In: Accounting
Pick any topic and write a risk impact mitigation tree with 3 Risks, 2 impact for each risk with one risk having 3 impacts, 2 Mitigations with one having 3 Mitigations, and 2 Gaps?
Topic | Purchases are made incorrectly | ||||
Risks | Purchase order (PO) is not made by authorised personnel | Price in Purchase Order (PO) is entered incorrectly | Quantity in Purchase Order (PO) is entered incorrectly | ||
Impact 1 | Unauthorised personnel may not be competent enough to raise PO in right category | Incorrect price, if lower than agreed price, may lead to rejection of order from vendor | Incorrect qty, if lower than required qty, may lead to inconvenience of re-order | ||
Impact 2 | Unauthorised personnel may raise PO to a black listed vendor | Incorrect price, if higher than agreed price, may lead to over payment to vendor | Incorrect qty, if higher than required qty, may lead to over stock and adverse cashflows | ||
Incorrect price vs agreed price creates bad image for the firm | |||||
Mitigation1 for Impact 1 | Unauthorised personnel should not be able to login into PO module. Strong password and valid IDs should be used for loging into PO module | Apply maker checker control | Apply maker checker control | ||
Mitigation2 for Impact 1 | Periodically review the purchase history | Periodically review the purchase history | |||
Mitigation1 for Impact 2 | Unauthorised personnel should not be able to login into PO module. Strong password and valid IDs should be used for loging into PO module | Apply maker checker control | Apply maker checker control | ||
Mitigation2 for Impact 2 | Periodically review the purchase history | Periodically review the purchase history | |||
Mitigation1 for Impact 3 | Apply maker checker control | ||||
Mitigation2 for Impact 3 | Periodically review the purchase history | ||||
Gap 1 | Access available to unauthorised personnel | No threshold control on prices at time of ordering (approval matrix) | No threshold control on quantity at time of ordering (approval matrix) | ||
Gap 2 | Maker checker control not in place | Maker checker control not in place | Maker checker control not in place |