The influence of tone at the top management level and internal audit quality on the effectiveness of risk management practices in the financial services sector
Abstract
EconStor is a publication server for scholarly economic literature, provided as a non-commercial public service by the ZBW.
Full text
Kabuye, Frank; Bugambiro, Nicholas; Akugizibwe, Irene; Nuwasiima, Sharon; Naigaga, Sharon Article The influence of tone at the top management level and internal audit quality on the effectiveness of risk management practices in the financial services sector Cogent Business & Management Provided in Cooperation with: Taylor & Francis Group Suggested Citation: Kabuye, Frank; Bugambiro, Nicholas; Akugizibwe, Irene; Nuwasiima, Sharon; Naigaga, Sharon (2019) : The influence of tone at the top management level and internal audit quality on the effectiveness of risk management practices in the financial services sector, Cogent Business & Management, ISSN 2331-1975, Taylor & Francis, Abingdon, Vol. 6, pp. 1-24, https://doi.org/10.1080/23311975.2019.1704609 This Version is available at: https://hdl.handle.net/10419/244772 Standard-Nutzungsbedingungen: Die Dokumente auf EconStor dürfen zu eigenen wissenschaftlichen Zwecken und zum Privatgebrauch gespeichert und kopiert werden. Sie dürfen die Dokumente nicht für öffentliche oder kommerzielle Zwecke vervielfältigen, öffentlich ausstellen, öffentlich zugänglich machen, vertreiben oder anderweitig nutzen. Sofern die Verfasser die Dokumente unter Open-Content-Lizenzen (insbesondere CC-Lizenzen) zur Verfügung gestellt haben sollten, gelten abweichend von diesen Nutzungsbedingungen die in der dort genannten Lizenz gewährten Nutzungsrechte. Terms of use: Documents in EconStor may be saved and copied for your personal and scholarly purposes. You are not to copy documents for public or commercial purposes, to exhibit the documents publicly, to make them publicly available on the internet, or to distribute or otherwise use the documents in public. If the documents have been made available under an Open Content Licence (especially Creative Commons Licences), you may exercise further usage rights as specified in the indicated licence. https://creativecommons.org/licenses/by/4.0/
Full Terms & Conditions of access and use can be found at https://www.tandfonline.com/action/journalInformation?journalCode=oabm20 Cogent Business & Management ISSN: (Print) (Online) Journal homepage: https://www.tandfonline.com/loi/oabm20 The influence of tone at the top management level and internal audit quality on the effectiveness of risk management practices in the financial services sector Frank Kabuye, Nicholas Bugambiro, Irene Akugizibwe, Sharon Nuwasiima & Sharon Naigaga | To cite this article: Frank Kabuye, Nicholas Bugambiro, Irene Akugizibwe, Sharon Nuwasiima & Sharon Naigaga | (2019) The influence of tone at the top management level and internal audit quality on the effectiveness of risk management practices in the financial services sector, Cogent Business & Management, 6:1, 1704609, DOI: 10.1080/23311975.2019.1704609 To link to this article: https://doi.org/10.1080/23311975.2019.1704609 © 2019 The Author(s). This open access article is distributed under a Creative Commons Attribution (CC-BY) 4.0 license. Published online: 30 Dec 2019. Submit your article to this journal Article views: 2072 View related articles View Crossmark data Citing articles: 1 View citing articles
ACCOUNTING, CORPORATE GOVERNANCE & BUSINESS ETHICS | RESEARCH ARTICLE The influence of tone at the top management level and internal audit quality on the effectiveness of risk management practices in the financial services sector Frank Kabuye 1 *, Nicholas Bugambiro 1 , Irene Akugizibwe 1 , Sharon Nuwasiima 1 and Sharon Naigaga 1 Abstract: The purpose of this study is to examine the contribution made by the tone at the top management level and internal audit quality on the effectiveness of risk management practices (RMPs) in the financial services sector. This study is crosssectional and correlational, and it uses firm-level data that were collected by means of a questionnaire survey from a sample of 62 financial services firms in Uganda. Results suggest that the tone at the top management level and internal audit quality are both significant predictors of effective RMPs. However, the predictive potential of tone at the top management level towards effective RMPs reduces when internal audit quality is present. These results support the idea that in terms of agency theory, top management should oversee and review the organization’s risks as a way of spearheading effective RMPs. Similarly, internal auditors should sufficiently and appropriately review and coordinate risk management efforts in the organization, since high-quality internal Frank Kabuye ABOUT THE AUTHORS Frank Kabuye is a Lecturer in the Department of Accounting, Makerere University Business School. He holds a degree of Master of Science in Accounting and Finance and Bachelor of Business Administration of Makerere University. His research interests are in the areas of auditing, accounting, risk management and finance. Nicholas Bugambiro is a Teaching assistant in the Department of Accounting, Makerere University Business School. He holds a degree of Bachelor of Science in Accounting of Makerere University. Irene Akugizibwe, Sharon Naigaga and Sharon Nuwasiima are also Lecturers in the Department of Accounting, Makerere University Business School. They are all holders of a degree of Master of Science in Accounting and Finance of Makerere University. Their research interests are in the areas of corporate governance, taxation, financial reporting, risk management and sustainability reporting. Frank Kabuye, Nicholas Bugambiro and Sharon Nuwasiima are also certified public accountants. PUBLIC INTEREST STATEMENT To date, organizations across the world continue to seek for determinants of effective risk management practices. This is because of the increasing risks in organizations irrespective of the different efforts by management, those charged with governance and third parties such as the regulators to combat risks. Risks unfavourably affect the organizational activities and as a result, organization’s fail to achieve their desired goals and objectives. In the Ugandan financial services sector, risks such as the credit risk, operational risk, compliance risk and fraud risks are common and lead to huge annual financial and non-financial losses. This has prompted the organization’s top managers, scholars and regulators to continue seeking for ways of increasing the effectiveness of the multitudes of risk management practices in the organizations. Therefore, this study suggests that appropriate tone at the top management level and internal audit quality are significant determinants of effective risk management practices in the financial services sector. Kabuye et al., Cogent Business & Management (2019), 6: 1704609 https://doi.org/10.1080/23311975.2019.1704609 © 2019 The Author(s). This open access article is distributed under a Creative Commons Attribution (CC-BY) 4.0 license. Received: 18 September 2019 Accepted: 09 December 2019 First Published: 16 December 2019 *Corresponding author: Frank Kabuye, Accounting, Makerere University Business School, Uganda. E-mail: [email protected] Reviewing editor: Collins G. Ntim, Accounting, University of Southampton, Southampton UK Additional information is available at the end of the article Page 1 of 24
audits lead to effective RMPs. Top managers of financial services firms should encourage periodic reviews of the appropriateness and effectiveness of risk management systems and controls. At the same time, regulators should ensure that top managers of financial services firms have adequate risk management expertise, with no conflict of interest and apply mechanisms that detect significant risks in time. The study contributes to the strategic risk management position by showing that the tone at the top management level and internal audit quality sets pace for an organization culture towards effective RMPs. Subjects: Business, Management and Accounting; Accounting; Auditing; Risk Management Keywords: financial services firms; tone at the top management level; internal audit quality; risk management practices 1. Introduction The aim of this paper is to study the contribution made by the tone at the top management level and internal audit quality on the effectiveness of RMPs. As it becomes crucial for financial services firms to effectively manage prevalent risks such as credit risk, cyber risk, operational risk, compliance risk and fraud risks, implementation of effective RMPs become inevitable (PWC, 2017). The necessity to implement effective RMPs by financial services firms is ingrained in the need to enhance risk prevention, detection and reporting (Bezzina, Grima, & Mamo, 2014; Kim, 2019). Globally, the growth of profit adjusted for risk costs for financial services firms has slowed from 16 basis points overall in 2015 to 11 basis points in 2016, this is stalling economic recovery of the financial industry following five consecutive years of improvement in the aftermath of the 2007–2008 global financial crisis (Grasshoff et al., 2018). Similarly, Ernest and Young global banking outlook (2018) indicates that 85% of banks are citing proper management of evolving risks as one of the critical drivers for sustainable success. Thus, financial services firms still need effective RMPs and reforms to contain the adverse effects of risk(s) (Ahmad, Ibrahim, & Minai, 2018; Chornous & Ursulenko, 2013; Safari, Shateri, Baghiabadi, & Hozhabrnejad, 2016). In Uganda, financial services firms are continually experiencing prevalent risks. For example, in 2017 banks recorded more than 60% of non-performing loans due to factors like the diversion of funds by borrowers away from their intended use (PWC, 2017). Financial services firms in Uganda also lose between $1-10 m to fraud and cyber risks annually (Deloitte, 2013a; KPMG, 2015). The above risks and others have even led to the closure of banks like global trust bank and crane bank in 2016 and 2017 respectively (Bank of Uganda, 2017). This is regardless of global initiatives towards effective RMPs like the Basel committee on banking supervision’s new international regulations designed to minimize the possibility of risks causing the next large-scale financial crisis (Chornous & Ursulenko, 2013; Grasshoff et al., 2018). Questions thus continue to rise on how financial services firms can ensure effective RMPs. A number of studies have been conducted on the determinants of effective RMPs but most of these studies have focused on the aspects of risk management process such as understanding risk and risk management (URM), risk identification (RI), risk analysis and assessment (RAA), credit risk management (CRM), and risk monitoring (RM) (Abu Hussain & Al-Ajmi, 2012; Khalid & Amjad, 2012; Rosman, 2009). The call for further studies by previous scholars is also common, for example, Khalid & Amjad (2012) called for additional research on further understanding RMPs of banks through studying risk management techniques used to mitigate risk exposure, this has not been widely addressed to date. Similarly, the above studies have mainly focused on Islamic banking. This study focuses on the conventional financial institutions in a developing country which are even more risky. Khalid & Amjad (2012) carried out a study to evaluate the degree to which Islamic banks in Pakistan use RMPs and techniques in dealing with different types of risk. Their findings were that Islamic banks are Kabuye et al., Cogent Business & Management (2019), 6: 1704609 https://doi.org/10.1080/23311975.2019.1704609 Page 2 of 24
somewhat reasonably efficient in managing risk where URM, RM and CRM are the most influencing variables in RMPs. In addition, Khalid & Amjad (2012) found that RMPs are determined by the extent to which managers understand risk and risk management, efficient risk identification, risk assessment analysis, risk monitoring and credit risk analysis. There are hardly any studies that have directly linked tone at the top management level and risk management practices. Available scanty studies have linked tone at the top management level in terms of corporate cultures, ethical communication, operating models and organizational constructs, leadership and governance, as well as the more traditional talent management practices and processes (Cheese, 2016; Dresp-Langley, 2009; Huang, 2004; Ssekiziyivu, Mwesigwa, Joseph, & Nkote Nabeta, 2017). Correspondingly, Kim (2019) findings suggest that individual factors (behavioural belief about risk management, social pressure and risk management knowledge) positively influence risk management intention; organizational factors (such as organizational risk management support) positively affect managers’risk management knowledge; and both individual and organizational factors are affected by organizational environment and/or risk management championship. Furthermore, Law (2011), indicates that tone at the top managerial level, and managerial ethical guidelines and policies are positively associated with a lack of fraud risks within organizations. Nevertheless, these studies do not suggest how the strategic gap in establishing effective RMPs in an entity can be closed through appropriate tone at top management level efforts. As far as internal audit quality is concerned, Zwaan, Stewart, and Subramaniam (2011) found that a high involvement in enterprise risk management impacts the perceptions of internal auditors’willingness to report a breakdown in risk procedures to the audit committee. Also, internal audit should be alert to the whole process of implementation of the systems for managing operational risks in entities (Laviada, 2007). On the contrary, though internal auditors are believed to have a role to play but concerns are expressed about their expertise and independence (Fraser & Henry, 2007) which may limit the quality of their audits is discovering and reporting risks. In this study, we define RMPs as the procedures of understanding and managing the risks that the entity is inevitably subject to in attempting to achieve its corporate objectives (Chartered Institute of Management Accountants (CIMA) (2009)). By enlisting the views of the chief finance officers, internal audit managers, and risk managers, we find that there are no significant differences in the way these interest groups perceive the influence of tone at the top management level and internal audit quality on effective RMPs. The perceived tone at the top management level, internal audit quality and effective RMPs are all measured by perceptions of 62 financial services firms in Uganda. Hierarchical regression analysis is employed to test the contribution made by the tone at the top management level, and internal audit quality on effective RMPs. The results in this paper are particularly important for several reasons. First, whilst there are a number of studies that have investigated the link between tone at the top management level, internal audit quality and risk management (e.g. Battaglia, Fiordelisi, & Ricci, 2016; Bezzina et al., 2014; Kim, 2019; Parisi, Clements, & Cornejo, 2016), studies focusing on the financial services sector and developing economies like Uganda are limited. Existing literature has also focused on motivating risk managers in the risk management processes (Kim, 2019; Parisi et al., 2016). This study looks at how self-inspired risk management initiatives among top managers and internal auditors can enhance effective RMPs in their organizations in order to close the strategic gap towards risk management. Therefore, this study contributes to existing body of knowledge by showing that when an organization has effective tone at the top management level, and with quality internal audits they are likely to enhance the effectiveness of RMPs. This is important for regulators like the central bank to require the effectiveness and efficiency of senior management and internal auditors to be elevated. Second, the research results are also timely and important for policy recommendations to improve the effectiveness of RMPs in the Ugandan financial services sector. This is especially given that the Bank of Uganda’s annual supervisory reports (2013–2017) have over the past five years indicated the inadequacy of effective RMPs in the financial services sector. Specifically, according to the Bank of Kabuye et al., Cogent Business & Management (2019), 6: 1704609 https://doi.org/10.1080/23311975.2019.1704609 Page 3 of 24
Uganda (2019), a number of commercial banks in Uganda have weaknesses in the composition of board committees, succession planning for board members and senior management, and delays in addressing vacancies in key positions of banks’organizational structures which end up derailing the effectiveness of RMPs. This also creates a strategic gap in risk management efforts as the tone at the top management level and internal audit quality in those banks is a warning. Thus, the results suggest that both tone at the top management level and internal audit quality are significant in establishing, evaluating and coordinating effective RMPs in an organization. The rest of the paper is organized as follows. Section 2reviews literature and develops hypotheses. This is followed by a discussion of the research methodology in Section 3. Section 4presents and discusses results. The final section is summary and conclusion. 2. Literature review and hypotheses development 2.1. Theoretical foundation In this study, we use the agency theory to explain the contribution of tone at the top management level and internal audit quality on effective RMPs. According to agency theory, top managers (Agents) in the organization act on behalf of the shareholders (Principals) in dealing with other people and running the organization. Thus, top management has a duty to design, implement and maintain adequate and effective RMPs in order to achieve the goals of the shareholders such as profit maximization, wealth maximization, business continuity, business expansion and growth. Nevertheless, the conflict of interests between the top management and shareholders tend to derail the presupposed agency relationship which leads to agency conflicts/problems. For example, top managers usually earn most of their income from the company they work for. They are therefore interested in the stability of the company, because this will protect their job and their future income. This means that management might be risk averse, and reluctant to invest in higher-risk projects. Contrarily, shareholders might want the organization to take bigger risks, if the expected returns are sufficiently high. Shareholders often invest in a portfolio of different companies; therefore, it matters less to them if an individual company takes risks. Since, top management is unwilling to take risks it may not implement and maintain effective RMPs which may lead to huge financial and non-financial losses due to the failure to manage risks by the top managers as the agents. In the context of this study, the appropriate tone at the top management level can help in reducing goal incongruence between top managers and the shareholders towards implementing effective RMPs. Internal auditors are employed to monitor the agents (the managers); however, quite often they have not achieved their objectives due to poor-quality audits. The poor-quality internal audits are mainly attributed to limited independence of the internal auditors, inadequate management support, staff expertise, scope of services, and ineffective communication (Roussy & Brivot, 2016). Hitherto researchers such as Chambers and Odar (2015) have advocated the extended role and quality of the internal auditors in order to help in ensuring effective RMPs. Thus, as per the agency theory, internal auditors are expected to remain alert and help in ensuring effective RMPs as a way of adding value to the entity. 2.2. Tone at the top management level Tone at the top is the degree of commitment by management and those charged with governance of the entity (board of directors) to having an open, direct, honest, and ethically correct corporate culture (Law, 2011). Tone at the top management level is a key element of an organization’sriskmanagement framework, since proper and adequate support from the top is likely to provide a robust foundation for effective RMPs. From prior studies, top management is believed to have a strong influence in setting the overall risk governance within the organization (Cohen et al., 2002 &Horton,2002). This role extends to the identification, assessment, designing and implementing controls, and mitigating risks, guiding the development and implementation of internal policies and procedures and ensuring that activities are consistent with goals and objectives (Gatzert & Schmit, 2016). Cheese (2016), argue that in order to manage and mitigate risk, organizations need to understand corporate cultures, operating Kabuye et al., Cogent Business & Management (2019), 6: 1704609 https://doi.org/10.1080/23311975.2019.1704609 Page 4 of 24
models and organizational constructs, leadership and governance, as well as the more traditional talent management practices and processes. Similarly, Sheedy and Lubojanski (2018)reportthat appropriate risk management behaviour at the employee level includes compliance, speaking up, thoughtful engagement with and accountability for the risk management framework. Thus, older workers as well as those with greater seniority are more likely to report desirable risk management behaviour. Correspondingly, Law (2011), indicates that tone at the top managerial level and managerial ethical guidelines and policies are positively associated with a lack of risks within organizations. Therefore, top management must instil values in employees in order to achieve a consistently ethical environment and to avoid risk (Johari, Alam, & Said, 2018;Law,2011). Contrarily, Horton (2002) indicates that in 200 cases of purported financial fraud risks that had been investigated by the SEC, five out of the six involved the CEO, the CFO, or both. Meaning that, if there is no appropriate tone at the top management level, risks are likely to increase in the organization. Relatedly, there is a significant negative association between individual risk tolerance and desirable risk management behaviour (Gyensare, Arthur, Twumasi, & Agyapong, 2019; Sheedy & Lubojanski, 2018). Nevertheless, Fraser and Henry (2007) argue that while parent boards have ultimate responsibility, the ownership of risks must reside with management at lower levels. Consequently, management’s effectiveness in terms of moral and ethical behaviour is integral to the organization’s control systems (Kabuye, Kato, Akugizibwe, & Bugambiro, 2019). Risk management committees tend to exist in organizations with an independent board chairman and larger boards. In comparison to organizations with a combined risk management committee and audit committee, those with a separate risk management committee are more likely to have larger boards, higher financial reporting risk and lower organizational complexity (Subramaniam, McManus, & Zhang, 2009). Given that many boards formulate strategy and manage risk separately (through the risk management committee), organizations can gain a competitive advantage by managing them in an integrative fashion. Boards that integrate strategy formulation and risk management should achieve higher stakeholder returns and be more adaptive than rivals (Sheehan, 2009). At the same time, evaluating the effectiveness of the board risk management committee must include characteristics of the entire board as well as individual contributions of directors (Carretta, Farina, & Schwizer, 2010). Also, for risk management of organizational records to be effective, it needs to be incorporated into the decision-making process of the organization, making it central to all activities (Egbuji, 1999); thus, risk management needs to be proactive, not reactive. Overly, the board risk management committee oversees operational risk management systems, practices and procedures including risk identification, management, monitoring and control. The committee also monitors legal suits against the organization and their materiality and reports on risk assessment levels. Subordinately, the operational risk committee of executive management is responsible for risk assessment, management and reporting matters arising from discussions of existing and potential operational risk within the various units across the entire organization (Centenary Bank, 2017). Thus, the combined role of the risk management committee and the operational risk committee is very substantial in the overall risk management (Bananuka, Tumwebaze, & Orobia, 2018; Stanbic Bank, 2017; Tumwebaze, Mukyala, Ssekiziyivu, Tirisa, & Tumwebonire, 2018). Besides, when a board of directors takes formal responsibility for the overall health of its company’s reputation, two things generally happen: one is that the various board sub-committees look for the impact on corporate reputation of their decisions. The other is that corporate reputation becomes a key performance indicator of the company’s executive management team (Dowling, 2006; Sherafatmand & Yazdani, 2014). Majorly, the risk management function (and/or committee) facilitates and monitors the implementation of effective RMPs and assists risk owners in defining the target risk exposure and reporting adequate risk-related information throughout the organization (IIA, 2013a). Therefore, H 1 : Tone at the top management level is positively and significantly related with effective risk management practices. Kabuye et al., Cogent Business & Management (2019), 6: 1704609 https://doi.org/10.1080/23311975.2019.1704609 Page 5 of 24
2.3. Internal audit quality Internal audit quality involves the internal audit activity’s conformance with the definition of internal auditing and the standards and an evaluation of whether internal auditors apply the Code of ethics (Coetzee, Fourie, & Burnaby, 2015). Internal audit quality is further demonstrated by the internal auditor’s capability to provide useful audit findings and recommendations (Mihret & Yismaw, 2007). Zwaan et al. (2011), indicate that a high involvement in enterprise risk management (ERM) impacts the perceptions of internal auditors’willingness to report a breakdown in risk procedures to the audit committee. Similarly, internal audit is a rich resource for organizations as it monitors the adequacy and effectiveness of management’s internal control framework and contributes to the integrity of corporate governance; risk assessment; and financial, operating, and IT systems (Burnaby & Hass, 2009). Besides, internal audit is more proactive in the implementation of ERM in smaller organizations, and is more important in the finance industry and the private sector (Castanheira, Rodrigues, & Craig, 2009; IIA, 2014b). Though risk management is primarily the responsibility of directors and senior managers. Internal auditors also have a role in consulting and providing assurance on risk management (Stewart & Subramaniam, 2010). This role for internal auditors is predicted to increase in importance in the future (Burnaby & Hass, 2009). The change of systems and processes in organizations is too big for traditional compliance-based internal auditing to absorb, the fact that leads to the necessity that internal auditing includes a risk management focus (Spira & Page, 2003). Therefore, it is important that internal auditors understand well their role in the risk management process. Coetzee (2016) also confirms that internal auditing should play a prominent role in risk-related activities to ensure that the risks threatening the organization are reduced to acceptable levels. Internal audit should be alert to the whole process of implementation of the systems for managing operational risks in organizations (Kabuye, Nkundabanyanga, Opiso & Nakabuye, 2017; Laviada, 2007). Despite the fact that internal audit quality is perceived to have a significant role in enhancing the effectiveness of RMPs, Fraser and Henry (2007) argue that this role is most times weakened by inadequate expertise and independence of internal auditors. They thus recommend a split of the internal audit and risk management functions to preserve internal audit independence and clarify internal audit roles. Stewart and Kent (2006) indicate there is also a strong association between internal audit and the level of commitment to risk management. Consequently, the need to have strong internal control and risk management systems and to reduce both internal and external agency costs drives companies to have an internal audit function (Ismael & Roberts, 2018). In the Belgian cases, internal auditors’focus on acute shortcomings in the risk management system create opportunities to demonstrate their value. Internal auditors are playing a pioneering role in the creation of a higher level of risk and control awareness and a more formalized risk management system. In the US cases, internal auditors’objective evaluations and opinions are a valuable input for the new internal control review and disclosure requirements mentioned in the Sarbanes Oxley Act (Sarens & De Beelde, 2006). Contrarily, the role of internal auditors in risk management in banks in Jordan was found to be limited. The risks that internal auditors were most involved in managing were those related to compliance, while the risks least dealt with by internal auditors included those related to the Jordanian economy and culture (Abdullatif & Kawuq, 2015). Therefore, a more formalized risk environment would foster a stronger risk-aware culture and hence provide a strong foundation for internal audit to implement risk-based auditing. However, internal audit experience, size of internal audit function, audit committee qualifications, and internal control system are not found to be significant predictors of the presence of risk-based auditing (Hafizah & Abidin, 2016). Therefore, internal audit quality is arguably a function of extensive staff expertise; reasonableness of the scope of service; and effective planning, execution and communication of internal audits. Consequently, we believe that: Kabuye et al., Cogent Business & Management (2019), 6: 1704609 https://doi.org/10.1080/23311975.2019.1704609 Page 6 of 24
H 2 : Internal audit quality is positively and significantly associated with effective risk management practices. 2.4. Control variables Bartov et al. (2000) suggest that failure to control for confounding variables could lead to falsely rejecting the hypothesis when in fact it should be accepted. As such, firm type, ownership and size are controlled in this study. A number of studies have found that firm type (public/private limited) determine the risk management efforts and requirements in an organization (Beasley, Clune, & Hermanson, 2005; Eng & Mak, 2003; Hassan, 2009; Ho & Shun Wong, 2001). Studies by Elshandidy and Neri (2014) and Subramaniam et al. (2009) explicitly indicate that corporate governance councils (regulators) set guidelines for risk management within public listed organizations and the board of directors are seen to hold the primary responsibility over the establishment and implementation of a proper risk management system. Relatedly, firm size is associated with effective RMPs (Collier, Haughwout, Kunreuther, Michel-Kerjan, & Stewart, 2016; Subramaniam et al., 2009). For instance, small firms which are exposed to a myriad of risks do not have the capability to avoid, transfer, diversify all the risky events; thus, they accept more risks which they ultimately fail to effectively manage. Thus, smaller firms inexplicably bear the costs of risk (Collier et al., 2016). Nonetheless, other studies have indicated inconsistent results for the relationship between firm size and risk management (Law, 2011). Besides, firm ownership is a determinant of corporate risk management (Eng & Mak, 2003; Gul & Leung, 2004; Ho & Shun Wong, 2001; Nordin & Hamid, 2013; Samaha, Dahawy, Hussainey, & Stapleton, 2012). 3. Methodology 3.1. Research setting This study gathered data from financial services firms in Uganda. Financial services firms in Uganda primarily comprise financial institutions, insurance and investments subsectors. The Ugandan financial services firms are relatively well developed, and they have been helpful not only in fostering investment and growth but also in mobilizing resources and enabling poor people to have some control over risks in their lives through increased access to financial services (Bank of Uganda, 2017;PWC,2017). Nevertheless, there are huge concerns of increasing incidences of risk in the financial services firms which have aroused concern among the public and the policymakers (Bank of Uganda, 2019;Deloitte,2013b). This is also significantly affecting the achievement of the desired growth and strategic objectives of the financial services firms (Consultative Group to Assist the Poor [CGAP], 2015). There are a number of security measures and regulations that have been put in place to manage risks in the Ugandan financial services firms, such as, the financial institutions act of 2004 (amended in 2016); the Financial Service firms Regulations of 2005 and the Anti-money Laundering Act of 2013, Basel III and IV recommendations. Nonetheless, a number of high-profile risks, for example, credit risk, cyber risk, liquidity risk, market risk, operational risk, compliance risk, taxation risk, reputation risk and business/strategic risk have continued to affect the financial services firms leading to high actual financial losses, business failure, and reduced investor confidence (Centenary Bank, 2017; Deloitte, 2013b; Stanbic Bank, 2017). The high-risk prevalence in the financial services firms has similarly been attributed to tone at the top management level ineffectiveness, and lowquality internal audits which lead to performance of insufficient tasks and activities to minimize and mitigate risks (Bank of Uganda, 2019; Deloitte, 2013a; IIA Uganda Chapter, 2015). Given the above discussion, this study setting provides a wealthy basis to examine the contribution of tone at the top management level, and internal audit quality on the effectiveness of RMPs in financial services sector in Uganda. 3.2. Design, population and sample The research design for this study is cross-sectional and correlational. The population of interest is the financial service firms in Uganda. Specifically, the population includes 89 financial services firms obtained from the three main subsectors of the financial services sector that is financial institutions, Kabuye et al., Cogent Business & Management (2019), 6: 1704609 https://doi.org/10.1080/23311975.2019.1704609 Page 7 of 24
The problem with univariate analyses is that they do not control for other factors, thus making the interpretation of results difficult. We, therefore, extend the analysis to a multivariate setting. We first examine correlations among our independent variables to determine whether multicollinearity problems exist. Field (2009) suggests that multicollinearity becomes a problem only when correlations exceed 0.80 or 0.90. As Table 9shows, none of the correlations between independent variables is close to these threshold values. 3.4.1. Model The study utilizes a hierarchical regression model in investigating the contribution of tone at the top management level and internal audit quality on effectiveness of RMPs. To examine the contribution of tone at the top management level and internal audit quality on effective RMPs, we specify the following regression models (see Table 5): RMPs ¼β0þβ1FT þβ2OWNP þβ3FS þεj(1) RMPs ¼β0þβ1TTML þβ2FT þβ3OWNP þβ4FS þεj(2) RMPs ¼β0þβ1IAQ þβ2TTML þβ3FT þβ4OWNP þβ5FS þεj(3) where; RMPs are Risk management practices, FT is Firm size, OWNP is Ownership, FS is Firm size, TTML is Tone at the top management level, IAQ is internal audit quality, β 0 is a constant and εjis the error term. 4. Empirical findings 4.1. Descriptive statistics Table 6shows the mean scores of the study variables. Risk management practices had the lowest mean score of 4.9905 with a standard deviation of 0.42912. Internal audit quality had the highest mean score 5.1744 with a standard deviation of 0.30250. As standard deviations relative to mean values are small; the calculated means highly represent the observed data (Field, 2009). The data also indicate that predictor variables are rated high towards risk Table 5. Description of the model Variable Acronym Variable description Outcome variable Risk management practices RMPs Measured by average rating on a six-point Likert scale of questions on risk prevention, risk detection and risk response Predictor variables Tone at the top management level TTML Measured by average rating on a six-point Likert scale of questions on internal processes (inclusive of internal controls), objectivity, and experience and expertise Internal audit quality IAQ Measured by average rating on a six-point Likert scale of questions on scope of service, independence, staff expertise, effective communication and management support Control Variables Firm type FT A dummy variable coded as 0 if the firm is domestically owned, 1 if the firm is foreign owned. Ownership OWNP A dummy variable coded as 0 if the firm is domestically owned, 1 if the firm is foreign owned. Firm size FS A dummy variable coded as 0 if the firm is public limited, 1 if the firm is private limited. β 0 Constant εjError term Source: Primary data. Kabuye et al., Cogent Business & Management (2019), 6: 1704609 https://doi.org/10.1080/23311975.2019.1704609 Page 14 of 24
management in the financial service firms. This implies that effective tone at the top management level, risk management committee and internal audit quality are key towards managing risk in the organization. To determine whether the firm differences influenced the study variables, a one-way analysis of variance (ANOVA) was used to determine the impact of firm sector on the study variables. The results of the one-way ANOVA presented in Table 7show that the p-values for all study variables are above 0.05; also, the actual difference in mean scores between the groups on each of the global variables are reasonably small, indicating that the various group differences between firms did not significantly influence their responses on the study variables. Similarly, results in Table 8suggest that the overall differences between respondents did not bias the results of this study. 4.2. Correlation analysis results We present Pearson’s correlation coefficient analysis of the study variables. Correlations from Table 9indicate a significant positive relationship between tone at the top management level and risk management practices (r = 0.792** and p < 0.01). Meaning that Tone at the top management level leads to enhanced risk management practices. Thus, H1 is supported. There is also a significant positive relationship between internal audit quality and risk management practices (r = 0.719** and p < 0.01). This means that an increase in internal audit quality leads to improved risk management practices. Therefore, H2 is also supported. The correlation analysis results also show that control variables, that is, firm type, ownership and size are not significantly related at the 1 per cent level. This implies that control variables do not confound the results of testing for the relationship between tone at the top management level, internal audit quality and effective RMPs in the financial service firms. Consequently, the relationship between tone at the top management level effectiveness, risk internal audit quality and effective RMPs is not affected by the control variables. 4.3. Hierarchical regression analysis results To further test for the sensitivity of the results to the control variables and the contribution of each predictor variable, we performed hierarchical regression analysis as a means of statistical control and for examining incremental validity. Study variables were entered simultaneously within each hierarchical group (Field, 2009; Aiken & West 1991) as shown in Table 10. Standardized versions of the βvalues were used because they are easier to interpret and are not dependent on the units of measurement of the variables (Field, 2009). The standardized beta values also tell us the number of standard deviations that the outcome will change as a result of one standard deviation change Table 6. Descriptive statistics for dependent, independent and control variables Variables nMinimum Maximum Mean Std. Deviation Tone at the top management level (1) 62 4.27 5.92 5.1503 .30730 Internal audit quality (2) 62 4.21 5.76 5.1744 .30250 Risk management practices (3) 62 3.87 5.73 4.9905 .42912 Firm type (4) 62 0.00 1.00 .2742 .44975 Ownership (5) 62 0.00 1.00 .5645 .49987 Firm size (6) 62 0.00 1.00 .6129 .49106 Valid n(listwise) 62 Source: Primary data. Kabuye et al., Cogent Business & Management (2019), 6: 1704609 https://doi.org/10.1080/23311975.2019.1704609 Page 15 of 24
Table 7. Global variables and financial institution category Variables Firm subsector nMean SD df FSignificance Tone at the top management level Financial institution 30 5.1556 0.21306 2 0.092 0.912 Insurance companies 15 5.1214 0.39533 59 Capital markets sub sector 17 5.1667 0.37400 61 Total 62 5.1503 0.30730 Internal audit quality Financial institution 30 5.2441 0.19867 2 2.198 0.12 Insurance companies 15 5.1699 0.40105 59 Capital markets sub sector 17 5.0554 0.33526 61 Total 62 5.1744 0.30250 Risk management practices Financial institution 30 5.0185 0.34746 2 0.595 0.555 Insurance companies 15 4.8852 0.58523 59 Capital markets sub sector 17 5.0340 0.41191 61 Total 62 4.9905 0.42912 Source: Primary data. Kabuye et al., Cogent Business & Management (2019), 6: 1704609 https://doi.org/10.1080/23311975.2019.1704609 Page 16 of 24
Table 8. Global variables and position of respondent’s in the firm Variables Respondent’s position nMean SD df FSignificance Tone at the top management level Chief Finance Officer 54 5.0869 0.47089 2 1.062 0.348 Internal Audit Manager 55 5.1622 0.54043 157 Risk Manager 51 5.2217 0.39930 159 Total 160 5.1558 0.47567 Internal audit quality Chief Finance Officer 54 5.1340 0.45984 2 0.447 0.640 Internal Audit Manager 55 5.2096 0.43592 157 Risk Manager 51 5.1984 0.44968 159 Total 160 5.1805 0.44692 Risk management practices Chief Finance Officer 54 5.0012 0.56234 2 0.151 0.860 Internal Audit Manager 55 4.9782 0.64751 157 Risk Manager 51 5.0418 0.59239 159 Total 160 5.0063 0.59903 Source: Primary data. Kabuye et al., Cogent Business & Management (2019), 6: 1704609 https://doi.org/10.1080/23311975.2019.1704609 Page 17 of 24
in the predictor; thus, they are directly comparable and provide a better insight into the importance of each predictor in the model (Field, 2009). The hierarchical regression results in Table 10 indicate that Model 1 reports the baseline model with only control variables. The results show that control variables do not explain any significant variance in RMPs. This suggests that the models in this study are not sensitive to confounding factors and the models are highly acceptable (Field, 2009). Results in Models 2 and 3 show that the F is significant at the 1 per cent level or better with tone at the top management level (standardized β= 0.694, p < 0.01) as significant in model 2. Essentially, Model 3 presents the combined effect of all the predictor variables on the outcome variable, and the results show that internal audit quality is the best and significant predictor variable of effective RMPs (standardized β= 0.529**), and tone at the top management level has the least predictive potential of the variance of RMPs in the general model (standardized β= 0.299**). This means that H1 and H2 are both further supported at this level of analysis. This means that when an organization’s tone at the top management level is effective and with high-quality internal audits, effective RMPs are likely to be designed, implemented and maintained. Taken together, the predictor variables explain about 67.7 per cent of the variance in RMPs in financial service firms in Uganda. Generally, the results suggest that Model 3 in Table 10 is the most plausible model. The incremental validity in adjusted R 2 in Models 1–3 in Table 10 suggests a better fitting model which develops as tone at the top management level and internal audit quality are successively introduced (Field, 2009) because in Table 10. Hierarchical regression results Variables Model 1 Model 2 Model 3 Constant 4.771 −0.276 −1.149 Tone at the top management level 0.694** 0.299** Internal audit quality 0.529** Control variables Firm type −0.051 0.031 0.035 Ownership 0.283 0.11 0.111 Firm size 0.179 0.211 0.141 Model F3.051* 20.126** 26.629** Adjusted R 2 0.092 0.556 0.677 Fchange 3.051* 61.764** 22.406** R 2 change 0.136 0.449 0.118 Durbin–Watson statistic 1.707 Notes: **p< 0.01; *p< 0.05. Source: Primary data. Table 9. Pearson correlations between the dependent, independent and control variables Variables 1 23456 Tone at the top management level (1) 1 Internal audit quality (2) .748** 1 Firm type (3) −.080 −.091 1 Ownership (4) .196 .227 .102 1 Firm size (5) .144 .017 −.031 .237 1 Risk management practices (6) .792** .719** −.028 .320* .248 1 Notes: n= 62. **indicate that correlation is significant at 0.01 level (one tailed). Source: Primary data. Kabuye et al., Cogent Business & Management (2019), 6: 1704609 https://doi.org/10.1080/23311975.2019.1704609 Page 18 of 24
all the cases but Model 1, the F change is significant. Durbin–Watson test was carried out to test for serial correlations between errors in regression models. As a very conservative rule of thumb, values lesser than 1 or greater than 3 are definitely cause for concern, but, the closer to 2 the value is, the better it is (Field, 2009). For this study, the Durbin–Watson statistic was 1.707, which justifies the assumption of independent errors or no serial correlation. 4.4. Discussion The main theme arising out of this study is that effective RMPs are significantly influenced by appropriate tone at the top management level and high internal audit quality. This infers that agency theory is well suited to explain the relevance of tone at the top management level and internal audit quality in ensuring effective RMPs since most principal–agency associations can be identified among internal stakeholders of an organization (Nalukenge, Nkundabanyanga, & Ntayi, 2018). For example, the results indicate that when management and those charged with governance of the entity design, implement and maintain effective internal controls and there is commitment from the chief executive and executive management of the organization towards RMPs, there is likely to be effective RMPs in the organization. This is consistent with the suggestion that tone at the top management level is crucial in ensuring effective RMPs and responsible for maintaining effective internal controls and for executing risk and control procedures in risk firms (IIA, 2013a) such as financial services firms, making agency theory a relevant framework for understanding variances in RMPs. Further still, the current study concurs with Cheese (2016)on the need to manage and mitigate risks effectively, through understanding corporate cultures, operating models and organizational constructs, leadership and governance, as well as the more traditional talent management practices and processes. At the same time, since tone at the top management level’s scope of activities includes the identification, assessment, control, and mitigation of risks (Fraser & Henry, 2007), these roles make it lead the way to overall risk management in the organization. However, the efforts of top managers will be enhanced if contemporaneously they are knowledgeable in risk management, do not have any conflict of interest with the organization and focus on risk issues. That way the top manager’s role in managing risk is improved by the enhanced expertise and objectivity. The results also suggest that executive management should allocate appropriate resources for training and the development of an enhanced risk awareness by all stakeholders. In this regard, tone at the top managerial level is seen as an elevator of the risk management efforts in the organization which seems to concur with Sheedy and Lubojanski (2018) observation that older workers as well as those with greater seniority are more likely to report desirable risk management behaviour. Thus, senior staff are expected to play a greater role in promoting risk management in firms that are committed to risk culture. Overall, adequate internal processes, objectivity and experience and expertise are key considerations for tone at the top management level in influencing effective RMPs. The results further suggest that the individual contribution of internal audit quality to effective RMPs is very vital. It is highly likely that if the organization has an effective tone at the top management level, this will help internal auditors to perform their duties independently. Besides, with adequate management support, internal auditors will be able to access all records as necessary and acquire training of the necessary skills to perform their duties competently to prevent, detect and report the risks. This corroborates with Coetzee (2016) who confirms that internal auditing should play a prominent role in risk-related activities to ensure that the risks threatening an organization are reduced to acceptable levels. Other corroborative studies have indicated that internal auditors are sensitive to factors that may lead to risk disclosures and that when they encounter such factors, internal auditors may be more likely to design tests to search for risk, which in turn can increase the likelihood of detection and reporting (Abdullatif & Kawuq, 2015; Chambers & Odar, 2015; Zwaan et al., 2011). However, our results contradict the findings of Fraser and Henry (2007) who recommended a split of the internal audit and risk management functions to preserve internal audit independence and clarify internal audit roles. Nonetheless, in this study, we suggest that even though a separate risk management function is established in the organization, internal audit remains with the primary role of assisting the top management to Kabuye et al., Cogent Business & Management (2019), 6: 1704609 https://doi.org/10.1080/23311975.2019.1704609 Page 19 of 24
meet the strategic and operational objectives of the organization, by providing an independent and objective evaluation of the adequacy and effectiveness of risk management, controls and governance processes. As a result, the organization’s internal audit approach must be aligned with the organization’s risk management function by focusing on key strategic, financial, operational, compliance and information technology risks. This links well with the studies of Stewart and Kent (2006) and Ismael and Roberts (2018). The empirical results presented herein further confirm the contemporary literature in this regard, thus contributing to the internal audit quality and effective RMPs literature, particularly that focusing on the financial services sector. 5. Summary and conclusion The purpose of this paper was to examine the contribution made by the tone at the top management level effectiveness and internal audit quality on effective RMPs in the financial services firms. We surveyed 62 financial services firms and we find that tone at the top management level and internal audit quality are significant predictors of effective RMPs. Once the organization has effective tone at the top management level, it is likely to aid internal auditors perform quality audits to enhance effective risk management practices. This study offers several implications. We explore the role played by the tone at the top management level and internal audit quality in enhancing the effectiveness of RMPs, meaning that organization managers who design, implement and maintain effective internal controls and do not have any conflict of interest with the organization are likely to enhance risk prevention, detection and reporting. For policymakers like the central bank (e.g. Bank of Uganda), the findings of this study will help them in prescribing the operating standards for financial services firms, composition and expertise of the risk management committee and qualifications for internal auditors. Besides, internal auditors should be independent, competent, get adequate support from management and perform their new and expanded activities as per the institute of internal auditors (IIA, 2013a; IIA, 2014a) to ensure quality audits. The results are important for risk management policy development, for example, in terms of prescribing the role of tone at the top management level, and internal audit quality in spearheading risk management in the financial service firms. Despite the contributions and implications, this study focused on financial services firms in Uganda to determine the contribution of tone at the top management level effectiveness and internal audit quality on risk management. It is possible that these results are only applicable to financial service firms unlike other service firms. The study also used more of quantitative data which sometimes misses certain information and limits the respondent’s opinions on the study variables. While care was taken to control for response bias, it is unlikely it could be ruled out completely. However, this study clearly brought out the overall contribution of tone at the top managerial level, and internal audit quality in risk prevention, detection and reporting as necessary. Funding The authors received no direct funding for this research. Author details Frank Kabuye 1 E-mail: [email protected] ORCID ID: http://orcid.org/0000-0002-9367-9950 Nicholas Bugambiro 1 E-mail: [email protected] Irene Akugizibwe 1 E-mail: [email protected] Sharon Nuwasiima 1 E-mail: [email protected] Sharon Naigaga 1 E-mail: [email protected] 1 Department of Accounting, Makerere University Business School, Kampala, Uganda. Citation information Cite this article as: The influence of tone at the top management level and internal audit quality on the effectiveness of risk management practices in the financial services sector, Frank Kabuye, Nicholas Bugambiro, Irene Akugizibwe, Sharon Nuwasiima & Sharon Naigaga, Cogent Business & Management (2019), 6: 1704609. References Abdullatif, M., & Kawuq, S. (2015).Theroleofinternalauditing in risk management: Evidence from banks in Jordan. Journal of Economic and Administrative Sciences,31(1), 30–50. doi:10.1108/JEAS-08-2013-0025 Abu Hussain, H, & Al-Ajmi, J. (2012). Risk management practices of conventional and islamic banks in bahrain. The Journal of Risk Finance,13(3), 215–239. Kabuye et al., Cogent Business & Management (2019), 6: 1704609 https://doi.org/10.1080/23311975.2019.1704609 Page 20 of 24
Ahmad, U., Ibrahim, Y., & Minai, M. S. (2018). Malaysian public–private partnerships: Risk management in build, lease, maintain and transfer projects. Cogent Business & Management,5(1), 1550147. doi: doi.10.1080/23311975.2018.1550147 Aiken, L.S, & West, S.G. (1991). Multiple regression: testing and interpreting interactions. Newbury Park, CA:Sage. Al-Twaijry, A. A, Brierley, J. A, & Gwilliam, D. R. (2003). The development of internal audit in saudi arabia: an institutional theory perspective. Critical Perspectives on Accounting,14(5), 507–531. Arena, M., & Azzone, G. (2009). Identifying organizational drivers of internal audit effectiveness. International Journal of Auditing,13(1), 43–60. Badara, M. S, & Saidin, S. Z. (2013). The journey so far on internal audit effectiveness: a calling for expansion. International Journal of Academic Research in Accounting, Finance and Management Sciences,3(3), 240–351. doi: 10.6007/IJARAFMS/v3-i3/225 Bananuka, J., Tumwebaze, Z., & Orobia, L. A. (2018). The adoption of integrated reporting: A developing country perspective. Journal of Financial Reporting and Accounting. doi:10.1108/JFRA-09-2017-0089 Bank of Uganda. (2017). Annual supervision report, Issue Number 8. Kampala: Author. Retrieved from https:// islamicmarkets.com/publications/bank-of-ugandaannual-supervision-report-2017 Bank of Uganda. (2019, August 20). Bank of Uganda financial stability report June 2019, Issue number 11. Kampala: Author. Retrieved from https://www.bou.or. ug/bou/bouwebsite/bouwebsitecontent/ FinancialStability/financial_stability/Rpts/All/ Financial-Stability-Report-June-2019-final-2.pdf Bartov, E, Gul, F.A, & Tsui, J.S.L. (2000). Discretionaryaccruals models and audit qualifications. Journal Of Accounting and Economics,30(3), 421–452. Battaglia, F., Fiordelisi, F., & Ricci, O. (2016). Enterprise risk management and bank performance: Evidence from Eastern Europe during the financial crisis. In S. Boubaker, B. Buchanan, & D. K. Nguyen (Eds.), Risk Management in Emerging Markets: Issues, Framework, and Modeling (pp. 295–334). UK: Emerald Group Publishing Limited. Beasley, M. S., Clune, R., & Hermanson, D. R. (2005). Enterprise risk management: An empirical analysis of factors associated with the extent of implementation. Journal of Accounting and Public Policy,24(6), 521–531. doi:10.1108/S1474787120180000030002 Berger, V. W., & Zhang, J. (2005), Simple random sampling. Encyclopedia of Statistics in Behavioral Science. Bezzina, F., Grima, S., & Mamo, J. (2014). Risk management practices adopted by financial firms in Malta. Managerial Finance,40(6), 587–612. doi:10.1108/MF08-2013-0209 Burnaby, P., & Hass, S. (2009). A summary of the global common body of knowledge 2006 (CBOK) study in internal auditing. Managerial Auditing Journal,24(9), 813–834. doi:10.1108/02686900910994782 Carretta, A., Farina, V., & Schwizer, P. (2010). Assessing effectiveness and compliance of banking boards. Journal of Financial Regulation and Compliance,18(4), 356–369. doi:10.1108/13581981011093677 Castanheira, N., Rodrigues, L. L., & Craig, R. (2009). Factors associated with the adoption of risk-based internal auditing. Managerial Auditing Journal,25(1), 79–98. doi:10.1108/02686901011007315 Centenary Bank. (2017). Centenary bank, annual report 2017. Retrieved from http://www.centenarybank.co. ug/sites/default/files/2017%20Annual%20Report% 20for%20w eb.pdf Chambers, A. D., & Odar, M. (2015). A new vision for internal audit. Managerial Auditing Journal,30(1), 34–55. doi:10.1108/MAJ-08-2014-1073 Chartered Institute of Management Accountants (CIMA). (2009). Fraud risk management: A guide to good practice. Retrieved from www.cimaglobal.com Cheese, P. (2016). Managing risk and building resilient organisations in a riskier world. Journal of Organizational Effectiveness: People and Performance, 3(3), 323–331. doi:10.1108/JOEPP-07-2016-0044 Chornous, G., & Ursulenko, G. (2013). Risk management in banks: New approaches to risk assessment and information supporting. EKONOMIKA,92(1), 1392–1258. doi:10.15388/Ekon.2013.0.1131 Coetzee, P, Fourie, H, & Burnaby, P.A. (2015). The growth of the internal audit profession is more than just numbers: fact or fiction?. Evidence from South Africa," Managerial Auditing Journal,30(6/7), 514–538. Coetzee, P. P. (2016). Contribution of internal auditing to risk management: Perceptions of public sector senior management. International Journal of Public Sector Management,29(4), 348–364. doi:10.1108/IJPSM-122015-0215 Cohen, A, & Sayag, G. (2010). The effectiveness of internal auditing: an empirical examination of its determinants in israeli organizations. Australian Accounting Review,54 (20), 296–307. doi: 10.1111/j.18352561.2010.00092.x Cohen, J, Krishnamoorthy, G, & Wright, A. (2002). Corporate governance and the audit process. Contemporary Accounting Research,19, 573–592. Collier, B. L., Haughwout, A. F., Kunreuther, H. C., MichelKerjan, E. O., & Stewart, M. A. (2016). Firm age and size and the financial management of infrequent shocks. NBER working paper 22612. JEL classification: G32, G28, G22, D22, L25, Q54. Retrieved from http:// opim.wharton.upenn.edu/risk/library/WP201609_ Collier-etal_Firm-Age-and-Size Infrequent-Shocks. pdf Consultative Group to Assist the Poor (CGAP). (2015). Fraud in Uganda: How millions were lost to internal collusion. Retrieved from http://www.cgap.org/blog/ fraud Deloitte. (2013a). Financial crime survey report 2013: Where is the exposure? Retrieved from http:// Deloitte_Financial_Crimes_Survey_Report-2013.pdf Deloitte. (2013b). Governance in focus: Effectiveness of the external audit process. A framework for assessing the effectiveness of the external audit process. Retrieved from https://www2.deloitte.com/content/ dam/Deloitte/uk/Documents/audit/deloitte-ukauditgovernance-in-focus-effectiveness-of-theexternal-audit-sep2013.pdf Dowling, G. (2006). Reputation risk: It is the board’s ultimate responsibility. Journal of Business Strategy,27 (2), 59–68. doi:10.1108/02756660610650055 Dresp-Langley, B. (2009). The communication contract and its ten ground clauses. Journal of Business Ethics, 87, 415–455. doi:10.1007/s10551-008-9929-3 Egbuji, A. (1999). Risk management of organisational records. Records Management Journal,9(2), 93–116. doi:10.1108/EUM0000000007245 Elshandidy, T, & Neri, L. (2014). Corporate governance, risk disclosure practices, and market liquidity: Comparative evidence from the uk and italy. Corporate Governance: an International Review. doi:10.1111/corg.1209 Endaya, K.A, & Hanefah, M.M. (2013). Internal audit effectiveness: An approach proposition to develop Kabuye et al., Cogent Business & Management (2019), 6: 1704609 https://doi.org/10.1080/23311975.2019.1704609 Page 21 of 24
the theoretical framework research. Journal of Finance and Accounting,4(10), 92–102. Eng, L. L., & Mak, Y. T. (2003). Corporate governance and voluntary disclosure. Journal of Accounting and Public Policy,22(4), 325–345. doi:10.1016/S0278-4254(03) 00037-1 Ernest, & Young. (2018, June 05). Global banking outlook 2018 Pivoting toward an innovation-led strategy. Retrieved from file:///D:/IA%20and%20RM/ey-globalbanking-outlook-2018.pdf Feizizadeh, A. (2012). Strengthening internal audit effectiveness. Indian Journal of Science and Technology,5 (5), 2777–2778. Field, A. (2009). Discovering statistics using spss (3rd ed.). London: Sage. Fraser, I., & Henry, W. (2007). Embedding risk management: Structures and approaches. Managerial Auditing Journal,22(4), 392–409. doi:10.1108/ 02686900710741955 Garson, G.D. (2012). Testing Statistical Assumptions, 2012 ed., Statistical Associates publishing. Gatzert, N., & Schmit, J. (2016). Supporting strategic success through enterprise-wide reputation risk management. The Journal of Risk Finance,17(1), 26–45. doi:10.1108/JRF-09-2015-0083 Goodwin, J. (2004). A comparison of internal audit in the private and public sectors. Managerial Auditing Journal,19(5), 640–650. Grasshoff, G., Pfuhler, T., Coppola, M., Mogul, Z., Villafranca, V., Gittfried, N., …Wiegand, C. (2018, June 11). Global risk 2018: Future-proofing the bank risk agenda. Retrieved from https://www.bcg.com/publi cations/2018/global-risk-2018-future-proofing-bank agenda.aspx Gul, F. A., & Leung, S. (2004). Board leadership, outside directors’expertise and voluntary corporate disclosures. Journal of Accounting and Public Policy,23(5), 351–379. doi:10.1016/j.jaccpubpol.2004.07.001 Gyensare, M., Arthur, R., Twumasi, E., & Agyapong, J.-A. (2019). Leader effectiveness –The missing link in the relationship between employee voice and engagement. Cogent Business & Management,6(1), 1634910. doi:10.1080/23311975.2019.1634910 Hafizah, N., & Abidin, Z. (2016). Factors influencing the implementation of risk-based auditing. Asian Review of Accounting, 25 (3), 361–375. Hassan, M. K. (2009). UAE corporations-specific characteristics and level of risk disclosure. Managerial Auditing Journal,24(7), 668–687. doi:10.1108/ 02686900910975378 Ho, S. S. M., & Shun Wong, K. (2001). A study of the relationship between corporate governance structures and the extent of voluntary disclosure. Journal of International Accounting, Auditing and Taxation, 10(2), 139–156. doi:10.1016/S1061-9518(01)00041-6 Horton, T. (2002). Tone at the top. Directors and Boards, 26(4), 8–13. Huang, Y. (2004). Is symmetrical communication ethical and effective? Journal of Business Ethics,53, 333–352. doi:10.1023/B:BUSI.0000043494.17425.c6 IIA. (2013a). The three lines of defense in effective risk management and control. Retrieved from www.glo baliia.org. IIA. (2014a). Managing the business risk of fraud: A practical guide. Retrieved from www.acfe.com/ uploadedFiles/ACFE_Website/Content/documents/ managing-businessrisk.pdf IIA. (2014b). The institute of internal auditors; managing the business risk of fraud: A practical guide. Retrieved from www.theiia.org//fraud-white-paper/Fraud% 20Exec%20Summary.pdf IIA Uganda Chapter. (2015). The 10th national internal audit conference. Retrieved from www. newvision.co. ug/new_vision/news/1321504/institute-internalauditors-uganda Ismael, H. R., & Roberts, C. (2018). Factors affecting the voluntary use of internal audit: Evidence from the UK. Managerial Auditing Journal. doi:doi.10.1108/MAJ-082016-1425 Johari, R. J., Alam, M. M., & Said, J. (2018). Assessment of management commitment in Malaysian public sector. Cogent Business & Management,5(1), 1469955. doi:10.1080/23311975.2018.1469955 Kabuye, F., Kato, J., Akugizibwe, I., & Bugambiro, N. (2019). Internal control systems, working capital management and financial performance of supermarkets. Cogent Business & Management,6(1), 1573524. doi:10.1080/23311975.2019.1573524 Kabuye, F., Nkundabanyanga, S. K., Opiso, J., & Nakabuye, Z. (2017). Internal audit organisational status, competencies, activities and fraud management in the financial services sector. Managerial Auditing Journal,32(9), 924–944. doi:10.1108/MAJ09-2016-1452 Karagiorgos, T, Drogalas, G, & Giovanis, N. (2011). Evaluation of the effectiveness of internal audit in greek hotel business. International Journal Of Economic Sciences and Applied Research,4(1), 19–34. Khalid, S, & Amjad, S. (2012). Risk management practices in islamic banks of pakistan. Journal Of Risk Finance, 13(2), 148–159. Kim, S. S. (2019). The role of knowledge and organizational support in explaining managers’active risk management behavior. Journal of Enterprise Information Management,32(2), 345–363. doi:10.1108/JEIM-07-2018-0159 KPMG. (2015). East Africa insurance fraud risk survey 2015. Retrieved from http://isaca.or.ke/downloads/ Embedding-Data-Analytics-in-Fraud-Auditing.pdf Krejcie, R. V., & Morgan, D. W. (1970). Determining sample size for research activities, educational and psychological measurement. London: Sage Publications. Laviada, A. F. (2007). Internal audit function role in operational risk management. Journal of Financial Regulation and Compliance,15(2), 143–155. doi:10.1108/13581980710744039 Law, P. (2011). Corporate governance and no fraud occurrence in organizations. Managerial Auditing Journal,26(6), 501–518. doi:10.1108/ 02686901111142558 Levene, H. (1960). In Contributions to probability and statistics. (Ed.) Palo Alto. 278–292. Little, A.J.R. (1988). A test of missing completely at random for multivariate data with missing values. Journal Of The American Statistical Association,83 (404), 1198–1202. McEvily, B., & Marcus, A. (2005). Embedded ties and the acquisition of competitive capabilities. Strategic Management Journal,26(11), 1033–1055. doi:10.1002/(ISSN)1097-0266 Mihret, D. G, James, K, & Joseph, M. M. (2010). Antecedents and organizational performance implications of internal audit effectiveness: some propositions and research agenda. Pacific Accounting Review,22(3), 224–252. Mihret, D.G, & Yismaw, A.W. (2007). Internal audit effectiveness: an ethiopian public sector case study. Managerial Auditing Journal,22(5), 470–484. Nalukenge, I., Nkundabanyanga, S. K., & Ntayi, J. M. (2018). Corporate governance, ethics, internal controls and compliance with IFRS. Journal of Financial Reporting and Accounting,16(4), 764–786. Kabuye et al., Cogent Business & Management (2019), 6: 1704609 https://doi.org/10.1080/23311975.2019.1704609 Page 22 of 24
Nordin, N., & Hamid, M. A. (2013). Corporate risk management, firm characteristics, ownership structure, and governance attributes of banks: A case of Malaysia. Prosiding Perkem Viii, Jilid,2(1), 655–660. ISSN: 2231-962X. Norman, C, Rose, A, & Rose, J. (2010). Internal audit reporting lines. Fraud Risk Decomposition, and Assessments Of Fraud Risk, Accounting, Organizations and Society,35(5), 546–557. Parisi, F., Clements, S., & Cornejo, E. (2016). Risk management in a transition economy: The Chilean case. In S. Boubaker, B. Buchanan, & D. K. Nguyen (Eds.), Risk management in emerging markets (pp. 399–421). PWC. (2017). Uganda Economic Outlook 2017. Retrieved from www.pwc.com/ug Rooney, J., & Cuganesan, S. (2015). Leadership, governance and the mitigation of risk: A case study. Managerial Auditing Journal,30(2), 132–159. doi:10.1108/MAJ-08-2014-1078 Rosman, R. (2009). Risk management practices and risk management processes of islamic banks: a proposed framework, International Review of Business Research Paper, 5(1), 242–254. Roussy, M., & Brivot, M. (2016). Internal audit quality: A polysemous notion? Accounting, Auditing & Accountability Journal,29(5), 714–738. doi:10.1108/ AAAJ-10-2014-1843 Safari, R., Shateri, M., Baghiabadi, H. S., & Hozhabrnejad, N. (2016). The significance of risk management for banks and other financial service firms. International Journal of Research Grant Haalayah,4(4), 74–81. Samaha, K., Dahawy, K., Hussainey, K., & Stapleton, P. (2012). The extent of corporate governance disclosure and its determinants in a developing market: The case of Egypt. Advances in Accounting,28, 168– 178. doi:10.1016/j.adiac.2011.12.001 Sarens, G., & De Beelde, I. (2006). Internal auditors’perception about their role in risk management. A comparison between US and Belgian companies. Managerial Auditing Journal,21(1), 63–80. doi:10.1108/02686900610634766 Saunders, M., Lewis, P., & Thornhill, A. (2012). Methods for business students. Harlow: Pearson Education Ltd. Sheedy, E., & Lubojanski, M. (2018). Risk management behaviour in banking. Managerial Finance,44(7), 902–918. doi:10.1108/MF-11-2017-0465 Sheehan, N. T. (2009). Making risk pay: The board’s role. Journal of Business Strategy,30(1), 33–39. doi:10.1108/02756660910926957 Sherafatmand, H., & Yazdani, S. (2014). The management of price risk in Iranian dates: An application of futures instruments. Cogent Economics & Finance,2(1), 946998. doi:doi.10.1080/2332203 9.2014.946998 Soh, D.S.B, & Martinov-Bennie, N. (2011). The internal audit function: perceptions of internal audit roles, effectiveness, and evaluation. Managerial Auditing Journal,26(7), 605–622. Spira, L.F. & Page, M. (2003). Risk Management: The Reinvention of Internal Control and the Changing Role of Internal Audit. Accounting, Auditing & Accountability Journal,16, 640–661. http://dx.doi.org/ 10.1108/09513570310492335. Ssekiziyivu, B., Mwesigwa, R., Joseph, M., & Nkote Nabeta, I. (2017). Credit allocation, risk management and loan portfolio performance of MFIs – A case of Ugandan firms. Cogent Business & Management,4(1), 1374921. doi:doi.10.1080/23 311975.2017.1374921 Stanbic Bank. (2017). Stanbic Bank, Annual Report 2017. Retrieved from https://www.stanbicbank.co.ug/stan dimg/Uganda/fileDownloads/UG_ FinancialReport2017.pdf Stewart, J, & Subramaniam, N. (2010). Internal audit independence and objectivity: emerging research opportunities. Managerial Auditing Journal,25(4), 328–360. Stewart, J. G., & Kent, P. (2006). The use of internal audit by Australian companies. Managerial Auditing Journal,21(1), 81–101. doi:10.1108/ 02686900610634775 Subramaniam, N., McManus, L., & Zhang, J. (2009). Corporate governance, firm characteristics and risk management committee formation in Australian companies. Managerial Auditing Journal,24(4), 316–339. doi:10.1108/02686900910948170 Tumwebaze, Z., Mukyala, V., Ssekiziyivu, B., Tirisa, C. B., & Tumwebonire, A. (2018). Corporate governance, internal audit function and accountability in statutory corporations. Cogent Business & Management,5 (1), 1527054. doi:10.1080/23311975.2018.1527054 Vinnari, E, & Skaerbaek, P. (2014). The uncertainties of risk management: a field study on risk management internal audit practices in a finnish municipality. accounting. Auditing & Accountability Journal,27(3), 489–526. Zwaan, L., Stewart, J., & Subramaniam, N. (2011). Internal audit involvement in enterprise risk management. Managerial Auditing Journal,26(7), 586–604. doi:10.1108/02686901111151323 Kabuye et al., Cogent Business & Management (2019), 6: 1704609 https://doi.org/10.1080/23311975.2019.1704609 Page 23 of 24