Anagrams Flashcards
COSO Objectives (ORC)
O-operating objectives (effectiveness and efficiency)
R-reporting objectives (reliability, timeliness, transparency)
C-compliance objectives (adhering to laws and regulations)
COSO Components
- Control Environment
- Risk Assessment
- Control Activities
- Information and Communication
- Monitoring
Control Environment (EBOCA)
Ethics
Board independence and oversight
Org. structure
Commitment to competence
Accountability
Risk Assesment (SAFR)
Specify objectives
Assess and identify changes
Fraud potential
Risk (analyzed)
Information and Communication (OIE)
Obtain and use information
Internally communicate information
External parties communication
Monitoring (So D)
Separate/ongoing evaluations
Deficiencies communicated
Existing Control Activities (CA T P)
Control Activities
Technology controls
Policies and procedures
5 Components of ERM (GO PRO)
G-governance and culture
O-objective setting/strategy
P-performance
R-review and revision
O-ongoing information, communication, and reporting
Governance & Culture (“DOVES”)
D-desired culture
O-oversight from board
V-values commitment
E-employees (capable)
S-structure established
Objective setting/strategy (SOAR)
S-strategies (alternative)
O-objectives (business)
A-analyzes business context
R-defines risk appetite
Performance (VAPIR)
V-view (portfolio)
A-assesses severity of risk
P-prioritizes risk
I-identifies risks (events)
R-responses to risk implemented
Review and revision (SIR)
S-substantial change
I-improvement in ERM
R-reviews risk and performance
Ongoing information, communication, reporting (TIP)
T-technology and information leveraged
I-information risk communicated
P-performance and risk culture reports