Risk is present in every human activity, and particularly in economic and financial ones. The economic and financial activities of States and of businesses alike carry numerous risks of varying kinds.
Identifying, assessing and managing those risks is therefore part of the strategic development of a State or a business, and must be designed and planned at the highest level:
at State level, by the Council of Ministers or any equivalent body;
at company level, by the Board of Directors or any equivalent body.
An integrated approach to risk management must assess, control and monitor every risk to which the State or the business is exposed. In general terms, a pure risk is a combination of the probability or frequency of an event and of its consequence, which may be positive or negative. It can be measured by the deviation, or volatility, from the mathematical expectation or from anticipated results. Uncertainty is less precise, because the probability of an uncertain event is often unknown, as is its consequence. In that case one speaks of precautionary activity rather than preventive activity as the protection against uncertainty. Finally there are speculative risks, which consist of undertaking opportunistic activity in relation to future risks.
A dedicated risk audit consists of identifying, analysing and assessing the risks to which your activities are exposed — economic, financial and otherwise — and then proposing a policy for managing them.
That said, to ensure the quality of our conclusions, all of our audit engagements begin with a review and analysis of risk, so that we can satisfy ourselves as the work proceeds that measures are in place to mitigate the risks identified. This is the risk-based approach.