Articles liés à Value Added Auditing:4th Edition

Value Added Auditing:4th Edition - Couverture souple

Hutchins, Greg

 
9780965466554: Value Added Auditing:4th Edition

Synopsis

Too many audits end up as check-the-box exercises that add little value and frustrate both auditors and management. Yet in a world of relentless disruption, regulatory pressure, and growing ISO compliance demands, organizations can no longer afford audits that simply confirm yesterday’s controls. Auditing must evolve into a forward-looking, risk-based process that identifies vulnerabilities, strengthens governance, and drives performance.

Value Added Auditing shows you how. Grounded in proven practices and designed for ISO compliance, this book provides practical strategies, real-world case studies, and actionable tools to transform auditing into a powerful driver of resilience and business success. Whether you’re an auditor, executive, or quality professional, this guide will help you move beyond compliance to create true value


What Is Value Added Auditing?

VAA is a risk-based auditing and assurance system built on problem-solving, decision-making, and practical delivery. It’s the first and only auditing framework certified by the U.S. Department of Homeland Security for Critical Infrastructure Protection: Forensics, Assurance, Analytics®. This book shows you exactly how to conduct high-impact audits—from Homeland Security operations to ISO management systems and corporate compliance.

What Makes This Book Different?

Unlike traditional audit manuals, VAA goes far beyond the “what” and dives deep into the “how.” You’ll gain:

  • Detailed frameworks for audit planning, execution, and reporting

  • Real-world insights from certified homeland security audits

  • Customizable tools to assess and report process risks

  • Risk-focused methodologies that align with today’s evolving governance demands

Most importantly, VAA is the first book to bridge the gap between quality, operational, internal, compliance, and customer-supplier audits—delivering a unified, enterprise-wide audit solution.

Key Takeaways You’ll Learn:
  • How to identify and manage process risk audits

  • When and how risk auditors can serve as internal consultants

  • The six steps to managing and planning risk-based audits

  • How to develop realistic audit schedules and actionable audit plans

  • The most critical red flags every risk auditor must watch for

  • How to conduct powerful interviews and deliver insight-driven reports

  • Seven sample risk audit reports and how to tailor them to your organization

  • How to use custom questionnaires to evaluate internal controls and assure compliance

  • Proven techniques for evidence gathering, risk rating, and exit interviews

  • How to move from policing to value-added problem solving in your audits

Who Should Read This Book?
  • Internal and external auditors

  • Quality professionals and ISO auditors

  • Risk and compliance officers

  • Homeland Security contractors and infrastructure assessors

  • Corporate governance professionals

  • Anyone responsible for audit performance, process improvement, or operational assurance

Turn Your Audits into Strategic Assets

Audits shouldn’t just detect problems—they should prevent failure, uncover opportunity, and inform smart decision-making. Value Added Auditing gives you everything you need to implement risk-based auditing with clarity, confidence, and measurable impact.

Les informations fournies dans la section « Synopsis » peuvent faire référence à une autre édition de ce titre.

À propos de l'auteur

Greg Hutchins is the founder of 800Compete.com, WorkingIt.com, CERMAcademy.com, QualityPlusEngineering.com, and other startups. Greg Hutchins is the risk evangelist who coined the expression Future of Quality: Risk®. He can be contacted at GregH@europa.com. Greg Hutchins PE CERM is also the principal professional engineer Quality + Engineering - international supply and quality management firm. He has written best selling books on global ISO standards and risk management. Greg is the author of ISO 9000 (best selling translated into 8 languages published through John Wiley), Value Added Auditing, ISO 31000: Enterprise Risk Management, ISO Risk Based Thinking, Risk Based Thinking, Supply Management Strategies (APICS, ISM, ASQ endorsed and used in certifications), and Standard Manual of Quality Auditing and more than a dozen article international books. Q+E is the designer and developer of Certified Enterprise Risk Manager® (CERM), CERM Cyber™ certificate, and best selling ISO and ERM books. Q+E has deep domain expertise in ISO 31000, ISO 27001, and NIST 800’s. Q+E designed CERM based on its security IP including Critical Infrastructure Protection: Forensics, Assurance, Analytics®; Value Added Auditing™; Certified Enterprise Risk Manager®; Future of Quality: Risk®; CERM: Risk Based, Problem Solving | Risk Based, Decision Making®; etc. Q+E has been certified by the Department of Homeland Security for Critical Infrastructure Protection: Forensics, Assurance, Analytics®. Q+E has conducted the following Critical Infrastructure Protection (CIP) risk assessments: • Analytical. Q+E engineers and scientists conduct analytical analyses following Q+E protocols evaluating business continuity, cyber security, and physical security systems against IEEE, NFPA, ISA, PMI, ISO, NIST, COSO, NERC, DIACAP, FISMA, and ASIS standards. • Assurance. Q+E offers the client three levels of assurance: o Compliance. Q+E conducts a compliance audit against appropriate standards and guidance. o Assurance with opinion. Q+E issues an opinion based on the results of a governance, risk, and compliance (GRC) audit or ERM controls assessment. o Assurance with insurance coverage. Q+E conducts an audit and provides the requisite level of due diligence for the auditee to be covered. • Forensics. Q+E provides the above levels of assurance as well as supplies a letter to the regulatory authority averring compliance that criteria have been met.

Les informations fournies dans la section « A propos du livre » peuvent faire référence à une autre édition de ce titre.