Internal Controls and Risk Management -Five Key defenses against risk

(Extract from Online News)

"Achieving the proper balance between entrepreneurial risk and enterprise value protection is the most difficult task of risk management and internal control, according to a new report from the Committee of Sponsoring Organizations of the Treadway Commission (COSO)"

The report describes how COSO’s enterprise risk management (ERM) and internal control frameworks can be used to improve organisational performance and governance

"The five lines of defence identified by DeLoach, a managing director for global consulting firm Protiviti, are:

1. Tone of the organisation. Tone at the top is not enough, DeLoach said. He said the tone at the middle and bottom of organisations – as established by middle managers instructing their employees – must be aligned with the tone at the top. “A proper tone of the organisation sets a strong risk culture, which is foundational to the other lines of defence,” DeLoach said.

2. Primary risk owners. These include business owners and process leaders whose activities create risk. DeLoach said they need to take ownership in managing and mitigating risk.

3. Independent risk-management and compliance management functions. The titles of these functions vary across organisations, but DeLoach said their duties are to create a framework for identifying, measuring, evaluating and monitoring risk, and to ensure that the framework is applied across the organisation in a robust manner.

4. Assurance functions. This role is typically filled by internal audit, DeLoach said.

5. Escalation process. This involves reporting of status, progress and problems all the way up to executive management and the board of directors. “They are the last line of defence,” DeLoach said."

http://www.coso.org/documents/2014-2-10-COSO%20Thought%20Paper.pdf

Article Source : http://www.cgma.org/Magazine/News/Pages/20149569.aspx

Risk Category: 

Other Services of Interest

  • Sox Training

    Our sox training covers the following points. 1. What is SOX? 2. The Act and its Sponsorors. 3. The background for bringing in this act. 4. Major Sections in the Act 5. Section 404 overview 6...
  • EUC Risks : Manage Spreadsheet risks - Riskpro India

    EVENT OVERVIEW Uncontrolled and untested spreadsheet models pose significant business risks. These risks include: lost revenue and profits; mispricing and poor decision making due to prevalent but...
  • 1 Day AML Training by Riskpro India - Mumbai

    Training event in Bangalore on Anti Money Laundering (AML) and KYC “Are we doing enough to protect integrity of Indian financial sector?” Banks face growing costs to comply with AML requirements...
  • Risk Management Software - Riskpro India's solution for Automating Risk Management

    Riskpro India finally offers small and mid enterprises a risk management tool that helps them to manage risks effectively. To request a 30 days trial, please contact info@riskpro.in Why is Risk...
  • Riskpro's Service Verticals

    In today's world, risks are not few. An enterprise faces various risks and challenges and is subject to uncertainties and negative impacts from these risks. Managing risks is your key to untapped...
  • Privacy and Data Protection Services - General Data Protection Regulation (GDPR)

    The EU General Data Protection Regulation (GDPR) is the most important change in data privacy regulation in 20 years. Riskpro India now offers Indian companies Data Protection assessments, GDPR...
  • Reduce your GDPR implementation Costs - Hire GDPR Experts in India

    Reduce cost for GDPR Compliance - Remote Consulting from India GDPR readiness assessment and implementation can be costly. And time is short. Instead of paying premium fees to local GDPR consultants...
  • Riskpro India on top of Emerging Risks that bother you

    Riskpro India is well positioned to offer advisory services for emerging risks such as Data Protection (GDPR), information security, assurance services such as Third party risk management, internal...
  • Assurance Services

    In Riskpro we believe that Internal audit function has to align its activities with business activities of any organisation to achieve its objectives. IA can be of significant value if it maintains...
  • Go to top