SlideShare ist ein Scribd-Unternehmen logo
1 von 20
Enterprise Risk
 Management
 Take a Close Look at
    COSO’s New
   Internal Control
     Framework
Eight
Components
Three more layers
added to the
original five COSO
components:

 • Internal
   Environment
 • Objective
   Setting
 • Event
   Identification
Four
Objectives
Strategic objective
added to the
original three
COSO objectives:
• Operations
• Reporting*
• Compliance
* Reporting is now
  much more than
  financial reporting
Internal Environment
The internal environment encompasses the tone of an organiza-
tion, influencing the risk consciousness of its people, and is the
foundation for all other components of enterprise risk manage-
ment, providing discipline and structure.
Internal environment factors include:
   • an entity’s risk management philosophy;
   • its risk appetite and risk culture;
   • oversight by the board of directors;
   • the integrity, ethical values and competence of the entity’s
     people;
   • management’s philosophy and operating style; and
   • the way management assigns authority and responsibility,
     and organizes and develops its people.
Objective Setting
Every entity faces a variety of risks from external and internal
sources, and a precondition to effective event identification, risk
assessment and risk response is establishment of objectives,
linked at different levels and internally consistent.
Objectives are set at the strategic level, establishing a basis for
operations, reporting, and compliance objectives.
Objectives are aligned with the entity’s risk appetite, which
drives risk tolerance levels for the entity’s activities.
Event Identification
Management identifies potential events affecting an entity’s
ability to successfully implement strategy and achieve objectives.
Events with a potentially negative impact represent risks, which
require management’s assessment and response.
Events with a potentially positive impact may offset negative
impacts or represent opportunities. Management channels
opportunities back into the strategy and objective-setting
processes.
A variety of internal and external factors give rise to events.
When identifying potential events, management considers the full
scope of the organization. Management considers the context
within which the entity operates and its risk tolerances.
Risk Assessment
Risk assessment allows an entity to consider the extent to which
potential events might have an impact on achievement of
objectives.
Management should assess events from two perspectives –
likelihood and impact – and normally uses a combination of
qualitative and quantitative methods.
The positive and negative impacts of potential events should be
examined, individually or by category, across the entity.
Potentially negative events are assessed on both an inherent and a
residual basis.
Risk Response

 Having assessed relevant risks, management determines how
 it will respond.
 Responses include risk avoidance, reduction, sharing and
 acceptance.
 In considering its response, management considers costs and
 benefits, and selects a response that brings expected likelihood
 and impact within the desired risk tolerances.
Control Activities
Control activities are the policies and procedures that help
ensure that management’s risk responses are carried out.
Control activities occur throughout the organization, at all
levels and in all functions.
They include a range of activities as diverse as:
  • approvals,
  • authorizations,
  • verifications,
  • reconciliations,
  • reviews of operating performance,
  • security of assets, and
  • segregation of duties.
Information and Communication
Pertinent information is identified, captured and communicated in a
form and timeframe that enable people to carry out their
responsibilities. Information systems use internally generated data,
and information about external events, activities and conditions,
providing information for managing enterprise risks and making
informed decisions relative to objectives. Effective communication
also occurs, flowing down, across and up the organization. All
personnel receive a clear message from top management that
enterprise risk management responsibilities must be taken seriously.
They understand their own role in enterprise risk management, as
well as how individual activities relate to the work of others. They
must have a means of communicating significant information
upstream. There is also effective communication with external
parties.
Monitoring
Enterprise risk management is monitored –a process that
assesses the presence and functioning of its components over
time.
This is accomplished through ongoing monitoring activities,
separate evaluations or a combination of the two. Ongoing
monitoring occurs in the normal course of management
activities.
The scope and frequency of separate evaluations will depend
primarily on an assessment of risks and the effectiveness of
ongoing monitoring procedures.
Enterprise risk management deficiencies are reported upstream,
with serious matters reported to top management and the board.
Internal Environment
   Risk                 Risk                 Risk             Board of            Integrity and      Commitment
Management             Appetite             Culture           Directors              Ethical            to
Philosophy                                                                           Values          Competence

•Value              •Value             •Independent        •Independent          •Standards of      •Knowledge
•Communicate        •Qualitative       •Active             •Active                 behavior         •Skills
  in words and      •Quantitative      •Involved           •Involved             •Prerequisite      •Trade-offs
  actions           •Linked to                                                   •CEO example
                     strategy                                                     Incentives




  Management             Organizational          Assignment of            Human Resource            Differences in
 Philosophy and            Structure             Authority and              Policies and            Environment
 Operating Style                                 Responsibility              Practices

•Formal vs.             •Reporting lines        •Empowerment              •Qualified              •Management
  Informal              •Centralized/           •Accountability           •Training                 preferences
•Conservative vs.        Decentralized                                    •Compensation           •Value judgments
 Aggressive             •Matrix/Function/                                 •Incentives and         •Management
•Aligned                 Geography                                          Discipline              Styles
OBJECTIVE SETTING

 Strategic      Related       Selected       Risk             Risk
 Objectives    Objectives    Objectives     Appetite        Tolerance


•High-level   •Operations   •Align and    •Growth, risk    •Acceptable
 goals        •Reporting      support      and return        variance
•Support      •Compliance   •Manage-      •Resource        •Unit of
 mission/     •Safeguard-    ment          allocation       measure
  vision       ing of         decision    •People,           of
•Strategic     assets                      process and      objective
 choices                                  infrastructure
EVENT IDENTIFICATION
                    Factors
   Events         Influencing    Metho-          Event          Event       Risks and
                 Strategy and   dology and    Interdepen-     Categories    Opportu-
                   Objectives   Techniques      dencies                       nities



•Incident        •Internal      •Ongoing      •Triggering    •Common       •Negative
•Positive and/   •External      •Periodic      events         groupings     impact: risks
 or negative                    •Past and     •Interrelate                 •Positive
 impacts                         future                                     impact:
                                •Supporting                                 opportunity;
                                 tools                                       offsets to
                                                                             risks
RISK ASSESSMENT

 Inherent and        Likelihood and       Qualitative and      Correlation
 Residual Risk          Impact             Quantitative
                                           Methodologies
                                          and Techniques


•Before             •Expected, worst-     •Qualitative      •Sequence of events
 management          case, distribution   •Quantitative     •Categories
 actions            •Time horizons        •Inherent and     •Stress testing
•After management   •Unit of measure       residual basis   •Scenarios
 actions            •Observable data
•Expected and
 unexpected
RISK RESPONSE
 Identify Risk      Evaluate         Select     Portfolio View
  Responses       Possible Risk     Response
                   Responses

•Avoid           •Impact          •Management   •Entity level
•Reduce          •Likelihood       decision     •Business unit
•Share           •Cost versus                    level
•Accept           benefit                       •Inherent and
                 •Innovative                     residual basis
                  responses
CONTROL ACTIVITIES
 Integration        Types of        General          Application          Entity-
  with Risk         Control         Controls          Controls           Specific
  Response          Activities
•Build directly   •Policies       •Information       •Completeness    •Entity specific
 into             •Procedures      technology (IT)   •Accuracy          strategies and
 management       •Preventative     management       •Authorization    objectives
  processes       •Detective      •IT infra-         •Validity        •Operating
•Interrelate      •Manual           structure                          environment
                  •Automatic      •Security                           •Complexity of
                                   management                           the entity
                                  •Software
                                   development &
                                    maintenance
INFORMATION &
        COMMUNICATION
      Information      Strategic and Integrated       Communication
                               Systems


•Internal              •Strategic                 •Internal
•External              •Operational               •External
•Manual                •Past and current          •Entity-wide
•Computerized          •Level of detail           •Expectations and
•Formal                •Timeliness                 responsibilities
•Informal              •Quality                   •Framing
•Information systems                              •Means of transmission
 architecture
MONITORING
     Ongoing                Separate             Reporting
                           Evaluations          Deficiencies

•Real-time               •Scope               •Ongoing
•Built-in                •Frequency           •External parties
•Day-to-day operations   •Self-assessments/   •Protocols
                          internal auditors   •Alternative channels
                         •Extent of
                          documentation
For more information:

             Check out COSO’s exposure draft
             Enterprise Risk Management
             Framework
             At www.erm.coso.org


             Download it in Adobe PDF format
             (152 pages)

Weitere ähnliche Inhalte

Was ist angesagt?

Competency romance pt2 Markus + O'Connor ~ The reality of the competency ap...
Competency romance pt2   Markus + O'Connor ~ The reality of the competency ap...Competency romance pt2   Markus + O'Connor ~ The reality of the competency ap...
Competency romance pt2 Markus + O'Connor ~ The reality of the competency ap...Frank O'Connor
 
PECB Webinar: An Integrated QMS EMS OHSAS System Using ISO 31000
PECB Webinar: An Integrated QMS EMS OHSAS System Using ISO 31000PECB Webinar: An Integrated QMS EMS OHSAS System Using ISO 31000
PECB Webinar: An Integrated QMS EMS OHSAS System Using ISO 31000PECB
 
Risk seminar - john crawley & emer mc aneny
Risk seminar - john crawley & emer mc anenyRisk seminar - john crawley & emer mc aneny
Risk seminar - john crawley & emer mc anenyИван Вали-Пур
 
Mapping Your Career in Physical Security
Mapping Your Career in Physical SecurityMapping Your Career in Physical Security
Mapping Your Career in Physical Securityguidepostsolutions
 
Security risk management
Security risk managementSecurity risk management
Security risk managementbrijesh singh
 
Business continuity management fundamentals update
Business continuity management fundamentals updateBusiness continuity management fundamentals update
Business continuity management fundamentals updateExo Futures
 
Formal Risk Assessment Workshop
Formal Risk Assessment WorkshopFormal Risk Assessment Workshop
Formal Risk Assessment WorkshopPraveen Vackayil
 
A structured approach to Enterprise Risk Management (ERM) and the requirement...
A structured approach to Enterprise Risk Management (ERM) and the requirement...A structured approach to Enterprise Risk Management (ERM) and the requirement...
A structured approach to Enterprise Risk Management (ERM) and the requirement...Hassan Zaitoun
 
PECB Webinar: Risk-management in IT intensive SMEs
PECB Webinar: Risk-management in IT intensive SMEsPECB Webinar: Risk-management in IT intensive SMEs
PECB Webinar: Risk-management in IT intensive SMEsPECB
 
CFO Risk Intelligence - Harvey Christophers
CFO Risk Intelligence - Harvey ChristophersCFO Risk Intelligence - Harvey Christophers
CFO Risk Intelligence - Harvey ChristophersAzure Group
 
Targeting change efforts at organizational subsystems
Targeting change efforts at organizational subsystemsTargeting change efforts at organizational subsystems
Targeting change efforts at organizational subsystemsSharon Johnson
 
Enterprise Risk Management and Sustainability
Enterprise Risk Management and SustainabilityEnterprise Risk Management and Sustainability
Enterprise Risk Management and SustainabilityJeff B
 
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...PECB
 
PECB Webinar: Enterprise Risk Management - Unsuccessful efforts due to lack o...
PECB Webinar: Enterprise Risk Management - Unsuccessful efforts due to lack o...PECB Webinar: Enterprise Risk Management - Unsuccessful efforts due to lack o...
PECB Webinar: Enterprise Risk Management - Unsuccessful efforts due to lack o...PECB
 
Robert jones & agnes hunt hospital presentation
Robert jones & agnes hunt hospital presentationRobert jones & agnes hunt hospital presentation
Robert jones & agnes hunt hospital presentationLawson Odere
 
ToTCOOP+i O3 o4 unit-9_final_version_en
ToTCOOP+i O3 o4 unit-9_final_version_enToTCOOP+i O3 o4 unit-9_final_version_en
ToTCOOP+i O3 o4 unit-9_final_version_enToTCOOPiTech
 

Was ist angesagt? (18)

Competency romance pt2 Markus + O'Connor ~ The reality of the competency ap...
Competency romance pt2   Markus + O'Connor ~ The reality of the competency ap...Competency romance pt2   Markus + O'Connor ~ The reality of the competency ap...
Competency romance pt2 Markus + O'Connor ~ The reality of the competency ap...
 
PECB Webinar: An Integrated QMS EMS OHSAS System Using ISO 31000
PECB Webinar: An Integrated QMS EMS OHSAS System Using ISO 31000PECB Webinar: An Integrated QMS EMS OHSAS System Using ISO 31000
PECB Webinar: An Integrated QMS EMS OHSAS System Using ISO 31000
 
Risk Management Overview
Risk Management OverviewRisk Management Overview
Risk Management Overview
 
Risk seminar - john crawley & emer mc aneny
Risk seminar - john crawley & emer mc anenyRisk seminar - john crawley & emer mc aneny
Risk seminar - john crawley & emer mc aneny
 
Mapping Your Career in Physical Security
Mapping Your Career in Physical SecurityMapping Your Career in Physical Security
Mapping Your Career in Physical Security
 
Security risk management
Security risk managementSecurity risk management
Security risk management
 
Business continuity management fundamentals update
Business continuity management fundamentals updateBusiness continuity management fundamentals update
Business continuity management fundamentals update
 
Formal Risk Assessment Workshop
Formal Risk Assessment WorkshopFormal Risk Assessment Workshop
Formal Risk Assessment Workshop
 
A structured approach to Enterprise Risk Management (ERM) and the requirement...
A structured approach to Enterprise Risk Management (ERM) and the requirement...A structured approach to Enterprise Risk Management (ERM) and the requirement...
A structured approach to Enterprise Risk Management (ERM) and the requirement...
 
PECB Webinar: Risk-management in IT intensive SMEs
PECB Webinar: Risk-management in IT intensive SMEsPECB Webinar: Risk-management in IT intensive SMEs
PECB Webinar: Risk-management in IT intensive SMEs
 
CFO Risk Intelligence - Harvey Christophers
CFO Risk Intelligence - Harvey ChristophersCFO Risk Intelligence - Harvey Christophers
CFO Risk Intelligence - Harvey Christophers
 
Targeting change efforts at organizational subsystems
Targeting change efforts at organizational subsystemsTargeting change efforts at organizational subsystems
Targeting change efforts at organizational subsystems
 
Enterprise Risk Management and Sustainability
Enterprise Risk Management and SustainabilityEnterprise Risk Management and Sustainability
Enterprise Risk Management and Sustainability
 
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
Implementation of Enterprise Risk Management with ISO 31000 Risk Management S...
 
PECB Webinar: Enterprise Risk Management - Unsuccessful efforts due to lack o...
PECB Webinar: Enterprise Risk Management - Unsuccessful efforts due to lack o...PECB Webinar: Enterprise Risk Management - Unsuccessful efforts due to lack o...
PECB Webinar: Enterprise Risk Management - Unsuccessful efforts due to lack o...
 
Robert jones & agnes hunt hospital presentation
Robert jones & agnes hunt hospital presentationRobert jones & agnes hunt hospital presentation
Robert jones & agnes hunt hospital presentation
 
T. vogus saturday the case for org
T. vogus saturday the case for orgT. vogus saturday the case for org
T. vogus saturday the case for org
 
ToTCOOP+i O3 o4 unit-9_final_version_en
ToTCOOP+i O3 o4 unit-9_final_version_enToTCOOP+i O3 o4 unit-9_final_version_en
ToTCOOP+i O3 o4 unit-9_final_version_en
 

Andere mochten auch

Unit 2 business-plan
Unit 2 business-planUnit 2 business-plan
Unit 2 business-planartipradhan
 
Entrepreneurship development
Entrepreneurship developmentEntrepreneurship development
Entrepreneurship developmentartipradhan
 
Sales of goods_act,1930
Sales of goods_act,1930Sales of goods_act,1930
Sales of goods_act,1930artipradhan
 
Entrepreneurship
EntrepreneurshipEntrepreneurship
Entrepreneurshipartipradhan
 
Remedies for breach_of_contract-10
Remedies for breach_of_contract-10Remedies for breach_of_contract-10
Remedies for breach_of_contract-10artipradhan
 
Srivastava women 2006
Srivastava women 2006Srivastava women 2006
Srivastava women 2006artipradhan
 

Andere mochten auch (8)

Unit 2 business-plan
Unit 2 business-planUnit 2 business-plan
Unit 2 business-plan
 
Entrepreneurship development
Entrepreneurship developmentEntrepreneurship development
Entrepreneurship development
 
Sales of goods_act,1930
Sales of goods_act,1930Sales of goods_act,1930
Sales of goods_act,1930
 
Details
DetailsDetails
Details
 
Entrepreneurship
EntrepreneurshipEntrepreneurship
Entrepreneurship
 
Remedies for breach_of_contract-10
Remedies for breach_of_contract-10Remedies for breach_of_contract-10
Remedies for breach_of_contract-10
 
Ventrue capital
Ventrue capitalVentrue capital
Ventrue capital
 
Srivastava women 2006
Srivastava women 2006Srivastava women 2006
Srivastava women 2006
 

Ähnlich wie Enterprise risk-mgmt[1]

mr neeraj - day 1 - compliance
mr neeraj - day 1 - compliancemr neeraj - day 1 - compliance
mr neeraj - day 1 - complianceNeeraj Verma
 
Risk Management Framework - Dr. Mustafa Degerli
Risk Management Framework - Dr. Mustafa DegerliRisk Management Framework - Dr. Mustafa Degerli
Risk Management Framework - Dr. Mustafa DegerliDr. Mustafa Değerli
 
Agile and the nature of decision making
Agile and the nature of decision makingAgile and the nature of decision making
Agile and the nature of decision makingDennis Stevens
 
Manajemen Risiko Menurut COSO
Manajemen Risiko Menurut COSOManajemen Risiko Menurut COSO
Manajemen Risiko Menurut COSODina Pramudianti
 
Agile and the nature of decision making
Agile and the nature of decision makingAgile and the nature of decision making
Agile and the nature of decision makingdrewz lin
 
Environmental Analysis
Environmental  AnalysisEnvironmental  Analysis
Environmental AnalysisElijah Ezendu
 
Mastering Information Technology Risk Management
Mastering Information Technology Risk ManagementMastering Information Technology Risk Management
Mastering Information Technology Risk ManagementGoutama Bachtiar
 
Panel Debate - Rating Agencies and Risk Management
Panel Debate - Rating Agencies and Risk Management Panel Debate - Rating Agencies and Risk Management
Panel Debate - Rating Agencies and Risk Management FERMA
 
Incorporating Risk Management into BCP
Incorporating Risk Management into BCPIncorporating Risk Management into BCP
Incorporating Risk Management into BCPRon Andrews
 
Risk management ppt 111p (training module)
Risk management ppt 111p (training module)Risk management ppt 111p (training module)
Risk management ppt 111p (training module)Sadia Razzaq
 
Pivotal role of Intelligence analysts in intelligence-led-policing
Pivotal role of Intelligence analysts in intelligence-led-policingPivotal role of Intelligence analysts in intelligence-led-policing
Pivotal role of Intelligence analysts in intelligence-led-policingDalene
 
Pivotal role of intelligence analysis in ILP
Pivotal role of intelligence analysis in ILPPivotal role of intelligence analysis in ILP
Pivotal role of intelligence analysis in ILPdalened
 
Risk assessment and compliance 151119
Risk assessment and compliance 151119Risk assessment and compliance 151119
Risk assessment and compliance 151119KAYODE ADEBIYI
 

Ähnlich wie Enterprise risk-mgmt[1] (20)

Risk Health Check
Risk Health CheckRisk Health Check
Risk Health Check
 
mr neeraj - day 1 - compliance
mr neeraj - day 1 - compliancemr neeraj - day 1 - compliance
mr neeraj - day 1 - compliance
 
Risk Management Framework - Dr. Mustafa Degerli
Risk Management Framework - Dr. Mustafa DegerliRisk Management Framework - Dr. Mustafa Degerli
Risk Management Framework - Dr. Mustafa Degerli
 
MAA_Riskmanagement
MAA_RiskmanagementMAA_Riskmanagement
MAA_Riskmanagement
 
Agile and the nature of decision making
Agile and the nature of decision makingAgile and the nature of decision making
Agile and the nature of decision making
 
Coso erm
Coso ermCoso erm
Coso erm
 
Coso erm
Coso ermCoso erm
Coso erm
 
Manajemen Risiko Menurut COSO
Manajemen Risiko Menurut COSOManajemen Risiko Menurut COSO
Manajemen Risiko Menurut COSO
 
Agile and the nature of decision making
Agile and the nature of decision makingAgile and the nature of decision making
Agile and the nature of decision making
 
COSO Vs ERM - NMIMS INDORE
COSO Vs ERM - NMIMS INDORECOSO Vs ERM - NMIMS INDORE
COSO Vs ERM - NMIMS INDORE
 
Risk management
Risk managementRisk management
Risk management
 
Environmental Analysis
Environmental  AnalysisEnvironmental  Analysis
Environmental Analysis
 
Mastering Information Technology Risk Management
Mastering Information Technology Risk ManagementMastering Information Technology Risk Management
Mastering Information Technology Risk Management
 
COSO_ERM.ppt
COSO_ERM.pptCOSO_ERM.ppt
COSO_ERM.ppt
 
Panel Debate - Rating Agencies and Risk Management
Panel Debate - Rating Agencies and Risk Management Panel Debate - Rating Agencies and Risk Management
Panel Debate - Rating Agencies and Risk Management
 
Incorporating Risk Management into BCP
Incorporating Risk Management into BCPIncorporating Risk Management into BCP
Incorporating Risk Management into BCP
 
Risk management ppt 111p (training module)
Risk management ppt 111p (training module)Risk management ppt 111p (training module)
Risk management ppt 111p (training module)
 
Pivotal role of Intelligence analysts in intelligence-led-policing
Pivotal role of Intelligence analysts in intelligence-led-policingPivotal role of Intelligence analysts in intelligence-led-policing
Pivotal role of Intelligence analysts in intelligence-led-policing
 
Pivotal role of intelligence analysis in ILP
Pivotal role of intelligence analysis in ILPPivotal role of intelligence analysis in ILP
Pivotal role of intelligence analysis in ILP
 
Risk assessment and compliance 151119
Risk assessment and compliance 151119Risk assessment and compliance 151119
Risk assessment and compliance 151119
 

Mehr von artipradhan

Feasibility study
Feasibility studyFeasibility study
Feasibility studyartipradhan
 
Entrepreneurship developmen 21_sep_2010
Entrepreneurship developmen 21_sep_2010Entrepreneurship developmen 21_sep_2010
Entrepreneurship developmen 21_sep_2010artipradhan
 
Business plan format_
Business plan format_Business plan format_
Business plan format_artipradhan
 
Sales of good_act
Sales of good_actSales of good_act
Sales of good_actartipradhan
 
Performance of contract-8
Performance of contract-8Performance of contract-8
Performance of contract-8artipradhan
 
Offer and acceptance-3
Offer and acceptance-3Offer and acceptance-3
Offer and acceptance-3artipradhan
 
Nature of contract-2
Nature of contract-2Nature of contract-2
Nature of contract-2artipradhan
 
Legality of object-7
Legality of object-7Legality of object-7
Legality of object-7artipradhan
 
Indemnity and guarantee-11
Indemnity and guarantee-11Indemnity and guarantee-11
Indemnity and guarantee-11artipradhan
 
Dischrage of contract-9
Dischrage of contract-9Dischrage of contract-9
Dischrage of contract-9artipradhan
 
Contract of agency-12
Contract of agency-12Contract of agency-12
Contract of agency-12artipradhan
 
Contingent contract
Contingent contractContingent contract
Contingent contractartipradhan
 
Capacityto contract
Capacityto contractCapacityto contract
Capacityto contractartipradhan
 

Mehr von artipradhan (20)

Mf3 01 ms-mamik
Mf3 01 ms-mamikMf3 01 ms-mamik
Mf3 01 ms-mamik
 
Feasibility study
Feasibility studyFeasibility study
Feasibility study
 
Entrepreneurship developmen 21_sep_2010
Entrepreneurship developmen 21_sep_2010Entrepreneurship developmen 21_sep_2010
Entrepreneurship developmen 21_sep_2010
 
Business plan format_
Business plan format_Business plan format_
Business plan format_
 
Void agreements
Void agreementsVoid agreements
Void agreements
 
Sales of good_act
Sales of good_actSales of good_act
Sales of good_act
 
Performance of contract-8
Performance of contract-8Performance of contract-8
Performance of contract-8
 
Offer and acceptance-3
Offer and acceptance-3Offer and acceptance-3
Offer and acceptance-3
 
Ni act
Ni actNi act
Ni act
 
Nature of contract-2
Nature of contract-2Nature of contract-2
Nature of contract-2
 
Legality of object-7
Legality of object-7Legality of object-7
Legality of object-7
 
Indemnity and guarantee-11
Indemnity and guarantee-11Indemnity and guarantee-11
Indemnity and guarantee-11
 
Free consent 6
Free consent 6Free consent 6
Free consent 6
 
Dischrage of contract-9
Dischrage of contract-9Dischrage of contract-9
Dischrage of contract-9
 
Cp act
Cp actCp act
Cp act
 
Contract of agency-12
Contract of agency-12Contract of agency-12
Contract of agency-12
 
Contingent contract
Contingent contractContingent contract
Contingent contract
 
Consideration 4
Consideration 4Consideration 4
Consideration 4
 
Risk eng
Risk engRisk eng
Risk eng
 
Capacityto contract
Capacityto contractCapacityto contract
Capacityto contract
 

Kürzlich hochgeladen

Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth MarketingShawn Pang
 
Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Servicediscovermytutordmt
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...lizamodels9
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMANIlamathiKannappan
 
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLSeo
 
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779Delhi Call girls
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Neil Kimberley
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...Paul Menig
 
The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024christinemoorman
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Dave Litwiller
 
Catalogue ONG NƯỚC uPVC - HDPE DE NHAT.pdf
Catalogue ONG NƯỚC uPVC - HDPE DE NHAT.pdfCatalogue ONG NƯỚC uPVC - HDPE DE NHAT.pdf
Catalogue ONG NƯỚC uPVC - HDPE DE NHAT.pdfOrient Homes
 
The Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case studyThe Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case studyEthan lee
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Dipal Arora
 
BEST ✨ Call Girls In Indirapuram Ghaziabad ✔️ 9871031762 ✔️ Escorts Service...
BEST ✨ Call Girls In  Indirapuram Ghaziabad  ✔️ 9871031762 ✔️ Escorts Service...BEST ✨ Call Girls In  Indirapuram Ghaziabad  ✔️ 9871031762 ✔️ Escorts Service...
BEST ✨ Call Girls In Indirapuram Ghaziabad ✔️ 9871031762 ✔️ Escorts Service...noida100girls
 
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurVIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurSuhani Kapoor
 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communicationskarancommunications
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst SummitHolger Mueller
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Roland Driesen
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 

Kürzlich hochgeladen (20)

Tech Startup Growth Hacking 101 - Basics on Growth Marketing
Tech Startup Growth Hacking 101  - Basics on Growth MarketingTech Startup Growth Hacking 101  - Basics on Growth Marketing
Tech Startup Growth Hacking 101 - Basics on Growth Marketing
 
Call Girls in Gomti Nagar - 7388211116 - With room Service
Call Girls in Gomti Nagar - 7388211116  - With room ServiceCall Girls in Gomti Nagar - 7388211116  - With room Service
Call Girls in Gomti Nagar - 7388211116 - With room Service
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
 
A DAY IN THE LIFE OF A SALESMAN / WOMAN
A DAY IN THE LIFE OF A  SALESMAN / WOMANA DAY IN THE LIFE OF A  SALESMAN / WOMAN
A DAY IN THE LIFE OF A SALESMAN / WOMAN
 
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
 
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
Best VIP Call Girls Noida Sector 40 Call Me: 8448380779
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023
 
7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...7.pdf This presentation captures many uses and the significance of the number...
7.pdf This presentation captures many uses and the significance of the number...
 
The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024The CMO Survey - Highlights and Insights Report - Spring 2024
The CMO Survey - Highlights and Insights Report - Spring 2024
 
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
Enhancing and Restoring Safety & Quality Cultures - Dave Litwiller - May 2024...
 
Catalogue ONG NƯỚC uPVC - HDPE DE NHAT.pdf
Catalogue ONG NƯỚC uPVC - HDPE DE NHAT.pdfCatalogue ONG NƯỚC uPVC - HDPE DE NHAT.pdf
Catalogue ONG NƯỚC uPVC - HDPE DE NHAT.pdf
 
The Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case studyThe Coffee Bean & Tea Leaf(CBTL), Business strategy case study
The Coffee Bean & Tea Leaf(CBTL), Business strategy case study
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
 
BEST ✨ Call Girls In Indirapuram Ghaziabad ✔️ 9871031762 ✔️ Escorts Service...
BEST ✨ Call Girls In  Indirapuram Ghaziabad  ✔️ 9871031762 ✔️ Escorts Service...BEST ✨ Call Girls In  Indirapuram Ghaziabad  ✔️ 9871031762 ✔️ Escorts Service...
BEST ✨ Call Girls In Indirapuram Ghaziabad ✔️ 9871031762 ✔️ Escorts Service...
 
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service JamshedpurVIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
VIP Call Girl Jamshedpur Aashi 8250192130 Independent Escort Service Jamshedpur
 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communications
 
KestrelPro Flyer Japan IT Week 2024 (English)
KestrelPro Flyer Japan IT Week 2024 (English)KestrelPro Flyer Japan IT Week 2024 (English)
KestrelPro Flyer Japan IT Week 2024 (English)
 
Progress Report - Oracle Database Analyst Summit
Progress  Report - Oracle Database Analyst SummitProgress  Report - Oracle Database Analyst Summit
Progress Report - Oracle Database Analyst Summit
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
 

Enterprise risk-mgmt[1]

  • 1. Enterprise Risk Management Take a Close Look at COSO’s New Internal Control Framework
  • 2. Eight Components Three more layers added to the original five COSO components: • Internal Environment • Objective Setting • Event Identification
  • 3. Four Objectives Strategic objective added to the original three COSO objectives: • Operations • Reporting* • Compliance * Reporting is now much more than financial reporting
  • 4. Internal Environment The internal environment encompasses the tone of an organiza- tion, influencing the risk consciousness of its people, and is the foundation for all other components of enterprise risk manage- ment, providing discipline and structure. Internal environment factors include: • an entity’s risk management philosophy; • its risk appetite and risk culture; • oversight by the board of directors; • the integrity, ethical values and competence of the entity’s people; • management’s philosophy and operating style; and • the way management assigns authority and responsibility, and organizes and develops its people.
  • 5. Objective Setting Every entity faces a variety of risks from external and internal sources, and a precondition to effective event identification, risk assessment and risk response is establishment of objectives, linked at different levels and internally consistent. Objectives are set at the strategic level, establishing a basis for operations, reporting, and compliance objectives. Objectives are aligned with the entity’s risk appetite, which drives risk tolerance levels for the entity’s activities.
  • 6. Event Identification Management identifies potential events affecting an entity’s ability to successfully implement strategy and achieve objectives. Events with a potentially negative impact represent risks, which require management’s assessment and response. Events with a potentially positive impact may offset negative impacts or represent opportunities. Management channels opportunities back into the strategy and objective-setting processes. A variety of internal and external factors give rise to events. When identifying potential events, management considers the full scope of the organization. Management considers the context within which the entity operates and its risk tolerances.
  • 7. Risk Assessment Risk assessment allows an entity to consider the extent to which potential events might have an impact on achievement of objectives. Management should assess events from two perspectives – likelihood and impact – and normally uses a combination of qualitative and quantitative methods. The positive and negative impacts of potential events should be examined, individually or by category, across the entity. Potentially negative events are assessed on both an inherent and a residual basis.
  • 8. Risk Response Having assessed relevant risks, management determines how it will respond. Responses include risk avoidance, reduction, sharing and acceptance. In considering its response, management considers costs and benefits, and selects a response that brings expected likelihood and impact within the desired risk tolerances.
  • 9. Control Activities Control activities are the policies and procedures that help ensure that management’s risk responses are carried out. Control activities occur throughout the organization, at all levels and in all functions. They include a range of activities as diverse as: • approvals, • authorizations, • verifications, • reconciliations, • reviews of operating performance, • security of assets, and • segregation of duties.
  • 10. Information and Communication Pertinent information is identified, captured and communicated in a form and timeframe that enable people to carry out their responsibilities. Information systems use internally generated data, and information about external events, activities and conditions, providing information for managing enterprise risks and making informed decisions relative to objectives. Effective communication also occurs, flowing down, across and up the organization. All personnel receive a clear message from top management that enterprise risk management responsibilities must be taken seriously. They understand their own role in enterprise risk management, as well as how individual activities relate to the work of others. They must have a means of communicating significant information upstream. There is also effective communication with external parties.
  • 11. Monitoring Enterprise risk management is monitored –a process that assesses the presence and functioning of its components over time. This is accomplished through ongoing monitoring activities, separate evaluations or a combination of the two. Ongoing monitoring occurs in the normal course of management activities. The scope and frequency of separate evaluations will depend primarily on an assessment of risks and the effectiveness of ongoing monitoring procedures. Enterprise risk management deficiencies are reported upstream, with serious matters reported to top management and the board.
  • 12. Internal Environment Risk Risk Risk Board of Integrity and Commitment Management Appetite Culture Directors Ethical to Philosophy Values Competence •Value •Value •Independent •Independent •Standards of •Knowledge •Communicate •Qualitative •Active •Active behavior •Skills in words and •Quantitative •Involved •Involved •Prerequisite •Trade-offs actions •Linked to •CEO example strategy Incentives Management Organizational Assignment of Human Resource Differences in Philosophy and Structure Authority and Policies and Environment Operating Style Responsibility Practices •Formal vs. •Reporting lines •Empowerment •Qualified •Management Informal •Centralized/ •Accountability •Training preferences •Conservative vs. Decentralized •Compensation •Value judgments Aggressive •Matrix/Function/ •Incentives and •Management •Aligned Geography Discipline Styles
  • 13. OBJECTIVE SETTING Strategic Related Selected Risk Risk Objectives Objectives Objectives Appetite Tolerance •High-level •Operations •Align and •Growth, risk •Acceptable goals •Reporting support and return variance •Support •Compliance •Manage- •Resource •Unit of mission/ •Safeguard- ment allocation measure vision ing of decision •People, of •Strategic assets process and objective choices infrastructure
  • 14. EVENT IDENTIFICATION Factors Events Influencing Metho- Event Event Risks and Strategy and dology and Interdepen- Categories Opportu- Objectives Techniques dencies nities •Incident •Internal •Ongoing •Triggering •Common •Negative •Positive and/ •External •Periodic events groupings impact: risks or negative •Past and •Interrelate •Positive impacts future impact: •Supporting opportunity; tools offsets to risks
  • 15. RISK ASSESSMENT Inherent and Likelihood and Qualitative and Correlation Residual Risk Impact Quantitative Methodologies and Techniques •Before •Expected, worst- •Qualitative •Sequence of events management case, distribution •Quantitative •Categories actions •Time horizons •Inherent and •Stress testing •After management •Unit of measure residual basis •Scenarios actions •Observable data •Expected and unexpected
  • 16. RISK RESPONSE Identify Risk Evaluate Select Portfolio View Responses Possible Risk Response Responses •Avoid •Impact •Management •Entity level •Reduce •Likelihood decision •Business unit •Share •Cost versus level •Accept benefit •Inherent and •Innovative residual basis responses
  • 17. CONTROL ACTIVITIES Integration Types of General Application Entity- with Risk Control Controls Controls Specific Response Activities •Build directly •Policies •Information •Completeness •Entity specific into •Procedures technology (IT) •Accuracy strategies and management •Preventative management •Authorization objectives processes •Detective •IT infra- •Validity •Operating •Interrelate •Manual structure environment •Automatic •Security •Complexity of management the entity •Software development & maintenance
  • 18. INFORMATION & COMMUNICATION Information Strategic and Integrated Communication Systems •Internal •Strategic •Internal •External •Operational •External •Manual •Past and current •Entity-wide •Computerized •Level of detail •Expectations and •Formal •Timeliness responsibilities •Informal •Quality •Framing •Information systems •Means of transmission architecture
  • 19. MONITORING Ongoing Separate Reporting Evaluations Deficiencies •Real-time •Scope •Ongoing •Built-in •Frequency •External parties •Day-to-day operations •Self-assessments/ •Protocols internal auditors •Alternative channels •Extent of documentation
  • 20. For more information: Check out COSO’s exposure draft Enterprise Risk Management Framework At www.erm.coso.org Download it in Adobe PDF format (152 pages)