Governance is very important for every organizations. Giant organizations such as Enron and World Com went bankrupt due to lack of governance. The Institute of Internal Auditors (The IIA) on International Professional Practices Framework (IPPF) defines “governance is the combination of processes and structures implemented by the board to inform, direct, manage, and monitor the activities of the organization toward the achievement of its objectives”. From this definition, governance is the duty of the organization to ensure the achievement of its objectives.
Risk management is a major part of governance. In achieving its objectives, the organization will face so many risks. Risk management process starts from setting the objectives to assessing the risks (identifying, analyzing, prioritizing and responding to risk).
Controls is a major part of risk management. In responding to risks, the organization exercises controls to decrease the impact and likelihood of risks while to increase the opportunity to achieve its objectives.
The organization to assure the achievement of its objectives need to implement governance, risk management and controls as an iterative, consistent, accountable, systematic and dynamic process.