Internal Audit Hospital
Internal Audit Hospital
Internal Audit Hospital
Healthcare Industry
Riskpro, India
1
Who is Riskpro… Why us?
ABOUT US MISSION
Riskpro is an organisation of member firms
around India devoted to client service Provide integrated risk management
excellence. Member firms offer wide range consulting services to mid-large sized
of services in the field of risk management. corporate /financial institutions in India
Currently it has offices in three major cities Be the preferred service provider for
Mumbai, Delhi and Bangalore and alliances complete Governance, Risk and Compliance
in other cities. (GRC) solutions.
Managed by experienced professionals with
experiences spanning various industries.
2
Risk Management Advisory Services
Training Recruitment
Banking – E Learning Virtual Risk Managers
Corporate Training Full Time Risk Professionals
Regular Risk Management Training Part time Risk Professionals
Online Training material Risk Managers on call – free
Workshops / Events
3
Our Delivery Methodology
FREE USP
“No Cost – Know Risk” Diagnostic Assessment
(To determine your pain points, industry benchmarking etc)
USP
PROJECT TEAM DEFINITION
Client gets to select Riskpro team members, subject matter experts.
Riskpro uses a mix of client staff / own staff for maximum value add
PROJECT EXECUTION
Constant project updates, timely project completion and project
outcomes that are practical and easy to maintain
4
Business Model – Hospital (Illustrative)
Corporate Governance Business Planning
Stakeholder
perspective
Mergers & Acquisitions/ Projects Marketing & Sales
Medical Audit
Other
Insurance including TPA Finance & Accounts MIS & FR
Enablers
Administration & Facility
Customer Service Legal & Taxation
Management
Misc.
Blood Bank Management Waste & Energy Management F&B
Important
Quality Assurance
5
Key Issues noticed in Hospitals
6
Risk Based Internal Audit How we Do
Process
Reviews
7
Internal Audit Universe
Ensuring processes to help units and HO comply with internal policy and
vi Compliance Management procedures, legal requirements, JCI, NABH and other requirements.
8
Internal Audit methodology for Hospitals
• Gaining detailed understanding of your • Detailed scoping for each audit in discussion • Providing detailed audit issues and supporting
organisation. with process leaders, unit heads, FCs and evidence (including discussions) to process leaders
• Identification of key business processes HO to identify key focus areas. at unit and management for management comments.
supporting patient service. • Conducting detailed process walkthroughs, • Organising audit closure workshop at unit with
• Importance mapping of business processes documentation , risk & controls identification process leaders, unit head and medical director to
with patient journey. and testing. discuss audit issues, rating and recommendations
Key Activities
• Identification of business risks at unit and • Continuous discussion with management at and attain common understanding.
organisation wide level. unit and HO. • Submit final audit report to unit, HO and audit
• Organising workshops at unit and HO level • Identification of issues, risks, implications, committee.
to discuss key business processes and risk recommendations and discussion with • Formation of recommendations implementation
rating to attain common understanding. process leaders. roadmap in consultation with unit and HO.
• Identification of operational and clinical • Audit issue/ process gap impact analysis on • Summary reporting to audit committee and
processes to be audited (audit wish list). clinical and support processes. presentation.
• Discussion with unit heads and HO to • Benchmarking of processes with leading • Obtain feedback.
prioritise audits. hospital practices.
• Final internal audit plan • Engagement scoping document and timelines • Final report for management and audit committee
• • • Practical recommendations and implementation
es
•
Quality
9
Patient Journey View - Illustrative
10
Other factors to be considered for Scoping
Multi-specialty Vs. Super Specialty hospital. More intense IA’s in case hospital is multi & super specialty.
Business Objectives – have to be kept in mind for each hospital/ unit and IA scope should be fine tweaked
accordingly
Age of the hospital – for new hospitals, key focus is effective implementation of SOP’s, clarity in roles &
responsibilities, service delivery monitoring. Stable/ Mature hospitals focus more on operational excellence,
introducing industry best practices.
Integrated Compliance Risk Management – Most hospitals review same controls more than once, for eg.
Billing process may be reviewed in NABH/ JCI and/ or in Internal Audit and or in ISO and or in Internal Controls
over financial reporting review. Management should consider developing an integrated compliance risk
management framework whereby risk is assessed/ tested once and reported in multiple places as required.
Past IA scope – key issues/ challenges play important role in direction setting. Audit Charter should cover key
processes/ controls monitoring regularly. Non key processes/ controls can be tested/ reviewed once in 2/3 years.
11
Riskpro Clients Our Clients
Any trademarks or logos used throughout this presentation are the property of their
respective owners
12
Team Experiences Our Experiences
Founder - Riskpro
CA, CPA, MBA-Finance (USA), FRM (GARP)
Manoj Jain
Over 15 years of extensive internal and external audit experience in India and
abroad.
Worked with KPMG United Arab Emirates, PKF South Africa, Ernst and Young
Kuwait, Deloitte Netherlands and KPMG India.
Worked with clients in a wide variety of industries and countries including trading,
retail and consumer goods, NGO, manufacturing and banking and finance. Major
clients include banks, investment companies, manufacturing organizations,
aviation etc.
14
RESUMES - Our team Credentials
Co-Founder - Riskpro
Casper Abraham
Co-Founder - Riskpro
B.Com, CA
30 years of accounting, finance and risk management experience
Most recent employment with Emerson, a USA Fortune 500
Worked for Hinduja, Pidilite, Excel Industries and internationally
Strong Financial Process and internal controls experience
15
RESUMES - PARTNERSHIPS
Specialist Risk Consultant – Business Continuity
Andrew Hiles
Founder and 15-year Chairman of Survive, the first international user group for Business
Continuity professionals
Founding director and first Fellow of the Business Continuity Institute
Over 25 years international consulting expertise in Risk, Crisis, Emergency, Incident, and
Business Continuity and ICT Disaster Recovery Management
Multi-sector experience including Banking, Insurance, Finance, Oil, Gas, Energy,
Manufacturing, Retail, Hi-Tech & Telecom
Western Press Award for services to business, 1994; BCI/CIR nomination for
lifetime achievement in BC, 1999, London; inducted into BC Hall of Fame by CPM magazine,
2004, Washington DC.
Chartered Accountant and CISA, with over 12 years of experience in business risk services.
16
Contacts
Email : info@riskpro.in
Web: www.riskpro.in
THANKS
17
Detailed Coverage - Hospital Audits
18
Detailed Coverage – Hospital Governance
Business Whether IA
Sub Areas
Criticality recommended
Marketing H Yes
19
Detailed Coverage – Hospital Governance
(ii) Medical & Quality Audit
Whether IA
Sub Areas Business Criticality
recommended
Allied Health operations M Yes
Admissions H Yes
Pharmacy M Yes
Whether IA
Sub Areas Business Criticality
recommended
22
Detailed Coverage – Hospital Governance
(v) Finance & Accounts
Whether IA
Sub Areas Business Criticality
recommended
Budgeting H Yes
Treasury M Yes
Taxation H Yes
Investments M Yes
23
Detailed Coverage – Hospital Governance
(vi) Compliance
Whether IA
Sub Areas Business Criticality
recommended
Secretarial H Yes
EHS H Yes
Yes
JCI standards compliance H
24
Examples of our Services
Risk
25
Governance, Risk and Compliance Offering Our GRC Approach
Company level
Support Processes
• GRC Technology Implementation – Provide recommendations and select vendor for GRC Tool
•HR Policies and Processes to minimize people risk, frauds and strengthen succession planning
•Training and Awareness build up – Targeted and Ongoing training in areas of concern.
•E Learning Courses in Risk Management, Fraud Risk Management, Governance etc
26
Governance, Risk and Compliance (GRC) Our GRC Approach
Risk management software implementation
27
Enterprise Risk Management (ERM) - Methodology How we Do
28
IT Governance How we Do
IS AUDIT
• Operating Systems Audit
• Database Audit
• Networking Audit IT GOVERNANCE
• Firewall Audit • COBIT
• IDS Audit • ValIT
• Web Application, Data Center Audit • Balanced Scorecard
• Internet Banking, Core Banking Audit • IT & Business Maturity Models
• Performance & Forensic Auditing
•Application Systems - Functional review
• Compliance with IS Policies & Procedures
IT ASSURANCE
• Business Continuity Planning
• Computer Crime Investigations
INFORMATION SECURITY • Training in IT
• Penetration Testing • Compliance with IS Policies &
• Application Systems - Security review Procedures
• Review of IS Controls
• BS 7799 / (ISO 27001) Implémentation
• Formation of IS Security Policy
• Compliance with IS Policies & Procedures
29
Forensic and investigation services How we Do
Based on our understanding of your requirements, we have customized a package of our solution
offerings to meet your needs, which is detailed in the ensuing slides.
Based on our understanding of your requirements, we have customized a package of our solution
To detect and prevent fraud
offerings to meet your needs, which is detailed in the ensuing slides.
and evaluate Code Of Conduct Our Solution for you Benefits To You
Compliance on following Our Solution For you
parameters :-
30