• 内部控制 内控体系框架测试与内控缺陷流程梳理内控自评价内部审计
  • 行业实践 重点行业案例研究专项风险管理企业实践财务管理
  • 风险管理 理论前沿风险评估风险预警策略与方案
  • 关于我们 本网简介 本网专家视点 资料下载中心
  • 电话:010-68827610
    专家QQ:421183643在线咨询  查看更多>>
    • 姓名:
    • 电话:
    • 内容:
    理论前沿[COSO shows how to put risk assessment into practice]  >  理论前沿  >  首页
    COSO shows how to put risk assessment into practice
    COSO   日期:2014-09-05

        The Committee of Sponsoring Organizations of the Treadway Commission (COSO) on Friday released a thought paper, Risk Assessment in Practice, designed to help organizations find the optimal risk-taking zone, which the paper refers to as the “sweet spot.”
        “Risk assessment is all about measuring and prioritizing risks so that risk levels are managed within defined tolerance thresholds without being over controlled or forgoing desirable opportunities,” Deloitte & Touche LLP partner and paper co-author Patchin Curtis said in a news release.

        The thought paper describes a risk assessment process that should be practical, sustainable and understandable. The enterprise risk management process (ERM) must be structured, disciplined, and correctly scaled to the organization’s size, complexity and geographic reach, according to the paper.

        Identifying risks requires casting a wide net at first to understand the possibilities that need to be included in the organization’s risk profile, according to the paper. Prioritization then takes place to focus senior management and board attention on key risks.

        The risk assessment process outlined in the paper includes:

    developing assessment criteria
    assigning values to each risk and opportunity
    considering risk interactions because risks, when combined, can cause compounded damage
    prioritizing risks
    responding to risks

        The authors advocate developing “assessment scales” to measure the impact, likelihood, organizational vulnerability and speed of onset of risks on a scale from 1 (low) to 5 (high). Any two of those factors can be plotted against each other in graphical representations known as “risk maps” or “heat maps” to inform decisions, according to the paper.

        Although many organizations begin this ERM process by using simple spreadsheets, the paper says, software and systems that quickly will pay for themselves in saved labor costs are available.

        The paper advises that the information learned from the risk management process must feed into the strategic planning process to facilitate the proper actions.

        “You’ll know you’re doing risk assessment right,” the paper concludes, “when leaders at every level use the information to make decisions regarding value.”

    
    网站首页|网站公告|联系我们|版权保护
    风险导向内部控制网 中国-北京 版权所有 电话: 010-68827610 传真: 010-68827610
    京ICP备00000000号