Category: Risk & Advisory

Cybersecurity and Privacy Become Key ESG Imperatives

Cybersecurity and privacy issues have become prominent ESG concerns as organizations frequently manage sensitive information concerning their beneficiaries, employees, third parties, and other stakeholders. Protecting this data from cyber threats and ensuring privacy is a crucial responsibility, as stakeholders expect organizations to have robust cybersecurity measures in place to safeguard their personal information. Failure to…

Read more ›

Risk Management is on the Rise at Not-For-Profit Organizations

2023 State of Risk Oversight Survey Results By Amy Wares, CPA, MBA, Enterprise Risk Management Specialist Managing risk is more challenging than ever. New research reveals that not-for-profit organizations are responding by expanding their risk management practices. On July 11, 2023, the Enterprise Risk Management (ERM) Initiative at NC State University published the 14th edition…

Read more ›

Best Practices for Mitigating Risk in Expense Reporting Platforms

Expense reporting platforms have simplified the review and approval processes, making it easier to submit documentation for payment. However, this convenience can also lead to less stringent review of submitted documents and opportunities for changing electronic receipts. As a result, organizations need to implement best practices to reduce the risk associated with these reporting systems….

Read more ›

How Internal Audit Can Support Whistleblower Investigations

Do you know if an employee is stealing from your company?  Quite often, the first hint of a problem comes from an insider tip. Having a comprehensive whistleblower program in place is a powerful early warning mechanism for identifying potential fraud or misconduct. If you have an internal audit function, you already have the tools…

Read more ›

Essential stages of a third party risk management program

Developing and maintaining a third party risk management (TPRM) program can help to reduce the overall risk to your organization. What is TPRM?  In short, it is the process of analyzing and mitigating risks associated with working relationships with outside entities. These parties can include everyone from contractors providing janitorial services to suppliers of a…

Read more ›

Four Things You Can Do Today to Improve Your Cybersecurity Posture

Cybersecurity is always changing and evolving as threats grow. Here are ideas that you can start on today that will help reduce your risk and improve your cybersecurity posture: 1. Require Multi-Factor Authentication Having multi-factor authentication (MFA) is essential for granting access to confidential data. It helps to reduce the risk of credential loss and…

Read more ›

Workshop Highlights: Navigating the World of Uncertainties Impacting Non-Profit Organizations

The 4th Annual GRF /NC State ERM Workshop for Nonprofits was held on February 23 and 24, 2023. Nonprofit executives and board members from across the U.S. came together to share their experiences and discuss strategies and tactics for strengthening enterprise risk management at tax-exempt organizations. Melissa Musser, Partner and Director of GRF’s Risk Advisory…

Read more ›

Getting Started with Cybersecurity Training

TLDR: End user cybersecurity training is essential for preventing malicious actors from gaining unauthorized access to your organization’s network. Creating a risk-averse organization involves making your staff aware of best-practices for identifying common attacks, like phishing scams. At the end of this article, you will find a cyber hygiene template and risk checklists for privacy,…

Read more ›

Internal Audit: Preventing Fraud through Travel & Expense Reimbursement Audits

Travel & Expense (T&E) reimbursement fraud can have a significant impact on your organization. The Association of Certified Fraud Examiners’ 2022 Report to the Nations found the average loss from an expense reimbursement scheme was $152,000. The report, which is based on a worldwide survey of Certified Fraud Examiners conducted between July and September 2021,…

Read more ›

Obtaining Cyber Insurance For Your Organization

By Darren Hulem, CISA, CEH, Security+, Supervisor, IT and Risk & Advisory Services As cyberattacks grow in frequency and complexity, organizations are asking, “Is Cyber Insurance worth it?” The short answer is “Absolutely!” Before contacting an insurance company, we recommend some research and due diligence to position your organization for reasonable rates. Coverages can vary…

Read more ›