COSO Flashcards
What does COSO stand for?
Committee of Sponsoring Organisations
What does COSO do?
Provides frameworks against which risk management and internal control systems can be assessed and improved
What are the 8 components of the COSO framework?
Control Environment Objective Setting Event Identification Risk Assessment Risk Response Control Activities Info & Communication Monitoring
What does Control Environment do?
Establishes the tone of the org.
What does Objective setting do?
Management needs to support the organizations mission and is consistent with it’s risk tolerance.
Describe Event Identification
Organization must identify internal and external events that affect the the achievement of objectives
What is Risk Assessment ?
The likelihood and impact of risk are assessed as well as how to manage them.
What is Risk Response?
Mgmt should respond to risk realistically, taking into account cost of the impact.
Describe the Control Activities?
The internal controls themselves, and polices & procedures.
Describe the Information and communication component?
Data and info needs to be delivered timely to managemwent to ensure they can carry out duties.
Describe monitoring?
Weaknesses should be reporting, assessed and their root causes corrected.
Possible responses to risk?
Avoid or Reduce, Share or Accept