COSO_ERM企业风险管理框架_第1页
COSO_ERM企业风险管理框架_第2页
COSO_ERM企业风险管理框架_第3页
COSO_ERM企业风险管理框架_第4页
COSO_ERM企业风险管理框架_第5页
已阅读5页,还剩23页未读 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

1、ApplyingCOSOsEnterpriseRiskEnterpriseRiskManagementManagementIntegratedIntegratedFrameworkFrameworkSeptember29,2004TheInstituteofInternalAuditorsTheInstituteofInternalAuditorsTodaysorganizationsareconcernedabTodaysorganizationsareconcernedabout:out: RiskManagement Governance Control Assurance(andCon

2、sulting)ERMDefined:ERMDefined:aprocess,effectedbyanentitysboardofdirectors,managementandotherpersonnel,appliedinstrategysettingandacrosstheenterprise,designedtoidentifypotentialeventsthatmayaffecttheentity,andmanageriskstobewithinitsriskappetite,toprovidereasonableassuranceregardingtheachievementofe

3、ntityobjectives.z,Source:COSOEnterpriseRiskManacjement-IntegratedFramework.2004.COSO.苗WhyERMIsImportantWhyERMIsImportantUnderlyingprinciples: Everyentity,whetherfor-profitornot,existstorealizevalueforitsstakeholders. Valueiscreated,preserved,orerodedbymanagementdecisionsinallactivities,fromsettingst

4、rategytooperatingtheenterpriseday-to-day.觎WhyERMIsImportantWhyERMIsImportantERMsupportsvaluecreationbyenablingmanagementto: Dealeffectivelywithpotentialfutureeventsthatcreateuncertainty. Respondinamannerthatreducesthelikelihoodofdownsideoutcomesandincreasestheupside.觑EnterpriseRiskManagementEnterpri

5、seRiskManagementIntegrateIntegrated dFrameworkFrameworkThisCOSOERMframeworkdefinesessentialcomponents,suggestsacommonlanguage,andprovidescleardirectionandguidanceforenterpriseriskmanagement.TheERMFrameworkTheERMFrameworkEntityobjectivescanbeviewedinthecontextoffourcategories: Strategic Operations Re

6、porting ComplianceTheERMFrameworkTheERMFrameworkERMconsidersactivitiesatalllevelsoftheorganization: Enterprise-level Divisionorsubsidiary BusinessunitprocessesTheERMFrameworkTheERMFrameworkEnterpriseriskmanagementrequiresanentitytotakeaportfolioviewofrisk,44TheERMFrameworkTheERMFramework Managementc

7、onsidershowindividualrisksinterrelate. Managementdevelopsaportfolioviewfromtwoperspectives:-Businessunitlevel-Entitylevel觎TheERMFrameworkTheERMFrameworkTheeightcomponentsoftheframeworkareinterrelated.InternalEnvironmentInternalEnvironment Establishesaphilosophyregardingriskmanagement.Itrecognizestha

8、tunexpectedaswellasexpectedeventsmayoccur, Establishestheentitysriskculture. Considersallotheraspectsofhowtheorganizationsactionsmayaffectitsriskculture.觎ObjectiveSettingObjectiveSetting Isappliedwhenmanagementconsidersrisksstrategyinthesettingofobjectives. Formstheriskappetiteoftheentityahigh-level

9、viewofhowmuchriskmanagementandtheboardarewillingtoaccept. Risktolerance,theacceptablelevelofvariationaroundobjectives,isalignedwithriskappetite.EventIdentificationEventIdentification Differentiatesrisksandopportunities. Eventsthatmayhaveanegativeimpactrepresentrisks. Eventsthatmayhaveapositiveimpact

10、representnaturaloffsets(opportunities),whichmanagementchannelsbacktostrategysetting.觎EventIdentificationEventIdentification Involvesidentifyingthoseincidents,occurringinternallyorexternally,thatcouldaffectstrategyandachievementofobjectives. Addresseshowinternalandexternalfactorscombineandinteracttoi

11、nfluencetheriskprofile.44RiskAssessmentRiskAssessment Allowsanentitytounderstandtheextenttowhichpotentialeventsmightimpactobjectives. Assessesrisksfromtwoperspectives:-Likelihood-Impact Isusedtoassessrisksandisnormallyalsousedtomeasuretherelatedobjectives.44RiskAssessmentRiskAssessment Employsacombi

12、nationofbothqualitativeandquantitativeriskassessmentmethodologies. Relatestimehorizonstoobjectivehorizons. Assessesriskonbothaninherentandaresidualbasis.RiskResponseRiskResponse Identifiesandevaluatespossibleresponsestorisk. Evaluatesoptionsinrelationtoentitysriskappetite,costvs.benefitofpotentialri

13、skresponses,anddegreetowhicharesponsewillreduceimpactand/orlikelihood. Selectsandexecutesresponsebasedonevaluationoftheportfolioofrisksandresponses.备&ControlActivitiesControlActivities Policiesandproceduresthathelpensurethattheriskresponses,aswellasotherentitydirectives,arecarriedout. Occurthrou

14、ghouttheorganization,atalllevelsandinallfunctions. Includeapplicationandgeneralinformationtechnologycontrols.觊Information&CommunicationInformation&Communication Managementidentifies,captures,andcommunicatespertinentinformationinaformandtimeframethatenablespeopletocarryouttheirresponsibilitie

15、s. Communicationoccursinabroadersense,flowingdown,across,anduptheorganization.觊MonitoringMonitoringEffectivenessoftheotherERMcomponentsismonitoredthrough: Ongoingmonitoringactivities. Separateevaluations. Acombinationofthetwo.InternalControlInternalControlAstrongsystemofinternalcontrolisessentialtoe

16、ffectiveenterpriseriskmanagement.RelationshiptoRelationshiptoInternalControlInternalControlIntIntegratedFrameworkegratedFrameworkExpandsandelaboratesonelementsofinternalcontrolassetoutinCOSOscontrolframework.z,Includesobjectivesettingasaseparatecomponent.Objectivesareaprerequisite7forinternalcontrol

17、.ExpandsthecontrolframeworksFinancialReportingandRiskAssessment/觑ERMRoles&ResponsibilitiesERMRoles&Responsibilities Management Theboardofdirectors Riskofficers InternalauditorsInternalAuditorsInternalAuditors PlayanimportantroleinmonitoringERM,butdoNOThaveprimaryresponsibilityforitsimplement

18、ationormaintenance. Assistmanagementandtheboardorauditcommitteeintheprocessby:-Monitoring-Evaluating-Examining-Reporting-Recommendingimprovements觑InternalAuditorsInternalAuditorsVisittheguidancesectionofTheIIAsWebsiteforTheIIAspositionpaper,RoleofInternalAuditingsinEnterpriseRiskManagement.,zStandar

19、dsStandards 2010.Al2010.Al- -Theinternalauditactivitysplanofengagementsshouldbebasedonariskassessment,undertakenatleastannually. 2120.Al2120.Al- -Basedontheresultsoftheriskassessment,theinternalauditactivityshouldevaluatetheadequacyandeffectivenessofcontrolsencompassingtheorganizationsgovernance,ope

20、rations,andinformationsystems. 2210.Al2210.Al- -Whenplanningtheengagement,theinternalauditorshouldidentifyandassessrisksrelevanttotheactivityunderreview.Theengagementobjectivesshouldreflecttheresultsoftheriskassessment.KeyImplementationFactorsKeyImplementationFactors1.Organizationaldesignofbusiness2

21、. EstablishinganERMorganization3. Performingriskassessments4. Determiningoverallriskappetite5. Identifyingriskresponses6. Communicationofriskresults7. Monitoring8. Oversight&periodicreviewbymanagement3434TKTK ProfessionalProfessionalPracticesPracticesOrganizationalDesignOrganizationalDesign Stra

22、tegiesofthebusiness Keybusinessobjectives Relatedobjectivesthatcascadedowntheorganizationfromkeybusinessobjectives Assignmentofresponsibilitiestoorganizationalelementsandleaders(linkage)44Example:LinkageExample:Linkage MissionMission- -Toprovidehigh-qualityaccessibleandaffordablecommunitybasedhealth

23、care StrategicObjectiveStrategicObjective- -Tobethefirstorsecondlargest,full-servicehealthcareproviderinmid-sizemetropolitanmarketsRelatedObjectiveRelatedObjective- -Toinitiatedialoguewithleadershipof10topunder-performinghospitalsandnegotiateagreementswithtwothisyear Determineariskphilosophy Surveyr

24、iskculture Considerorganizationalintegrityandethicalvalues Deciderolesandresponsibilities融Example:ERMOrganizationExample:ERMOrganizationAssessRiskAssessRiskRiskassessmentistheidentificationandanalysisofriskstotheachievementofbusinessobjectives.Itformsabasisfordetermininghowrisksshouldbemanaged.“觎Exa

25、mple:RiskModelExample:RiskModelEnvironmentalRisksEnvironmentalRisks CapitalAvailability Regulatory,Political,andLegal FinancialMarketsandShareholderRelationsProcessRisksProcessRisks OperationsRisk EmpowermentRisk InformationProcessing/TechnologyRisk IntegrityRisk FinancialRiskInformationforDecisionM

26、akingInformationforDecisionMaking OperationalRisk FinancialRisk StrategicRiskRiskAnalysisRiskAnalysis Riskappetiteistheamountofriskonabroadlevelanentityiswillingtoacceptinpursuitofvalue. Usequantitativeorqualitativeterms(e.g.earningsatriskvs.reputationrisk),andconsiderrisktolerance(rangeofacceptable

27、variation).DETERMINERISKAPPETITEDETERMINERISKAPPETITEKeyquestions: Whatriskswilltheorganizationnotaccept?(e.g.environmentalorqualitycompromises) Whatriskswilltheorganizationtakeonnewinitiatives?(e.g.newproductUnes) Whatriskswilltheorganizationacceptforcompetingobjectives?(e.g.grossprofitvs.marketsha

28、re?)44IDENTIFYRISKRESPONSESIDENTIFYRISKRESPONSES Quantificationofriskexposure Optionsavailable:- Accept=monitor- Avoid=eliminate(getoutofsituation)- Reduce=institutecontrols- Share=partnerwithsomeone(e.g.insurance)Residualrisk(unmitigatedrisk-e.g.shrinkage)觎HighMediumRiskHiqhRiskLOW Lossofphones Los

29、sofcomputersLowRisk Fraud Losttransactions Employeemorale Creditrisk Customerhasalongwait Customercantgetthrough.Customercan/tgetanswersMediumRisk.Entryerrors Equipmentobsolescence RepeatcallsforsameproblemPROBABILITYPROBABILITYHighImpactvs.ProbabilityImpactvs.ProbabilityExample:CallCenterRiskAssess

30、mentExample:CallCenterRiskAssessmentHighMediumRiskHiqhRiskShareShareMitigate&ControlMitigate&ControlAcceptAcceptLowRiskControlControlMediumRiskLowPROBABILITYPROBABILITYHighExample:AccountsPayableProcessExample:AccountsPayableProcessControlActivityAccrualofopenliabilitiesInvoicesaccruedafterc

31、losingIssue:InvoicesgotofieldandAPisnotawareofliability.CommunicateResultsCommunicateResults Dashboardofrisksandrelatedresponses(visualstatusofwherekeyrisksstandrelativetorisktolerances) Flowchartsofprocesseswithkeycontrolsnoted Narrativesofbusinessobjectiveslinkedtooperationalrisksandresponses List

32、ofkeyriskstobemonitoredorused Managementunderstandingofkeybusinessriskresponsibilityandcommunicationofassignments CollectanddisplayinformationControlObjectiveCompletenessRiskMaterialtransactionnotrecorded PerformanalysisRisksarebeingproperlyaddressedControlsareworkingtomitigaterisks1414ManagementOversight&PeriodicReviewManagementOversight&PeriodicReview Accountabilityforrisks Ownership Updates-Changesinbusinessobjectives- Changesinsystems- Changesinprocesses觎Internalauditorscanaddvalueby:Internalauditorscanaddvalueby: Reviewingcriticalcontrolsystemsandriskmanagementprocesses. Perf

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

评论

0/150

提交评论