Welcome to P3 Risk Management: Roles and Responsibilities

Hello there! Welcome to one of the most important chapters in your P3 journey. When we talk about Internal Control, it is easy to think it is just a set of rules written in a manual. But in reality, controls are only as good as the people who manage them. This chapter explores "Who does what?" when it comes to keeping an organization safe.

Don't worry if this seems a bit "dry" at first. Think of a professional sports team: the players, the coach, the referees, and the owners all have different jobs to ensure the game is played fairly and successfully. Managing risk is exactly the same!

1. The "Tone at the Top": The Board of Directors

In the world of CIMA P3, everything starts with the Board of Directors. They are ultimately responsible for the company’s system of internal control. They don't necessarily "do" the daily checks, but they are the ones who answer for them if things go wrong.

Key Responsibilities of the Board:

1. Setting the Strategy: They decide how much risk the company is willing to take (this is known as Risk Appetite).
2. Reviewing Effectiveness: Under corporate governance codes (like the UK Corporate Governance Code), the Board must review the effectiveness of the control systems at least annually.
3. Culture: They establish the "Tone at the Top," meaning they demonstrate through their actions that honesty and control are important.

Quick Analogy: The Board is like the Captain of a Ship. They don't personally scrub the deck or cook the food, but if the ship hits an iceberg because the lookout was asleep, it’s the Captain’s responsibility.

Key Takeaway: The Board owns the internal control framework. They are accountable to the shareholders for ensuring controls exist and work.

2. The Three Lines of Defense Model

This is a foundational concept in the CIMA P3 curriculum. If you understand this model, you understand how roles are divided to ensure no one marks their own homework!

First Line: Operational Management

These are the managers on the "front line" (e.g., Warehouse Managers, Sales Heads). They own the risks and are responsible for implementing controls every day.
Example: A shop manager making sure the till is locked at night.

Second Line: Risk Management and Compliance

These functions oversee the first line. They don't run the business day-to-day, but they provide the frameworks and tools. They monitor whether the first line is following the rules.
Example: A Compliance Officer checking if the shop manager's paperwork is correct.

Third Line: Internal Audit

This is the Independent Assurance. They sit apart from the first two lines. They report directly to the Board (usually via the Audit Committee) to give an unbiased opinion on whether the controls are actually working.
Example: An auditor coming from Head Office to test the security systems of all shops.

Memory Aid: 1-2-3 Defense
1. Doers (Operations)
2. Helpers/Checkers (Risk/Compliance)
3. Judges (Internal Audit)

3. The Role of Executive Management

While the Board has oversight, the CEO and Senior Management have ownership of the implementation. They are the ones who design the specific controls and ensure that staff have the resources to follow them.

Did you know? In some jurisdictions, like the USA under the Sarbanes-Oxley Act (SOX), the CEO and CFO must personally sign off on the accuracy of internal controls. That's a huge responsibility!

4. The Audit Committee

The Audit Committee is a sub-committee of the Board, made up of Non-Executive Directors (NEDs). Their role is specifically focused on oversight of the financial reporting and internal control process.

Why do we need them?

Because they are "independent" (they don't work for the company full-time), they can challenge the CEO and CFO without fear of being fired. They act as a bridge between the Internal/External Auditors and the Board.

Common Mistake to Avoid: Many students think the Audit Committee performs the audits. They don't! They review the results of the audits and ensure management takes action on the findings.

5. Internal Audit vs. External Audit

It is vital to distinguish between these two roles in your exam:

Internal Audit:
- Appointed by the Board/Audit Committee.
- Focuses on all risks (operational, strategic, financial).
- Aim: To improve the organization’s operations.

External Audit:
- Appointed by the Shareholders.
- Focuses primarily on the financial statements.
- Aim: To provide an opinion on whether the accounts are "true and fair." They only look at internal controls to see if they can trust the numbers in the system.

Quick Review Box:
- Board: Ultimate accountability.
- Audit Committee: Oversight and independence.
- Internal Audit: Testing and reporting on control effectiveness.
- Employees: Following the controls in their daily tasks.

6. The Role of Every Employee

Finally, don't forget that Internal Control is everyone's responsibility. Even the most junior employee has a role. If a staff member notices a security door is left open and fails to report it, the entire control system has failed.

Organizations encourage this through Whistleblowing Policies, which allow employees to report control failures or unethical behavior anonymously.

Chapter Summary

Managing risk isn't a solo sport. The Board sets the strategy, Management implements it, the Three Lines of Defense provide structure and checking, and the Audit Committee ensures the whole process is transparent and honest. When everyone understands their role, the organization is much more likely to achieve its objectives while staying within its risk appetite.

Keep going! You're doing great. Understanding these roles is the "skeleton" that holds the rest of the Risk Management curriculum together!