommendations. %
11. Implementation rate for internal audit recommendations. %
12. [staff survey]. %
PUBLIC INTEGRITY INDICATORS – RISK MANAGEMENT
3
Indicator 1: Regulatory framework for internal control.
Review of relevant regulations for internal control (IC), including, regulations specific to financial control and risk management
and regulations for internal audit (IA).
The criteria below are based on COSO 2013 IC-IF, IIA IPPF standards 2017, and INTOSAI GOV 9100 and 9130.
The following criteria are part of this indicator:
1. One central government institution is responsible for developing the IC and IA framework, coordinating and
monitoring the implementation of IC across the public sector.
2. The definition of IC and IA in policy or regulatory documents are defined according to international standards.1
3. Regulations on IC define managerial responsibility regarding the implementation of IC and IA, and objectives of IC.
4. Regulations on IC establish annual IC and IA reporting activities, and responsibilities of Central Harmonisation Unit
(CHU).
5. Guidelines on fraud and corruption prevention are available and part of the IC framework.
6. Regulation on financial management make reference to regulations on IC.2
7. Regulations for implementing internal control are applicable to all central and all sub-national government institutions,
including social security funds.
8. Standards of conduct and ethical behaviour are published and applicable for ministers.
9. Standards of conduct and ethical behaviour are published and applicable for members of parliament.
10. Standards of conduct and ethical behaviour are published and applicable for other political appointees.
11. Standards of conduct and ethical behaviour are published and applicable for civil servants.
12. Standards of conduct and ethical behaviour are published and applicable for public officials.
1 COSO 2013 IC-IF, IIA IPPF standards 2017, and INTOSAI GOV 9100 and 9130.
2 Financial management regulations cover budget, accounting and treasury regulations. These can be separate or consolidated. Regulations on IC
cover as a minimum budget planning, execution, accounting, registry of commitments, expenditure controls, and information technology applications.
PUBLIC INTEGRITY INDICATORS – RISK MANAGEMENT
4
Indicator 2: Regulatory framework for internal audit.
Review of the regulations established for the internal audit (IA) function.
The criteria below are based on the IIA IPPF Standards 2017, and INTOSAI GOV 9140 professional standards.
The following criteria are part of this indicator:
1. The regulatory framework specifies the operational arrangements for IA.3
2. The regulatory framework specifies the scope of work as well as the minimum organisational requirements and size
of these units (minimum two persons per unit).
3. The regulatory framework allows IA arrangements to differ depending on the type and size of the institution.
4. Standards directly aimed at the conduct and ethical behaviour of internal auditors are published.
5. The regulatory framework stipulates that the head of the IA function has direct and unrestricted access to political
staff and senior managers of all public sector bodies.
6. The regulatory framework stipulates the independence of the IA function in determining the scope of internal auditing,
performing work, and communicating results.
7. The regulatory framework prohibits internal audit staff to audit operations for which they have previously been
responsible to avoid any perceived conflict of interest.
8. The regulatory framework requires the Internal Audit Unit (IAU) to develop an internal audit activity manual based on
Central Harmonisation Unit (CHU) standard methodology or guidelines, and international standards. 4
9. Quality assessments of IA activity are required by the regulation to be performed no less than once in 5 years by a
party independent from the IA organisation.
10. The regulatory framework stipulates that the head of IAU must provide annual activity reports to the CHU.
Indicator 3: Risk management framework.
Review of risk management regulations adopted at the central government level.
The criteria below are based on COSO 2017 ERM Framework, ISO 31000:2018, ISO 37301:2021, ISO 37001:2016, and ACFE
2016 Fraud Risk Management Framework.
The following criteria are part of this indicator:
1. A risk management framework exists.
2. Public integrity risks are explicitly addressed in the risk management framework.
3. The risk management framework explicitly delegates responsibility for conducting risk assessments to management,
not internal auditors.
4. Risk assessments must be documented, and an entity-wide risk register or fraud risk profile must be prepared.
5. Processes and procedures are established for addressing the risks and actions that management must take,
including reporting procedures or addressing weaknesses in the internal control system.
3 As a minimum which public sector bodies are obliged to establish an IA unit and how IA services are provided to other public sector bodies not
obliged to have an IA unit.
4 Applicable international standards include the IIA IPPF Standards 2017, and INTOSAI GOV 9140, ISA 610, and ISSAI 1610 professional standards.
PUBLIC INTEGRITY INDICATORS – RISK MANAGEMENT
5
Indicator 4: Coverage of functions to implement internal control and internal audit.
Review of the mandate and specific duties of the central government body responsible for co-ordinating and monitoring
implementation of internal control (IC) and internal audit (IA) activities. This is often described as the central harmonisation
function or the central harmonisation unit (CHU).
The criteria below are based on COSO 2013 IC-IF, IIA IPPF standards 2017, INTOSAI GOV 9100, and 9130 and the EU PIC
model.
The following criteria are part of this indicator:
1. One central government body (CHU) is responsible for developing the IC system and the IA activity.
2. The CHU is responsible for developing and promoting IC and IA methodologies based on internationally accepted
standards and best practices.
3. The CHU is responsible for reviewing the quality and functioning of the IC system and the IA function.
4. The CHU has conducted a government-wide review on the functioning of the IC system and IA function, annually
during the last 3 years.
5. The CHU has informed budget organisations in writing each year for the past three years about the good practices
and the main foreseen risks based on a government-wide review of the annual reports on IC.
6. The CHF/CHU coordinates the training and certification system to ensure the inclusion of new IA staff and the
continuous professional education.
7. Guidelines on assessing integrity risks have been issued within the last 5 years by the CHU to all public sector
institutions implementing IC.
Indicator 5: Reporting on internal control and internal audit.
Review of reports for internal control (IC) and internal audit (IA). It can be one report or two separate reports.5 The annual
report refers to a summary of all individual IC reports.
The following criteria are part of this indicator:
1. All central government institutions that are required to implement IC reported on actions taken to the ministry
responsible for IC policy (CHU) in the latest full calendar year.
2. The annual reports on IC from the past 3 years cover all five IC elements.6
3. The annual reports on IC from the past 3 years present the rates of implementation 7 of IA and Supreme Audit
Institution (SAI) recommendations.
4. The annual reports on IC for the past 3 years are publicly available.
5. The annual reports on IC were shared with the SAI for the past three years or published.
6. The latest annual reports on IC from the past 3 years included summary statistics of auditing, and a summary of self-
assessments of internal control and risk management activities.
7. The latest annual reports on IC from the past 3 years included aggregated information from the sub-national level.
8. The latest annual report on IC or IA contained a dedicated section or data on integrity, anti-corruption or fraud risks
and controls.
9. More than 50% of public sector bodies covered by IC provided a self-assessment report regarding the maturity of
their IC systems during the latest full calendar year.
10. An intergovernmental organisation has conducted a review of the internal control system within the past 5 years.
5 One report which integrates IC and IA. Or a separate report for each.
6 INTOSAI, Guidelines for Internal Control Standards for the Public Sector, INTOSAI GOV 9100, Available at
https://www.issai.org/pronouncements/endorsed-as-intosai-gov-9100/; COSO (2013), Internal Control - Integrated Framework. The five elements
would be: Control Environment, Risk Assessment, Control Activities, Information and Communication, and Monitoring Activities.
7 “Implemented” means that management completed the actions required to address the recommendation from internal audit.
PUBLIC INTEGRITY INDICATORS – RISK MANAGEMENT
6
11. The SAI has conducted a review of the IC system within the past 5 years.
Indicator 6: Internal audit and risk-based approaches in practice.
Review of data provided by Central Harmonisation Unit (CHU) or the ministry responsible for co-ordinating the development of
internal audit (IA). For criteria 6 to 10, a sample is taken to review practice. The sample organisations include all ministries and
the 10 central government agencies reporting directly to a ministry, the Government, or the central budget authority with the
largest budgets.
The following criteria are part of this indicator:
1. IA units are staffed according to legal requirements, and their staff includes at least 2 auditors (to meet IIA standards
for internal quality control).
2. A certification scheme for IA professionals is operational at the national level.8
3. At least 85% of public officials performing internal audit functions have obtained a national or international certificate
for IA.
4. Audit charters are adopted by heads of institutions for all sample organisations.9
5. Audit procedure manuals are adopted by heads of institutions for all sample organisations.
6. Reports from the IA unit are submitted directly to the managing body10 of the institution for all sample organisations.11
7. Annual activity reports from all the IA units are submitted to the CHU.
8. Audit plans in all sample organisations use data from an entity-wide risk register and the IA function’s risk assessment
to select areas to audit within the defined audit universe.
9. Audit plans in all sample organisations include integrity-specific objectives aimed at reducing fraud and other public
integrity risks.
10. At least 90% of IA reports in sample organisations include the results of IC assessment in the audited area.
11. External quality assurance has been conducted of the IA function with the last 5 years.
Indicator 7: Use of integrity risk management in budget organisations in practice.
Review of data provided by the central government body responsible for risk management. Α sample is taken to review practice.
The sample organisations include all ministries and the 10 central government agencies reporting directly to a ministry, the
Government, or the central budget authority with the largest budgets. Integrity risk assessments have to be conducted within
the past 2 years.
The following criteria are part of this indicator:
1. All sample organisations have conducted at least one risk assessment exercise in the past 3 years.
2. Roles and responsibilities for risk management and for managing integrity risks have been assigned in all budget
organisations, in line with the regulatory framework.
3. All sample organisations have established a system for documenting the results of risk assessments, including as a
minimum creating risk profiles or risk registers.
4. The entity with direct responsibility for managing integrity risks is not part of the IA function, compliance department,
or legal counsel and reports directly to the head of the institution in all sample organisations.
5. Integrity risk assessments for all sample organisations identify both inherent and residual risks.
6. Integrity risk assessments for all sample organisations identify both internal and external, as well as current and
emerging, integrity risks.
7. Integrity risk assessments for all sample organisations include an examination of existing controls and whether
changes are needed in the control environment (i.e. risk treatment).
8 Includes for example IIA professional designations as well as other schemes delivered by universities, national schools of public administration and
professional certifications relating with audit functions such as ACCA, CA, CPA, CFE, and CISA.
9 As a minimum detailing the IA legislation in terms of roles and responsibilities as well as reporting arrangements.
10 Can be either a monocratic or collective body, such as a Director or a Board.
11 For example, IA reports should not be submitted to the Secretary-General for review before submitted to the minister.
PUBLIC INTEGRITY INDICATORS – RISK MANAGEMENT
7
8. Integrity risk assessments for all sample organisations apply either a qualitative or quantitative scoring methodology
(e.g. risk likelihood, impact and velocity) that enables prioritisation of high versus low risks.
9. Guidance documents on managing integrity risks, including red flags for corruption and fraud risks that are relevant
for the entity’s operations, exist for all sample organisations.
10. The IA function has reviewed the adequacy and effectiveness of the risk management policies and processes for all
sample organisations within the past 3 years.
Indicator 8: National budget organisations covered by internal audit.
The analysis is carried out based on the number of total organisations that are actually covered by internal audit (IA) regulations,
divided by the number of all public organisations in the country financed by public funds (national budget), expressed as a
percentage.12 Public organisations included in the IA mandate are defined by the IA charter or regulation (audit universe),
which legally represent a range of potential audit activities to be carried out by the audit function, consisting of auditable entities,
processes, systems and activities. This indicator measures the de jure share of national organisations covered by IA regulation.
Indicator 9: National budget organisations audited in the past five years.
The analysis is carried out based on the number of actual organisations that were audited in the past 5 years divided by the
number of all public organisations in the country financed by public funds (national budget).13 Public organisations included in
the internal audit (IA) mandate are defined by the IA charter or regulation (audit universe), which legally represent a range of
potential audit activities to be carried out by the audit function, consisting of auditable entities, processes, systems and
activities. This indicator measures the de facto share of national budget audited in the past 5 years.
Indicator 10: Adoption rate for internal audit recommendations.
Review of data from the CHU or the ministry responsible for co-ordinating the development of internal audit (IA) to identify the
share of IA recommendations made during the year prior to the latest full calendar year that were adopted within one year.
“Adopted” means that the recommendation was accepted by management and they intend to act on it. The same data request
is made to the Supreme Audit Institution. If no central statistics have been collected a sample is taken that includes as a
minimum all ministries and central government agencies. The adoption rate is expressed as a percentage of the total number
of recommendations.
Indicator 11: Implementation rate for internal audit recommendations.
Review of data from the CHU or the ministry responsible for co-ordinating the development of internal audit (IA) to identify the
share of IA recommendations made during the year prior to the latest full calendar year that were implemented within one year.
“Implemented” means that management completed the actions that addressed the recommendation from internal audit. The
same data request is made to the Supreme Audit Institution. If no central statistics have been collected a sample is taken that
includes as a minimum all ministries and central government agencies. The implementation rate is expressed as a percentage
of the total number of recommendations.
Indicator 12: [STAFF SURVEYS].
[To be developed].
12 This information can usually be derived from the annual activity reports from the IA units that are submitted to the CHU.
13 This information can usually be derived from the annual activity reports from the IA units that are submitted to the CHU.
PUBLIC INTEGRITY INDICATORS – RISK MANAGEMENT
8
Glossary
Audit universe: The range of organisations and activities that can be audited.
Budget organisation (or spending unit): Public body having a separate financial plan.
Central Budget Authority (CBA): A public entity, or several co-ordinated entities, located at the central/national/federal level
of government, which is responsible for the custody and management of the national/federal budget and is the hub of the
central government budget process.
Central government: The central government consists of the institutional units controlled and financed at the central level plus
those NPIs (non-profit institutions) that are controlled and mainly financed by central government. The political authority of
central government extends over the entire national territory and the national economy, and central government has therefore
the authority to impose taxes on all residents and non-resident units engaged in economic activities within the country.
CHU: A policy unit attached and directly reporting to the Minister of Finance on the status of internal control in the entire public
sector, responsible for redesigning, updating and maintaining the quality of internal control systems, for harmonising and co-
ordinating definitions, standards and methodologies, for networking between all actors (managers, financial officers, internal
auditors), for the establishment and co-ordination of sustainable training facilities, including the setting of criteria for the
certification of public internal auditors, and for all other actions to improve pubic internal control systems.
Conflict-of-interest: Situations involving a conflict between the public duty and the private interests of a public official, in which
the public official has private-capacity interests, which could improperly influence the performance of their official duties and
responsibilities.
Financial management cycle: A process of budgeting, accounting, auditing, and reviewing and evaluating.
Five IC elements: Control Environment, Risk Assessment, Control Activities, Information and Communication, and Monitoring
Activities.
Government: 'The Government' is usually taken to define the individuals who exert political power over the state and its
institutions at a given time (for example the prime minister, ministers and ministers without portfolio). The Government is thus
the particular group of people that controls the state apparatus at a given time, and is the means through which state power is
employed (for example the adoption of laws). In a democracy, the state is served by a continuous succession of different
Governments. The number of Governments is determined by the number of terms served by the head of the executive branch
(where a term is defined by a change in the executive or an election that renewed support for the incumbent government).
Government in this definition is not the same as the use of the term government in a statistical or expenditure context.
Inherent risk: Inherent risks are risks assessed in the absence of control measures.
Internal audit activity manual/audit procedure manual: A document that set out internal audit policies and procedures and
to provide essential guidelines to the internal audit staff in performing the internal auditing activities. The internal audit process
manual determines the planning of the activities of the internal audit service, the procedure for carrying out the internal audit
process and consulting activities, the rights and duties of the internal auditor and the head of internal audit. The Manual
describes the generic processes for establishing risk based annual audit plans, planning and conducting audit engagements
and reporting the results of the audit work. The use of the Manual should help bring a systematic and disciplined approach to
the audit of governance, risk management and control processes and assist the Internal Auditor meet the goal of adding value
to their respective organizations. Procedures and processes for maintaining a quality internal audit service are also provided
to enhance the quality and effectiveness of the Internal Audit Service by paving the way to put into practice procedures and
processes that would help it conform to legal requirements, professional standards and best practices.
Internal audit charter: A formal document that defines internal audit’s purpose, authority, and responsibility. The charter
establishes internal audit’s position within the organisation; including reporting relationships for the Head of Internal Audit;
authorises access to records, personnel, and physical properties relevant to the performance of engagements; and defines the
scope of internal audit activities.
Internal Audit Unit (IAU): A unit responsible for internal audit. The term unit is used to refer to Departments, Directorates,
Sections, or any other organizational segment that can be identified within the Centre of Government.
Internal audit: Internal audit is an independent, objective assurance and consulting activity designed to add value and improve
an organisation's operations. Internal audit helps an organisation accomplish its objectives by bringing a systematic, disciplined
approach to evaluate and improve the effectiveness of risk management, control, and governance processes.
Internal control objectives: A set of goals that demonstrate managers’ commitment to public integrity and public-service
values, and that provides a reasonable level of assurance of an organisation’s efficiency, performance and compliance with
laws and practices. These objectives relate to the risk assessment element of COSO and INTOSAI and focus on the ultimate
aim of IC rather than mere procedures.
Internal control: Internal control refers to the organisation, policies and procedures used to help ensure that government
programmes achieve their intended results; that the resources used to deliver these programmes are consistent with the stated
PUBLIC INTEGRITY INDICATORS – RISK MANAGEMENT
9
aims and objectives of the organisations concerned; that programmes are protected from waste, fraud and mismanagement;
and that reliable and timely information is obtained, maintained, reported and used for decision making. Internal control has
been broadly defined by the Committee of the Sponsoring Organizations of the Tredway Commission (COSO – www.coso.org)
as: “a process effected by an entity’s management designed to provide reasonable assurance regarding the achievement of
objectives in the following categories: (i) Effectiveness and efficiency of operations; (ii) Reliability of financial reporting; and (iii)
Compliance with applicable laws and regulations.”
Ministry: An organisation which forms part of the central core of the executive branch of government. A ministry is responsible
for the design and implementation of an area or sector of public policy and administration (e.g. agriculture, education, economy,
foreign affairs), in line with the government programme and strategy. A ministry is also responsible for the direction of agencies
under its authority. In some countries, such as Australia, Norway, the United States and the United Kingdom, ministries are
called 'departments'. Sub-national governments may also be organised into ministries. A ministry has a delegated budget to
exercise its responsibilities, under the authority and direction of the finance ministry or equivalent organisation responsible for
the budget in central government.
Public integrity: Public integrity refers to the consistent alignment of, and adherence to, shared ethical values, principles and
norms for upholding and prioritising the public interest over private interests in the public sector.
Regulation: Decisions and instruments implemented within the framework of public actions, directly or indirectly, to improve
social welfare. Regulation includes laws and regulations but also administrative formalities, code of conduct, etc.
Residual risk: Residual risks refers to perceived risk exposure after applying mitigation strategies and controls.
Risk assessment: A systematic process for assessing and integrating professional judgements about probable adverse
conditions and/or events. The risk assessment process should provide means of organising and integrating professional
judgements for development of the work schedule. Risk assessments are iterative processes that allow an organisation to
understand the enablers and barriers to its objectives, based on an analysis of inherent and residual risks. Risk assessments
serve to identify and evaluate risks for use in guiding the audit procedures, necessary to substantiate the amounts reported in
the financial statements.
Risk management: A process to identify, assess, manage, and control potential events or situations to provide reasonable
assurance regarding the achievement of the organisation’s objectives.
Risk profile: A composite view of the risk that may affect performance relative to the strategy and objectives.
Risk register: The risk register outlines the overall system of risks and the status of risk mitigation actions.
Risk treatment: The options and choices available to respond to or manage a risk. Examples of risk treatments include the
mitigation, transfer/sharing, avoidance, acceptance, and pursuit of risk.
Social security funds: Social security funds are defined as social insurance schemes covering the community as a whole.
These schemes may be either funded or unfunded. Those schemes established by government units to cover their own
employees only are not counted as social security schemes in the general government sector. For example, the financial assets
of pension funds for government employees are not included as financial assets of the government sector, but rather belong
in the insurance sector.
Supreme audit institution: A supreme audit institution (SAI), or national audit institution, fulfils the independent and technical
public sector external audit function that is typically established within a country’s constitution or by the supreme law-making
body. A SAI is responsible for overseeing and holding government to account for its use of public resources, together with the
legislature and other oversight bodies. SAIs have different models and institutional arrangements regarding the legislature,
executive and judiciary. Where there is more than one body fulfilling the public sector external audit role, the SAI is usually
distinguished as possessing the strongest constitutional guarantees of independence.
PUBLIC INTEGRITY INDICATORS – RISK MANAGEMENT
Public Integrity Indicators: Explanatory Note
Since the adoption of the OECD Council Recommendation on Public Integrity in 2017, a Task
Force consisting of nine members of the Working Party of Senior Public Integrity Officials
(SPIO)1 has been developing a set of indicators (Public Integrity Indicators) to “measure the
successful implementation of the OECD Recommendation on Public Integrity”.2 They
complement the Public Integrity Handbook and the maturity models.
The Public Integrity Indicators for the OECD Recommendation of the Council on Public Integrity
were validated for piloting in November 2019 by the SPIO and underwent expert
consultations in May 2020. The framework establishes standard indicators for the
preparedness and resilience of the public integrity system at the national level to prevent
corruption, mismanagement and waste of public funds, and to assess the likelihood of
detecting and mitigating various corruption risks by different actors in the system.3 The scope
of the Recommendation requires data collection from a wide range of actors across the
executive, legislative and judiciary branches.
The value added of the Public Integrity Indicators is to provide policy makers and practitioners
with an international perspective on the state of play for relevant parts of the integrity
system, and offer a credible alternative to existing indices. The purpose is not to rank
countries, but rather to identify the multiple steps that can be taken to strengthen core parts
of the integrity system. Finally, the successful implementation of the indicators will help
enhance the capacity of countries to measure corruption, corruption risks, effects of anti-
corruption interventions and the resilience of the public integrity system and will provide an
evidence-based approach to developing and implementing better integrity policies for better
lives.
For a brief introduction on the main underpinning principles and design features of these
indicators see this video produced for the expert consultations in May 2020.
You can also access the OECD Public Integrity Indicators Portal. This page here shows the main
radar where the data will feature for Principle 10 on Effectiveness of internal control and
risk management mechanisms for safeguarding public integrity (Risk management).
1
The SPIO Task Force members are delegates from Austria, Brazil, France, Germany, Italy, the
Netherlands, Poland, the United Kingdom and Slovakia
2
As described in the 2017 Roadmap for the Task Force on OECD Public Integrity Indicators.
3
These indicators combine sub-indicators establishing minimum legal, procedural and institutional
safeguards for the independence, mandate and operational capability of essential actors in the integrity
system with more outcome-oriented sub-indicators drawing on administrative data and surveys.
1
.10. Risk management - Ministry 8 Please provide the following information for your Ministry. Please provide the name of your organisation and a link to your website. [Draft] Answer: Ministry of Culture (https://www. kul .ee/) Is an audit charter in place for your organisation? If yes, please upload the charter. [Open for answering] Answer: Explanation: Was it adopted by the head or managing body of the institution? [Open for answering] Yes. No. Explanation: Does it describe the roles and responsibilities in alignment with the internal audit legislation? [Open for answering] Yes. No. Explanation: Does it describe reporting arrangements? [Open for answering] Yes. No. Explanation: Is an audit procedure manual in place for your organisation? If yes, please upload the manual. [Open for answering] Yes. No. Explanation: Was it adopted by the head or managing body of the institution? [Draft] Answer: Explanation: What proportion of internal audit reports were submitted directly to the head or managing body of your organisation during the latest full calendar year? [Open for answering] 100% 75-99.99% 50-74.99% 25-49.99% 0-24.99% Internal audit reports are, as a rule, never sent directly to the head or managing body of your organisation. Explanation: Please provide documentation that describes the approach to audit selection in your organisation (for example, an audit strategy, audit plan, or audit universe). [Open for answering] Answer: Explanation: Has your organisation conducted a risk assessment exercise? [Open for answering] Yes. No. Explanation: If "Yes.": Please provide documentation. Answer: Explanation: If "Yes.": When was the last time your organisation conducted a risk assessment exercise? Answer: Explanation: Please provide documentation that roles and responsibilities for risks management in general, and for managing integrity risks in particular, have been assigned in your organisation in line any relevant regulations. [Open for answering] Answer: Explanation: Has your organisation established a system for documenting the results of risk assessments, including as a minimum creating risk profiles or risks registers? See glossary. [Open for answering] Yes. No. Explanation: Please provide documentation. [Open for answering] Answer: Explanation: Which of the following entities has direct responsibility for designing, implementing and monitoring policies for managing integrity risks in your organisation? Please upload documentation (for example an organigram). [Open for answering] The internal audit function . The compliance department. The legal counsel/legal office. Another entity separate from the three above. There is no such responsibility established. The responsibility is shared across several units in the organisation. Other (please explain in the comment field). Explanation: Please upload the three most recent risks assessments that covered integrity themes and include any evidence on how results of risk assessments are systematically documented. [Open for answering] Answer: Explanation: Please provide any guidance documents in place within your organisation on managing integrity risks, including red flags for corruption and fraud risks that are relevant for the entity’s operations. [Open for answering] Answer: Explanation: How many internal audit recommendations were issued for your organisation the year prior to the latest full calendar year? [Open for answering] Answer: Explanation: Of these, how many recommendations were adopted by management within a year (the latest full calendar year)? [Open for answering] Answer: Explanation: Of these, how many recommendations were implemented by management within a year (the latest full calendar year)? [Open for answering] Answer: Explanation: Has the internal audit (IA) function of your organisation undergone external quality assurance? [Open for answering] Never. Yes, within the past 5 years. Yes, but it’s been longer than 5 years. Explanation: If "Yes, within the past 5 years.": Please provide documentation. Answer: Explanation: Please provide the name of your organisation and a link to your website. [Draft] Answer: Explanation: Is an audit charter in place for your organisation? If yes, please upload the charter. [Open for answering] Answer: Explanation: Was it adopted by the head or managing body of the institution? [Open for answering] Yes. No. Explanation: Does it describe the roles and responsibilities in alignment with the internal audit legislation? [Open for answering] Yes. No. Explanation: Does it describe reporting arrangements? [Open for answering] Yes. No. Explanation: Is an audit procedure manual in place for your organisation? If yes, please upload the manual. [Open for answering] Yes. No. Explanation: Was it adopted by the head or managing body of the institution? [Draft] Answer: Explanation: What proportion of internal audit reports were submitted directly to the head or managing body of your organisation during the latest full calendar year? [Open for answering] 100% 75-99.99% 50-74.99% 25-49.99% 0-24.99% Internal audit reports are, as a rule, never sent directly to the head or managing body of your organisation. Explanation: Please provide documentation that describes the approach to audit selection in your organisation (for example, an audit strategy, audit plan, or audit universe). [Open for answering] Answer: Explanation: Has your organisation conducted a risk assessment exercise? [Open for answering] Yes. No. Explanation: If "Yes.": Please provide documentation. Answer: Explanation: If "Yes.": When was the last time your organisation conducted a risk assessment exercise? Answer: Explanation: Please provide documentation that roles and responsibilities for risks management in general, and for managing integrity risks in particular, have been assigned in your organisation in line any relevant regulations. [Open for answering] Answer: Explanation: Has your organisation established a system for documenting the results of risk assessments, including as a minimum creating risk profiles or risks registers? See glossary. [Open for answering] Yes. No. Explanation: Please provide documentation. [Open for answering] Answer: Explanation: Which of the following entities has direct responsibility for designing, implementing and monitoring policies for managing integrity risks in your organisation? Please upload documentation (for example an organigram). [Open for answering] The internal audit function . The compliance department. The legal counsel/legal office. Another entity separate from the three above. There is no such responsibility established. The responsibility is shared across several units in the organisation. Other (please explain in the comment field). Explanation: Please upload the three most recent risks assessments that covered integrity themes and include any evidence on how results of risk assessments are systematically documented. [Open for answering] Answer: Explanation: Please provide any guidance documents in place within your organisation on managing integrity risks, including red flags for corruption and fraud risks that are relevant for the entity’s operations. [Open for answering] Answer: Explanation: How many internal audit recommendations were issued for your organisation the year prior to the latest full calendar year? [Open for answering] Answer: Explanation: Of these, how many recommendations were adopted by management within a year (the latest full calendar year)? [Open for answering] Answer: Explanation: Of these, how many recommendations were implemented by management within a year (the latest full calendar year)? [Open for answering] Answer: Explanation: Has the internal audit (IA) function of your organisation undergone external quality assurance? [Open for answering] Never. Yes, within the past 5 years. Yes, but it’s been longer than 5 years. Explanation: If "Yes, within the past 5 years.": Please provide documentation. Answer: Explanation: