Risk management should help us make better decisions, not create more paperwork. Yet Principle 21 of COSO’s draft framework, while containing some good ideas, pushes companies toward the same old mistakes that have plagued risk management for years. Let me be clear: linking risk to strategy is smart. Looking at both threats and opportunities makes… Continue reading Critique of draft COSO Corporate Governance Framework: Principle 21
Category: Internal audit
5 reasons why internal audit may be the best place for the risk manager to sit
A while back I recorded a short video on the topic of risk management organizational structure in a non-financial company. In the video I discussed various options for risk manager’s place in the overall organizational structure. Since there is really no single right answer, the few common options include: reporting directly to the CEO, reporting… Continue reading 5 reasons why internal audit may be the best place for the risk manager to sit
Can risk management even be effective?
Lately, everyone, from the government agencies to regulators to corporate board members, seem to be talking about the need for better, more effective risk management. The challenging part is that, despite the guidance provided in ISO 31000:2009, the concept of risk management effectiveness still remains vague. This article attempts to summarize the basic components of… Continue reading Can risk management even be effective?
