Authors: Ioannis Ploumpis, Nikolaos Eriotis, Theodoros Kounadeas
Title: Internal Audit and Risk Management at Public Sector
Abstract
The purpose of this study was to investigate the role and the way of implementation of internal audit and risk management in public institutions in Greece. In order to achieve this purpose, the concepts of risk management and internal audit were analyzed, while the case of risk management and internal control implementation in the public sector in particular was also examined. Furthermore, a review of the relevant international literature was conducted and the most important points were recorded. The second part of this paper includes the conduct of a quantitative study to investigate the implementation and role of internal control and risk management in public organizations in Greece. The data were collected using the research tool of a questionnaire, to which employees in different departments of public organizations were asked to respond. It emerges that risk management is applied to a moderate extent in public organizations while its main role is to identify and recognize potential risks, adopt risk management strategies and evaluate the effectiveness of risk management strategies. Internal audit is also applied to a moderate degree and its main role is to limit losses of resources, assets and reputation of the organization, to maintain or increase value, to develop, to ensure sustainability and to monitor the adoption and proper implementation of strategies and practices. It also appears that internal audit is quite important for risk management in organizations, as it facilitates and enhances risk management practices, monitors the adequacy, effectiveness and efficiency of these practices, evaluates the development, implementation and evolution of practices, and further assesses to what extent the probability of risk occurrence is reduced through management and whether the inherent risks of strategic objectives are recognized and identified. In conclusion, from the analysis of the results occurred, it is found that both risk management and internal control could be more widespread within Greek public organizations, while in addition, staff should be properly trained and educated and the practices implemented should be modernized.

