The COSO Framework for Internal Control
February 12, 2025
Morale can be defined as the total satisfaction derived by an individual from his job, his work-group, his superior, the organization he works for and the environment. It generally relates to the feeling of individual’s comfort, happiness and satisfaction. According to Davis, “Morale is a mental condition of groups and individuals which determines their attitude.” […]
The decades starting with the 1990s witnessed the proliferation of a new kind of sector among the various agencies and governmental departments engaged in public service. This sector was the Non-Profit or the NGO (Non Governmental Organizations) that mushroomed all over the world to fill the gap between the governmental agencies and the public. The […]
A set-up where individuals from diverse backgrounds, different educational qualifications and varied interests come together to work towards a common goal is called an organization. The employees must work in close coordination with each other and try their level best to achieve the organization’s goals. It is essential to manage the employees well for them […]
Every leader has a personal leadership brand which might be carefully cultivated or intuitively perceived by leaders themselves and their followers. A personal leadership brand is an exclusive and a specific approach of a leader to address challenges and manage his/her transactions with their subordinates or followers. The best part of having a leadership brand […]
What are Telephone Etiquettes ? Telephone is an important device with the help of which people separated by distance can easily interact and exchange their ideas. Got a brilliant idea and want to convey it to your friend staying out of the country, use the telephone. Telephone is one of the easiest and cheapest modes […]
Literally speaking, risk management is the process of minimizing or mitigating the risk. It starts with the identification and evaluation of risk followed by optimal use of resources to monitor and minimize the same.
Risk generally results from uncertainty. In organizations this risk can come from uncertainty in the market place (demand, supply and Stock market), failure of projects, accidents, natural disasters etc. There are different tools to deal with the same depending upon the kind of risk.
Ideally in risk management, a risk prioritization process is followed in which those risks that pose the threat of great loss and have great probability of occurrence are dealt with first. Refer to table below:
IMPACT | ACTIONS | ||
SIGNIFICANT | Considerable Management Required | Must Manage and Monitor Risks | Extensive Management essential |
MODERATE | Risk are bearable to certain extent | Management effort worthwhile | Management effort required |
MINOR | Accept Risks | Accept but monitor Risks | Manage and Monitor Risks |
LOW | MEDIUM | HIGH | |
LIKELIHOOD |
The above chart can be used to strategize in various situations. The two factors that govern the action required are the probability of occurrence and the impact of the risk.
For example a condition where the impact is minor and the probability of occurrence is low, it is better to accept the risk without any interventions.
A condition where the likelihood is high and the impact is significant, extensive management is required. This is how a certain priority can be established in dealing with the risk.
Apart from this, typically most of the organizations follow a risk management cycle. Refer diagram below:
According to this cycle there are four steps in the process of risk management.
The first step is the assessment of risk, followed by evaluation and management of the same. The last step is measuring the impact.
Risk identification can start at the base or the surface level, in the former case the source of problems is identified. We now have two things to deal with the source and the problem.
Risk Source: The source can be either internal or external to the system. External sources are beyond control whereas internal sources can be controlled to a certain extent. For example, the amount of rainfall, weather over an airport etc!
Problem: A problem at the surface level could be the threat of accident and casualty at the plant, a fire incident etc.
When any or both of the above two are known beforehand, certain steps can be taken to deal with the same.
After the risk/s has been identified then it/they must be assessed on the potential of criticality. Here we arrive upon risk prioritization.
In generic terms ‘Likelihood of Occurrence × Impact’ = Risk.
This is followed by development of a risk management plan and implementation of the same. It comprises of the effective security controls and control mechanisms for mitigation of risk.
A more challenging risk to organizational effectiveness is the risk that is present but cannot be identified. For example a perpetual inefficiency in the production process accumulates over a certain period of time and translates into operational risk.
Your email address will not be published. Required fields are marked *