Internal audit can take a 5-step approach to providing assurance over an organization's risk management culture.
If culture is “how things are done when no one is looking,” then risk management culture is “how risks are managed when those at the top aren’t looking.” Internal audit can take a five-step approach to auditing the organization’s risk management culture.