版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
Applying
COSO’sEnterprise
RiskManagement
—IntegratedFramework•September
29,
2004第一页
,共五十页。Today
’s
organizations
areconcerned
about
:•Risk
Management•Governance•
Control•
Assurance(and
Consulting)第二页,共五十页。ERMDefined:“…aprocess,efectedbyanentity"sboardofdirectors,managementandotherpersonnel,appliedinstrategysettingandacrosstheenterprise,designedtoidentifypotentialeventsthatmayafecttheentity,andmanageriskstobewithinitsriskappetite,toprovidereasonableassuranceregardingtheachievementofentityobjectives.”Source:COSOEnterpriseRiskManagement–IntegratedFramework.2004.COSO.第三页,共五十页。WhyERMIsImportantUnderlyingprinciples:•Everyentity,whetherfor-profitornot,existstorealizevalueforitsstakeholders.•Valueiscreated,preserved,orerodedbymanagementdecisionsinallactivities,fromsettingstrategytooperatingtheenterpriseday-to-day.第四页,共五十页。Why
ERM
Is
ImportantERM
supports
value
creation
by
enabling
management
to:•
Deal
effectivelywithpotential
future
events
that
createuncertainty.•
Respond
in
a
manner
that
reduces
the
likelihood
of
downside
outcomes
andincreases
theupside.第五页,共五十页。Enterprise
Risk
Management—
Integrated
FrameworkThisCOSOERM
framework
defines
essentialcomponents,
suggests
a
common
language,and
provides
clear
direction
and
guidance
forenterpriseriskmanagement.第六页,共五十页。The
ERM
FrameworkEntity
objectives
can
be
viewed
in
thecontext
of
four
categories:•Strategic•
Operations•Reporting•
Compliance第七页,共五十页。The
ERM
FrameworkERMconsiders
activitiesatalllevels
oftheorganization:•
Enterprise-level•
Division
orsubsidiary•Business
unit
processes第八页,共五十页。The
ERM
FrameworkEnterprise
risk
management
requires
an
entity
to
take
a
portfolio
view
ofrisk.第九页,共五十页。The
ERM
Framework•Management
consider
s
howindividualrisks
interrelate.•Management
develops
a
portfolio
view
from
two
perspectives
:-
Business
unit
level-
Entity
level第十页,共五十页。The
ERM
FrameworkThe
eight
componentsof
the
frameworkare
interrelated
…第十一页,共五十页。InternalEnvironment•Establishesaphilosophyregardingriskmanagement.Itrecognizesthatunexpectedaswellasexpectedeventsmayoccur.•Establishestheentity’sriskculture.•Considersallotheraspectsofhowtheorganization’sactionsmayaffectitsriskculture.第十二页,共五十页。Objective
Setting•Is
applied
when
management
considers
risks
strategy
in
the
setting
of
objectives.•Forms
the
risk
appetite
of
the
entity
—
a
high-level
view
of
how
much
riskmanagement
and
the
board
are
willing
toaccept.•
Risk
tolerance,
the
acceptable
level
ofvariation
around
objectives,
is
alignedwithrisk
appetite.第十三页,共五十页。•Differentiates
risks
and
opportunities.•
Events
that
may
have
a
negative
impact
representrisks.•Events
that
may
have
a
positive
impactrepresentnatural
offsets(opportunities),whichmanagement
channels
back
to
strategysetting.Event
Identification第十四页,共五十页。Event
Identification•Involves
identifying
those
incidents,occurring
internally
or
externally,
that
could
affect
strategy
and
achievement
ofobjectives.•
Addresses
how
internal
and
external
factorscombine
and
interact
to
influence
the
risk
profile.第十五页,共五十页。Risk
Assessment•
Allows
an
entity
to
understand
the
extent
to
which
potential
events
might
impactobjectives.•
Assesses
risks
from
two
perspectives:-
Likelihood-
Impact•
Is
used
to
assess
risks
and
is
normallyalso
used
to
measure
the
relatedobjectives.第十六页,共五十页。Risk
Assessment•
Employs
a
combination
of
both
qualitative
and
quantitative
risk
assessmentmethodologies.•
Relates
time
horizons
to
objective
horizons.•
Assesses
risk
on
both
an
inherent
and
a
residualbasis.第十七页,共五十页。RiskResponse•Identifiesandevaluatespossibleresponsestorisk.•Evaluatesoptionsinrelationtoentity’sriskappetite,costvs.benefitofpotentialriskresponses,anddegreetowhicharesponsewillreduceimpactand/orlikelihood.•Selectsandexecutesresponsebasedonevaluationoftheportfolioofrisksandresponses.第十八页,共五十页。•Policiesandproceduresthathelpensurethattheriskresponses,aswellasotherentitydirectives,arecarriedout.•Occurthroughouttheorganization,atalllevelsandinallfunctions.•Includeapplicationandgeneralinformationtechnologycontrols.第十九页,共五十页。ControlActivitiesInformation
&
Communication•
Management
identifies,
captures,andcommunicates
pertinent
information
in
a
formand
timeframe
that
enables
people
to
carry
out
theirresponsibilities.•Communication
occurs
in
a
broader
sense,flowing
down,
across,
and
upthe
organization.第二十页,共五十页。MonitoringEffectiveness
of
the
other
ERM
components
is
monitored
through
:•
Ongoing
monitoring
activities.•
Separate
evaluations.•
A
combination
of
the
two.第二十一页,共五十页。Internal
ControlA
strong
system
of
internalcontrol
is
essential
to
effective
enterpriserisk
management.第二十二页,共五十页。RelationshiptoInternalControlExpandsandelaboratesonelementsofinternalcontrolassetoutinCOSO’s“controlframework.”•Includesobjectivesettingasaseparatecomponent.Objectivesarea“prerequisite”forinternalcontrol.•Expandsthecontrolframework’s“FinancialReporting”and“RiskAssessment.”—•
IntegratedFramework第二十三页,共五十页。ERM
Roles
&
Responsibilities•Management•
The
board
of
directors•
Risk
officers•Internal
auditors第二十四页,共五十页。InternalAuditors•PlayanimportantroleinmonitoringERM,butdoNOThaveprimaryresponsibilityforitsimplementationormaintenance.•Assistmanagementandtheboardorauditcommitteeintheprocessby:-Monitoring-Evaluating-Examining-Reporting-Recommendingimprovements第二十五页,共五十页。InternalAuditorsVisittheguidancesectionofTheIIA’sWebsiteforTheIIA’spositionpaper,“RoleofInternalAuditing’sinEnterpriseRiskManagement.”第二十六页,共五十页。•2010.A1–Theinternalauditactivity’splanofengagementsshouldbebasedonariskassessment,undertakenatleastannually.•2120.A1–Basedontheresultsoftheriskassessment,theinternalauditactivityshouldevaluatetheadequacyandeffectivenessofcontrolsencompassingtheorganization’sgovernance,operations,andinformationsystems.•2210.A1–Whenplanningtheengagement,theinternalauditorshouldidentifyandassessrisksrelevanttotheactivityunderreview.Theengagementobjectivesshouldreflecttheresultsoftheriskassessment.Standards第二十七页,共五十页。Key
Implementation
Factors1.Organizational
design
ofbusiness2.Establishing
an
ERM
organization3.Performing
risk
assessments4.Determining
overallrisk
appetite5.Identifyingrisk
responses6.Communication
of
risk
results7.Monitoring8.Oversight
&
periodic
reviewby
management第二十八页,共五十页。•Strategiesofthebusiness•Keybusinessobjectives•Relatedobjectivesthatcascadedowntheorganizationfromkeybusinessobjectives•Assignmentofresponsibilitiestoorganizationalelementsandleaders(linkage)第二十九页,共五十页。Organizational
DesignExample:Linkage•Mission–Toprovidehigh-qualityaccessibleandaffordablecommunity-basedhealthcare•StrategicObjective–Tobethefirstorsecondlargest,full-servicehealthcareproviderinmid-sizemetropolitanmarkets•RelatedObjective–Toinitiatedialoguewithleadershipof10topunder-performinghospitalsandnegotiateagreementswithtwothisyear第三十页,共五十页。EstablishERM•Determineariskphilosophy•Surveyriskculture•Considerorganizationalintegrityandethicalvalues•Deciderolesandresponsibilities第三十一页,共五十页。Example:ERM
OrganizationFESCommodityRisk
Mg.DirectornsuranceRiskManagerERMDirectorCorporateC
re
itRiskManagerERMManagerERMManager Chief
Risk
Officer
StaffStaffStaffVicePresidentand第三十二页,共五十页。dIAssessRiskRiskassessmentistheidentificationandanalysisofriskstotheachievementofbusinessobjectives.Itformsabasisfordetermininghowrisksshouldbemanaged.第三十三页,共五十页。Example:RiskModelEnvironmental
Risks•
CapitalAvailability•Regulatory,Political,
and
Legal•Financial
Markets
and
Shareholder
RelationsProcess
Risks•Operations
Risk•Empowerment
Risk•Information
Processing
/
Technology
Risk•Integrity
Risk•Financial
RiskInformation
for
Decision
Making•
OperationalRisk•
FinancialRisk•
Strategic
Risk第三十四页,共五十页。RRiisskkAAnnaallyyssiissRiskManagementRiskMonitoringRiskAssessmentControl
ItShareor
TransferItDiversifyor
Avoid
ItProcessLevelActivityLevelEntityLevelIdentificationMeasurementPrioritizationSource:BusinessRiskAssessment.1998–TheInstituteofInternalAuditors第三十五页,共五十页。DETERMINERISKAPPETITE•Riskappetiteistheamountofrisk—onabroadlevel—anentityiswillingtoacceptinpursuitofvalue.•Usequantitativeorqualitativeterms(e.g.earningsatriskvs.reputationrisk),andconsiderrisktolerance(rangeofacceptablevariation).第三十六页,共五十页。DETERMINERISKAPPETITEKeyquestions:•Whatriskswilltheorganizationnotaccept?(e.g.environmentalorqualitycompromises)•Whatriskswilltheorganizationtakeonnewinitiatives?(e.g.newproductlines)•Whatriskswilltheorganizationacceptforcompetingobjectives?(e.g.grossprofitvs.marketshare?)第三十七页,共五十页。•Quantificationofriskexposure•Optionsavailable:-Accept=monitor-Avoid=eliminate(getoutofsituation)-Reduce=institutecontrols-Share=partnerwithsomeone(e.g.insurance)•Residualrisk(unmitigatedrisk–e.g.shrinkage)IDENTIFY
RISK
RESPONSES第三十八页,共五十页。Share
Mitigate
&ControlLow
Risk
MediumRiskHighIMPACTLowImpactvs.ProbabilityPROBABILITY
HighMedium
Risk
High
RiskControlAccept第三十九页,共五十页。Medium
RiskHigh
Risk•Loss
of
phones•Loss
of
computers•
Credit
risk•
Customer
has
a
long
wait•Customer
can
’t
get
through•
Customer
can
’t
get
answersMedium
Risk•
Fraud•
Lost
transactions•
Employee
morale•
Entry
errors•Equipment
obsolescence•Repeat
calls
for
same
problemExample:CallCenterRiskAssessmentHighIMPACTLowPROBABILITY
HighLow
Risk第四十页,共五十页。RiskMaterialtransactionnot
recordedInvoices
accruedControlActivityAccrual
ofopen
liabilitiesProcessControlObjectiveCompletenessExample:
AccountsPayableIssue:Invoicesgo
to
field
and
APis
not
aware
of
liability.after
closing第四十一页,共五十页。Communicate
Results•Dashboard
of
risks
and
related
responses(visual
status
ofwhere
key
risks
stand
relative
to
risk
tolerances)•Flowcharts
of
processes
with
key
controls
noted•Narratives
of
business
objectives
linked
to
operational
risks
and
responses•List
of
key
risks
to
be
monitored
or
used•Management
understanding
of
key
business
riskresponsibility
and
communication
of
assignments第四十二页,共五十页。Monitor•
Collect
and
display
information•
Perform
analysis-
Risks
are
being
properly
addressed-
Controls
are
working
to
mitigate
risks第四十三页,共五十页。Management
Oversight
&Periodic
Review•
Accountability
forrisks•Ownership•Updates-
Changes
in
business
objectives-
Changes
in
systems-
Changes
in
processes第四十四页,共五十页。Internal
auditors
can
addvalue
by
:Reviewing
critic
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 2025-2026学年广东省深圳市龙岗实验学校七年级(上)月考数学试卷(1月份)(含答案)
- 实木拼板机操作工岗位技能考试试卷及答案
- 桑蚕养殖技术员岗位技术考试试卷及答案
- 焊接专机装配工冲突解决测试考核试卷含答案
- 人力采伐工岗前技术管理考核试卷含答案
- 宝剑工岗前班组安全考核试卷含答案
- 温差电器件制造工安全检查考核试卷含答案
- 灯具零部件制造工创新应用强化考核试卷含答案
- 淀粉糖制造工操作能力竞赛考核试卷含答案
- 2026年生物制造事故预防与处理策略试题及答案
- 2026年护理管理基础考试练习试题(附答案)
- 2026中国历史文化街区土地开发中的文保平衡策略
- 精神病患者的危机干预与康复
- Python图像识别之OpenCV入门教学
- T∕CCEAS008-2026 建设工程造价咨询成果文件质量标准
- (2026年)糖尿病酮症酸中毒护理课件
- 2026年北京市地铁运营有限公司校园招聘笔试备考试题及答案解析
- 2026年新团员入团考试试题及答案
- 高级教师职称面试讲课答辩题目及答案(分五类共60题)
- 充电桩安装及配套工程竣工验收报告
- 2026润滑油产品认证体系与国际市场准入研究报告
评论
0/150
提交评论