Skip to main content

Round Table: DNB's good practice and the role of internal audit

October 4, 2023 | 16:00 - 19:00 | Hilversum

The DNB Information Security Good Practice.

De Nederlandsche Bank (DNB) has prepared a "Information Security Good Practice" as a guideline for financial institutions in the Netherlands. This good practice aims to support financial institutions in setting up their information security policies and practices effectively and efficiently. Internal Audit can add a lot of value here. In this Round Table we take you through a practical story about the added value that you as an internal auditor can deliver by stepping off the beaten track.

Content

The Good Practice acts as a guideline for organizations in their pursuit of watertight information security. So to get "in control" in the field of ICT. It provides an opportunity for Internal Audit to innovate and add value for the organization.

Carlo Bavius is Executive Partner at ARC People and, together with Jacko Möhle, IT audit expert, will address several topics during the Round Table, including:

  • The role of Internal Audit in DNB Good Practice Information Security.
  • The Role of Internal Audit in Control Self Assessments.
  • Internal Audit's role in reviewing assurance statements in the outsourcing supply chain

What else you need to know

There is no cost to participate. Afterwards, a meal will be available and the opportunity to chat with each other.

Sign up

Registration is no longer possible.

Free white paper

For years, DNB has had the Good Practice Information Security (Cobit-'light') on which it bases its supervision. In the coming years, this will be supplemented by regulations such as DORA and NIS2. At ARC People, we have developed a white paper in which we elaborate on, among other things, the new outlook and the impact these new regulations will have on the Dutch financial sector.

Round Table 'Soft Controls'

June 8, 2023 | 16:00 - 18:30 | Hilversum

Soft controls: what does science say and what does practice teach us?

Speaker Hein-Jan Vink is Manager of the audit department of the Central Agency for the Reception of Asylum Seekers (COA). In recent years, Hein-Jan conducted doctoral research on organizational culture and soft controls. During his PhD research Hein-Jan gained all kinds of interesting insights. Both from science and practice. He likes to share these insights with other Audit, Risk and Compliance professionals.

Content

There are many definitions of (and misunderstandings about) soft controls in circulation. Therefore Hein-Jan first briefly outlines what soft controls are and what is outside control. He also discusses the interesting difference between soft controls and culture.

It will then become clear that soft controls are significantly related to effectiveness. Hein-Jan will show the participants his knowledge and experience as a (scientific) researcher on organizational culture and soft controls. He conducted his research primarily using surveys and statistical analysis. In doing so, he frequently worked with "Kaptein's eight factors".

Hein-Jan will share insights including the following:

  • The importance of independent variables as well as a dependent variable.
  • What do low or high scores really say?
  • When is a certain score sufficient?
  • Factors can also work against each other.
  • What could be behind a particular score?
  • What research methods have worked in practice.
  • Why so-called "alignment research" is not recommended.

Hein-Jan also likes to hear participants' experiences. Therefore, you are invited to think in advance about (a) what has been your biggest challenge so far in applying soft controls, or (b) what the application of soft controls has concretely delivered. We hope you will share this experience with us during the Round Table.

What else you need to know

There is no cost to participate. Afterwards, a meal will be available and the opportunity to chat with each other.

Sign up

Registration is no longer possible.

Executive Round Table: ransomware resilience

March 9, 2023 | 16:00 - 18:30 | Hilversum

Armed together against ransomware

Ransomware is a topic that, unfortunately, more and more companies (and individuals) are (were) facing. To be well prepared against the risks of ransomware and to share knowledge in an interactive way, Anita van der Leeuw organized the Round Table Ransomware Resilience on March 9 at the offices of ARC People in Hilversum. Present at this session were representatives from 14 organizations; heads of internal audit (CAEs), heads of risk management and heads of information security (CISOs).

About the Round Table

The welcoming of the attendees was done by our experienced IT auditors Anita van der Leeuw and Carlo Bavius, who both served as moderators. After the substantive part of the agenda, the floor was then given to a "mystery guest" invited by us. He told us a fascinating story about ransomware from an organization that recently became a victim of it itself.

This was followed by an informal closing with and drinks and a delicious rice table. It was a fascinating Round Table in which we could exchange views on this important topic both during and after the session.

Sign up

Registration is no longer possible.

Another look at the contribution of 2nd and 3rd lines within the 3 Lines Model

December 1, 2022 | 16:00 - 18:30 | Hilversum

Contents of the Executive Round Table

Ruurd van den Berg will give his view on how the2nd and3rd lines can add more value to the organization. After a brief introduction about the value of the 3 Lines Model and what it aims at, Ruurd van den Berg will go a spade deeper to understand the relevance of the2nd and3rd lines.

What else you need to know

With regard to the2nd Line, it deals with the limitations and false security of the integral non-financial risk profile as is still mostly used. In contrast, the advantages of a vulnerability-based risk profile are presented.

With regard to the3rd Line, it is about positioning; when is Internal Audit really "on Board"? Ruurd van den Berg gives his vision on this and shows with an example how a culture program can help. He also gives insight on how vulnerability based risk management can strengthen the cooperation between2nd Line and3rd Line.

About Ruurd van den Berg

Ruurd van den Berg is an experienced executive in high-profile positions in Finance (Executive VP), Internal Audit (CAE) and IT Risk (CRO). He worked at KLM for 9 years and at Aegon for 28 years and was a member of the Global CEO Leadership Team at Aegon. Over a period of 25 years, he represented the respective 3 Lines on the Board and at Commissioners on the Audit & Risk Committee. He also has his own experience as a supervisor and member of various Audit & Risk Committees. He has operated in a culturally diverse and international environment in Europe, the United States and Asia.

Sign up

Registration is no longer possible.