SlideShare a Scribd company logo
HAPTER 6 Control and Accounting Information Systems
INTRODUCTION Questions to be addressed in this chapter: What are the basic internal control concepts, and why are computer control and security important? What is the difference between the COBIT, COSO, and ERM control frameworks? What are the major elements in the internal environment of a company? What are the four types of control objectives that companies need to set? What events affect uncertainty, and how can they be identified? How is the Enterprise Risk Management model used to assess and respond to risk? What control activities are commonly used in companies? How do organizations communicate information and monitor control processes?
INTRODUCTION Why AIS Threats Are Increasing Control risks have increased in the last few years because: There are computers and servers everywhere, and information is available to an unprecedented number of workers. Distributed computer networks make data available to many users, and these networks are harder to control than centralized mainframe systems. Wide area networks are giving customers and suppliers access to each other’s systems and data, making confidentiality a major concern.
INTRODUCTION Historically, many organizations have not adequately protected their data due to one or more of the following reasons: Computer control problems are often underestimated and downplayed. Control implications of moving from centralized, host-based computer systems to those of a networked system or Internet-based system are not always fully understood. Companies have not realized that data is a strategic resource and that data security must be a strategic requirement. Productivity and cost pressures may motivate management to forego time-consuming control measures.
INTRODUCTION Some vocabulary terms for this chapter: A  threat  is any potential adverse occurrence or unwanted event that could injure the AIS or the organization. The  exposure  or  impact  of the threat is the potential dollar loss that would occur if the threat becomes a reality. The  likelihood  is the probability that the threat will occur.
INTRODUCTION Control and Security are Important Companies are now recognizing the problems and taking positive steps to achieve better control, including: Devoting full-time staff to security and control concerns. Educating employees about control measures. Establishing and enforcing formal information security policies. Making controls a part of the applications development process. Moving sensitive data to more secure environments.
INTRODUCTION To use IT in achieving control objectives, accountants must: Understand how to protect systems from threats. Have a good understanding of IT and its capabilities and risks. Achieving adequate security and control over the information resources of an organization should be a top management priority.
INTRODUCTION Control objectives are the same regardless of the data processing method, but a computer-based AIS requires different internal control policies and procedures because: Computer processing may reduce clerical errors but increase risks of unauthorized access or modification of data files. Segregation of duties must be achieved differently in an AIS. Computers provide opportunities for enhancement of some internal controls.
INTRODUCTION One of the primary objectives of an AIS is to control a business organization. Accountants must help by designing effective control systems and auditing or reviewing control systems already in place to ensure their effectiveness. Management expects accountants to be control consultants by: Taking a proactive approach to eliminating system threats; and Detecting, correcting, and recovering from threats when they do occur.
INTRODUCTION It is much easier to build controls into a system during the initial stage than to add them after the fact. Consequently, accountants and control experts should be members of the teams that develop or modify information systems.
OVERVIEW OF CONTROL CONCEPTS In today’s dynamic business environment, companies must react quickly to changing conditions and markets, including steps to: Hire creative and innovative employees. Give these employees power and flexibility to: Satisfy changing customer demands; Pursue new opportunities to add value to the organization; and Implement process improvements. At the same time, the company needs control systems so they are not exposed to excessive risks or behaviors that could harm their reputation for honesty and integrity.
OVERVIEW OF CONTROL CONCEPTS Internal control  is the process implemented by the board of directors, management, and those under their direction to provide reasonable assurance that the following control objectives are achieved: Assets (including data) are safeguarded. This objective includes prevention or timely detection of unauthorized acquisition, use, or disposal of material company assets.
OVERVIEW OF CONTROL CONCEPTS Internal control  is the process implemented by the board of directors, management, and those under their direction to provide reasonable assurance that the following control objectives are achieved: Assets (including data) are safeguarded. Records are maintained in sufficient detail to accurately and fairly reflect company assets.
OVERVIEW OF CONTROL CONCEPTS Internal control  is the process implemented by the board of directors, management, and those under their direction to provide reasonable assurance that the following control objectives are achieved: Assets (including data) are safeguarded. Records are maintained in sufficient detail to accurately and fairly reflect company assets.  Accurate and reliable information is provided.
OVERVIEW OF CONTROL CONCEPTS Internal control  is the process implemented by the board of directors, management, and those under their direction to provide reasonable assurance that the following control objectives are achieved: Assets (including data) are safeguarded. Records are maintained in sufficient detail to accurately and fairly reflect company assets.  Accurate and reliable information is provided. There is reasonable assurance that financial reports are prepared in accordance with GAAP.
OVERVIEW OF CONTROL CONCEPTS Internal control  is the process implemented by the board of directors, management, and those under their direction to provide reasonable assurance that the following control objectives are achieved: Assets (including data) are safeguarded. Records are maintained in sufficient detail to accurately and fairly reflect company assets.  Accurate and reliable information is provided. There is reasonable assurance that financial reports are prepared in accordance with GAAP. Operational efficiency is promoted and improved. This objective includes ensuring that company receipts and expenditures are made in accordance with management and directors’ authorizations.
OVERVIEW OF CONTROL CONCEPTS Internal control  is the process implemented by the board of directors, management, and those under their direction to provide reasonable assurance that the following control objectives are achieved: Assets (including data) are safeguarded. Records are maintained in sufficient detail to accurately and fairly reflect company assets.  Accurate and reliable information is provided. There is reasonable assurance that financial reports are prepared in accordance with GAAP. Operational efficiency is promoted and improved. Adherence to prescribed managerial policies is encouraged.
OVERVIEW OF CONTROL CONCEPTS Internal control  is the process implemented by the board of directors, management, and those under their direction to provide reasonable assurance that the following control objectives are achieved: Assets (including data) are safeguarded. Records are maintained in sufficient detail to accurately and fairly reflect company assets.  Accurate and reliable information is provided. There is reasonable assurance that financial reports are prepared in accordance with GAAP. Operational efficiency is promoted and improved. Adherence to prescribed managerial policies is encouraged. The organization complies with applicable laws and regulations .
OVERVIEW OF CONTROL CONCEPTS Internal control is a  process  because: It permeates an organization’s operating activities. It is an integral part of basic management activities. Internal control provides  reasonable , rather than absolute, assurance, because complete assurance is difficult or impossible to achieve and prohibitively expensive.
OVERVIEW OF CONTROL CONCEPTS Internal control systems have inherent limitations, including: They are susceptible to errors and poor decisions. They can be overridden by management or by collusion of two or more employees. Internal control objectives are often at odds with each other. EXAMPLE:  Controls to safeguard assets may also reduce operational efficiency.
OVERVIEW OF CONTROL CONCEPTS Internal controls perform three important functions: Preventive controls Deter problems before they arise.
OVERVIEW OF CONTROL CONCEPTS Internal controls perform three important functions: Preventive controls Detective controls Discover problems quickly when they do arise.
OVERVIEW OF CONTROL CONCEPTS Internal controls perform three important functions: Preventive controls Detective controls Corrective controls Remedy problems that have occurred by: Identifying the cause; Correcting the resulting errors; and Modifying the system to prevent future problems of this sort.
OVERVIEW OF CONTROL CONCEPTS Internal controls are often classified as: General controls Those designed to make sure an organization’s control environment is stable and well managed. They apply to all sizes and types of systems. Examples:  Security management controls.
OVERVIEW OF CONTROL CONCEPTS Internal controls are often classified as: General controls Application controls Prevent, detect, and correct transaction errors and fraud. Are concerned with accuracy, completeness, validity, and authorization of the data captured, entered into the system, processed, stored, transmitted to other systems, and reported.
OVERVIEW OF CONTROL CONCEPTS An effective system of internal controls should exist in all organizations to: Help them achieve their missions and goals Minimize surprises
CONTROL FRAMEWORKS A number of frameworks have been developed to help companies develop good internal control systems.  Three of the most important are: The COBIT framework The COSO internal control framework COSO’s Enterprise Risk Management framework (ERM)
CONTROL FRAMEWORKS A number of frameworks have been developed to help companies develop good internal control systems.  Three of the most important are: The COBIT framework The COSO internal control framework COSO’s Enterprise Risk Management framework (ERM)
CONTROL FRAMEWORKS COBIT Framework Also know as the  Control Objectives for Information and Related Technology  framework. Developed by the Information Systems Audit and Control Foundation (ISACF). A framework of generally applicable information systems security and control practices for IT control.
CONTROL FRAMEWORKS The COBIT framework allows: Management to benchmark security and control practices of IT environments. Users of IT services to be assured that adequate security and control exists. Auditors to substantiate their opinions on internal control and advise on IT security and control matters.
CONTROL FRAMEWORKS The framework addresses the issue of control from three vantage points or dimensions: Business objectives To satisfy business objectives, information must conform to certain criteria referred to as “business requirements for information.” The criteria are divided into seven distinct yet overlapping categories that map into COSO objectives: Effectiveness (relevant, pertinent, and timely) Efficiency Confidentiality Integrity Availability Compliance with legal requirements Reliability
CONTROL FRAMEWORKS The framework addresses the issue of control from three vantage points or dimensions: Business objectives IT resources Includes: People Application systems Technology Facilities Data
CONTROL FRAMEWORKS The framework addresses the issue of control from three vantage points or dimensions: Business objectives IT resources IT processes Broken into four domains Planning and organization Acquisition and implementation Delivery and support Monitoring
CONTROL FRAMEWORKS COBIT consolidates standards from 36 different sources into a single framework. It is having a big impact on the IS profession. Helps managers to learn how to balance risk and control investment in an IS environment. Provides users with greater assurance that security and IT controls provided by internal and third parties are adequate. Guides auditors as they substantiate their opinions and provide advice to management on internal controls.
CONTROL FRAMEWORKS A number of frameworks have been developed to help companies develop good internal control systems.  Three of the most important are: The COBIT framework The COSO internal control framework COSO’s Enterprise Risk Management framework (ERM)
CONTROL FRAMEWORKS COSO’s Internal Control Framework The Committee of Sponsoring Organizations (COSO) is a private sector group consisting of: The American Accounting Association The AICPA The Institute of Internal Auditors The Institute of Management Accountants The Financial Executives Institute
CONTROL FRAMEWORKS In 1992, COSO issued the  Internal Control Integrated Framework : Defines internal controls. Provides guidance for evaluating and enhancing internal control systems. Widely accepted as the authority on internal controls. Incorporated into policies, rules, and regulations used to control business activities.
CONTROL FRAMEWORKS COSO’s internal control model has five crucial components: Control environment The core of any business is its people. Their integrity, ethical values, and competence make up the foundation on which everything else rests.
CONTROL FRAMEWORKS COSO’s internal control model has five crucial components: Control environment Control activities Policies and procedures must be established and executed to ensure that actions identified by management as necessary to address risks are, in fact, carried out.
CONTROL FRAMEWORKS COSO’s internal control model has five crucial components: Control environment Control activities Risk assessment The organization must be aware of and deal with the risks it faces. It must set objectives for its diverse activities and establish mechanisms to identify, analyze, and manage the related risks.
CONTROL FRAMEWORKS COSO’s internal control model has five crucial components: Control environment Control activities Risk assessment Information and communication Information and communications systems surround the control activities. They enable the organization’s people to capture and exchange information needed to conduct, manage, and control its operations.
CONTROL FRAMEWORKS COSO’s internal control model has five crucial components: Control environment Control activities Risk assessment Information and communication Monitoring The entire process must be monitored and modified as necessary.
CONTROL FRAMEWORKS A number of frameworks have been developed to help companies develop good internal control systems.  Three of the most important are: The COBIT framework The COSO internal control framework COSO’s Enterprise Risk Management framework (ERM)
CONTROL FRAMEWORKS Nine years after COSO issued the preceding framework, it began investigating how to effectively identify, assess, and manage risk so organizations could improve the risk management process. Result:  Enterprise Risk Manage Integrated Framework (ERM) An enhanced corporate governance document. Expands on elements of preceding framework. Provides a focus on the broader subject of enterprise risk management.
CONTROL FRAMEWORKS Intent of ERM is to achieve all goals of the internal control framework and help the organization: Provide reasonable assurance that company objectives and goals are achieved and problems and surprises are minimized. Achieve its financial and performance targets. Assess risks continuously and identify steps to take and resources to allocate to overcome or mitigate risk. Avoid adverse publicity and damage to the entity’s reputation.
CONTROL FRAMEWORKS ERM defines risk management as: A process effected by an entity’s board of directors, management, and other personnel Applied in strategy setting and across the enterprise To identify potential events that may affect the entity And manage risk to be within its risk appetite In order to provide reasonable assurance of the achievement of entity objectives.
CONTROL FRAMEWORKS Basic principles behind ERM: Companies are formed to create value for owners. Management must decide how much uncertainty they will accept. Uncertainty can result in: Risk The possibility that something will happen to: Adversely affect the ability to create value; or Erode existing value.
CONTROL FRAMEWORKS Basic principles behind ERM: Companies are formed to create value for owners. Management must decide how much uncertainty they will accept. Uncertainty can result in: Risk Opportunity The possibility that something will happen to positively affect the ability to create or preserve value.
CONTROL FRAMEWORKS The framework should help management manage uncertainty and its associated risk to build and preserve value. To maximize value, a company must balance its growth and return objectives and risks with efficient and effective use of company resources.
CONTROL FRAMEWORKS COSO developed a model to illustrate the elements of ERM.
CONTROL FRAMEWORKS Columns at the top represent the four types of  objectives  that management must meet to achieve company goals. Strategic objectives   Strategic objectives are high-level goals that are aligned with and support the company’s mission.
CONTROL FRAMEWORKS Columns at the top represent the four types of  objectives  that management must meet to achieve company goals. Strategic objectives  Operations objectives Operations objectives deal with effectiveness and efficiency of company operations, such as: Performance and profitability goals Safeguarding assets
CONTROL FRAMEWORKS Columns at the top represent the four types of  objectives  that management must meet to achieve company goals. Strategic objectives  Operations objectives Reporting objectives Reporting objectives help ensure the accuracy, completeness, and reliability of internal and external company reports of both a financial and non-financial nature. Improve decision-making and monitor company activities and performance more efficiently.
CONTROL FRAMEWORKS Columns at the top represent the four types of  objectives  that management must meet to achieve company goals. Strategic objectives  Operations objectives Reporting objectives Compliance objectives Compliance objectives help the company comply with applicable laws and regulations. External parties often set the compliance rules. Companies in the same industry often have similar concerns in this area.
CONTROL FRAMEWORKS ERM can provide reasonable assurance that reporting and compliance objectives will be achieved because companies have control over them. However, strategic and operations objectives are sometimes at the mercy of external events that the company can’t control. Therefore, in these areas, the only reasonable assurance the ERM can provide is that management and directors are informed on a timely basis of the progress the company is making in achieving them.
CONTROL FRAMEWORKS Columns on the right represent the company’s units: Entire company
CONTROL FRAMEWORKS Columns on the right represent the company’s units: Entire company Division
CONTROL FRAMEWORKS Columns on the right represent the company’s units: Entire company Division Business unit
CONTROL FRAMEWORKS Columns on the right represent the company’s units: Entire company Division Business unit Subsidiary
CONTROL FRAMEWORKS The horizontal rows are eight related risk and control components, including: Internal environment The tone or culture of the company. Provides discipline and structure and is the foundation for all other components. Essentially the same as  control environment  in the COSO internal control framework.
CONTROL FRAMEWORKS The horizontal rows are eight related risk and control components, including: Internal environment Objective setting Ensures that management implements a process to formulate strategic, operations, reporting, and compliance objectives that support the company’s mission and are consistent with the company’s tolerance for risk. Strategic objectives are set first as a foundation for the other three. The objectives provide guidance to companies as they identify risk-creating events and assess and respond to those risks.
CONTROL FRAMEWORKS The horizontal rows are eight related risk and control components, including: Internal environment Objective setting Event identification Requires management to identify events that may affect the company’s ability to implement its strategy and achieve its objectives. Management must then determine whether these events represent: Risks (negative-impact events requiring assessment and response); or Opportunities (positive-impact events that influence strategy and objective-setting processes).
CONTROL FRAMEWORKS The horizontal rows are eight related risk and control components, including: Internal environment Objective setting Event identification Risk assessment Identified risks are assessed to determine how to manage them and how they affect the company’s ability to achieve its objectives. Qualitative and quantitative methods are used to assess risks individually and by category in terms of: Likelihood Positive and negative impact Effect on other organizational units Risks are analyzed on an inherent and a residual basis. Corresponds to the risk assessment element in COSO’s internal control framework.
CONTROL FRAMEWORKS The horizontal rows are eight related risk and control components, including: Internal environment Objective setting Event identification Risk assessment Risk response Management aligns identified risks with the company’s tolerance for risk by choosing to: Avoid Reduce Share Accept Management takes an entity-wide or portfolio view of risks in assessing the likelihood of the risks, their potential impact, and costs-benefits of alternate responses.
CONTROL FRAMEWORKS The horizontal rows are eight related risk and control components, including: Internal environment Objective setting Event identification Risk assessment Risk response Control activities To implement management’s risk responses, control policies and procedures are established and implemented throughout the various levels and functions of the organization. Corresponds to the control activities element in the COSO internal control framework.
CONTROL FRAMEWORKS The horizontal rows are eight related risk and control components, including: Internal environment Objective setting Event identification Risk assessment Risk response Control activities Information and communication Information about the company and ERM components must be identified, captured, and communicated so employees can fulfill their responsibilities. Information must be able to flow through all levels and functions in the company as well as flowing to and from external parties. Employees should understand their role and importance in ERM and how these responsibilities relate to those of others. Has a corresponding element in the COSO internal control framework.
CONTROL FRAMEWORKS The horizontal rows are eight related risk and control components, including: Internal environment Objective setting Event identification Risk assessment Risk response Control activities Information and communication Monitoring ERM processes must be monitored on an ongoing basis and modified as needed. Accomplished with ongoing management activities and separate evaluations. Deficiencies are reported to management. Corresponding module in COSO internal control framework.
CONTROL FRAMEWORKS The ERM model is three-dimensional. Means that each of the eight risk and control elements are applied to the four objectives in the entire company and/or one of its subunits.
CONTROL FRAMEWORKS ERM Framework Vs. the Internal Control Framework The internal control framework has been widely adopted as the principal way to evaluate internal controls as required by SOX.  However, there are issues with it. It has too narrow of a focus. Examining controls without first examining purposes and risks of business processes provides little context for evaluating the results. Makes it difficult to know: Which control systems are most important. Whether they adequately deal with risk. Whether important control systems are missing.
CONTROL FRAMEWORKS ERM Framework Vs. the Internal Control Framework The internal control framework has been widely adopted as the principal way to evaluate internal controls as required by SOX.  However, there are issues with it. It has too narrow of a focus. Focusing on controls first has an inherent bias toward past problems and concerns. May contribute to systems with many controls to protect against risks that are no longer important.
CONTROL FRAMEWORKS These issues led to COSO’s development of the ERM framework. Takes a risk-based, rather than controls-based, approach to the organization. Oriented toward future and constant change. Incorporates rather than replaces COSO’s internal control framework and contains three additional elements: Setting objectives. Identifying positive and negative events that may affect the company’s ability to implement strategy and achieve objectives. Developing a response to assessed risk.
CONTROL FRAMEWORKS Controls are flexible and relevant because they are linked to current organizational objectives. ERM also recognizes more options than simply controlling risk, which include accepting it, avoiding it, diversifying it, sharing it, or transferring it.
CONTROL FRAMEWORKS Over time, ERM will probably become the most widely adopted risk and control model. Consequently, its eight components are the topic of the remainder of the chapter.

More Related Content

PPT
Ais Romney 2006 Slides 06 Control And Ais
PPT
Ais Romney 2006 Slides 09 Auditing Computer Based Is
PPTX
Information Systems Control and Audit - Chapter 3 - Top Management Controls -...
PPTX
Information Systems Audit - Ron Weber chapter 1
PPT
Ais Romney 2006 Slides 07 Is Control1
PDF
Control and audit of information System (hendri eka saputra)
PPTX
Information system control and audit
PDF
Internal Controls Over Information Systems
Ais Romney 2006 Slides 06 Control And Ais
Ais Romney 2006 Slides 09 Auditing Computer Based Is
Information Systems Control and Audit - Chapter 3 - Top Management Controls -...
Information Systems Audit - Ron Weber chapter 1
Ais Romney 2006 Slides 07 Is Control1
Control and audit of information System (hendri eka saputra)
Information system control and audit
Internal Controls Over Information Systems

What's hot (19)

PPTX
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)
PPTX
Simplifying IT GRC
PDF
Internal controls in an IT environment
PPTX
Conducting an Information Systems Audit
PDF
IT Control Objectives for SOX
PPTX
Information System audit
PPT
3c 2 Information Systems Audit
PPTX
Information System Audit and Control
PPT
Ais Romney 2006 Slides 08 Is Control2
PPTX
Fix nix, inc
PPT
Ais Romney 2006 Slides 19 Ais Development Strategies
PPTX
it grc
PPTX
Kontrol & Audit Sistem Informasi
PPT
Introduction to it auditing
PPT
Security audit
PPT
Ais Romney 2006 Slides 06 Control And Ais Part 1
PPTX
Lecture 16 internal control - james a. hall book chapter 3
PPT
Sap security compliance tools_PennonSoft
PPTX
Information System Architecture and Audit Control Lecture 1
CONTROL & AUDIT INFORMATION SYSTEM (HALL, 2015)
Simplifying IT GRC
Internal controls in an IT environment
Conducting an Information Systems Audit
IT Control Objectives for SOX
Information System audit
3c 2 Information Systems Audit
Information System Audit and Control
Ais Romney 2006 Slides 08 Is Control2
Fix nix, inc
Ais Romney 2006 Slides 19 Ais Development Strategies
it grc
Kontrol & Audit Sistem Informasi
Introduction to it auditing
Security audit
Ais Romney 2006 Slides 06 Control And Ais Part 1
Lecture 16 internal control - james a. hall book chapter 3
Sap security compliance tools_PennonSoft
Information System Architecture and Audit Control Lecture 1
Ad

Viewers also liked (6)

PPT
Ais Romney 2006 Slides 04 Relational Databases
PPT
Ais Romney 2006 Slides 17 Special Topics In Rea
PPT
Ais Romney 2006 Slides 16 Implementing An Rea
PPT
Ais Romney 2006 Slides 02 Business Process
PPT
Ais Romney 2006 Slides 18 Introduction To Systems Development
PPT
Ais Romney 2006 Slides 15 Database Design Using The Rea
Ais Romney 2006 Slides 04 Relational Databases
Ais Romney 2006 Slides 17 Special Topics In Rea
Ais Romney 2006 Slides 16 Implementing An Rea
Ais Romney 2006 Slides 02 Business Process
Ais Romney 2006 Slides 18 Introduction To Systems Development
Ais Romney 2006 Slides 15 Database Design Using The Rea
Ad

Similar to Ais Romney 2006 Slides 06 Control And Ais Part 1 (20)

PPT
Romney ch06
PPTX
CONTROL AND AUDIT
PDF
Core Concepts of Accounting Information Systems Canadian 1st Edition SimKin S...
PPT
Internal Controls Topic 2.ppt
PDF
Core Concepts of Accounting Information Systems Canadian 1st Edition SimKin S...
PPTX
Internal controls & ai ss
PPT
PDF
Core Concepts of Accounting Information Systems Canadian 1st Edition SimKin S...
PPT
Accounting Information Systems by James A. Hall 6th ed ch03
PDF
Core Concepts of Accounting Information Systems Canadian 1st Edition SimKin S...
PPT
ch03.ppt hjvfjkhvjhfukghufuoiugtoiijhguilgy
PDF
Core Concepts of Accounting Information Systems Canadian 1st Edition SimKin S...
DOCX
Information 2nd lesson
PPTX
Financial Auditing for Internal Auditors_CPD.pptx
PDF
Course Session Outline - Internal control in Information System
PPTX
Internal Control for Co-ops
PPT
Internal control 1_ricc_revised
PPT
General controls that we come across in Information Systems
DOC
Internal control.. control env
PDF
Chapter 7
Romney ch06
CONTROL AND AUDIT
Core Concepts of Accounting Information Systems Canadian 1st Edition SimKin S...
Internal Controls Topic 2.ppt
Core Concepts of Accounting Information Systems Canadian 1st Edition SimKin S...
Internal controls & ai ss
Core Concepts of Accounting Information Systems Canadian 1st Edition SimKin S...
Accounting Information Systems by James A. Hall 6th ed ch03
Core Concepts of Accounting Information Systems Canadian 1st Edition SimKin S...
ch03.ppt hjvfjkhvjhfukghufuoiugtoiijhguilgy
Core Concepts of Accounting Information Systems Canadian 1st Edition SimKin S...
Information 2nd lesson
Financial Auditing for Internal Auditors_CPD.pptx
Course Session Outline - Internal control in Information System
Internal Control for Co-ops
Internal control 1_ricc_revised
General controls that we come across in Information Systems
Internal control.. control env
Chapter 7

More from sharing notes123 (20)

PPTX
Uthaya Chap 05 Input
PPTX
Amr Grp Friendster
PPT
Bliana Grp Twitter Presentation
PPTX
Jasmeet Grp Facebook It Group Assig
PPT
Wong Pau Tung-special-topic-02-Virus
PPTX
Chen-special-topic-01-Multimedia
PPT
Faizan Chap 07 Storage
PPT
Dennis Chap 09 Data Communication
PPTX
Bliana Chap 02 Internet
PPTX
Amr Chap 08 Operating Systems & Utility Programs
PPTX
Pramilah Chap 04 System Unit
PPT
Adeyinka Chap 03 Application Software
PPTX
Mahendran Chap 06 Output
PPTX
Jasmeet Chap 01 Intro To Computers
PPT
Gevita Chap 10 Database Management
PPT
Ais Romney 2006 Slides 08 Is Control2
PPT
Ais Romney 2006 Slides 09 Auditing Computer Based Is
PPT
Ais Romney 2006 Slides 05 Computer Fraud And Abuse
PPT
Ais Romney 2006 Slides 19 Ais Development Strategies
PPT
Ais Romney 2006 Slides 06 Control And Ais
Uthaya Chap 05 Input
Amr Grp Friendster
Bliana Grp Twitter Presentation
Jasmeet Grp Facebook It Group Assig
Wong Pau Tung-special-topic-02-Virus
Chen-special-topic-01-Multimedia
Faizan Chap 07 Storage
Dennis Chap 09 Data Communication
Bliana Chap 02 Internet
Amr Chap 08 Operating Systems & Utility Programs
Pramilah Chap 04 System Unit
Adeyinka Chap 03 Application Software
Mahendran Chap 06 Output
Jasmeet Chap 01 Intro To Computers
Gevita Chap 10 Database Management
Ais Romney 2006 Slides 08 Is Control2
Ais Romney 2006 Slides 09 Auditing Computer Based Is
Ais Romney 2006 Slides 05 Computer Fraud And Abuse
Ais Romney 2006 Slides 19 Ais Development Strategies
Ais Romney 2006 Slides 06 Control And Ais

Recently uploaded (20)

PDF
2.FourierTransform-ShortQuestionswithAnswers.pdf
PDF
Supply Chain Operations Speaking Notes -ICLT Program
PDF
The Lost Whites of Pakistan by Jahanzaib Mughal.pdf
PDF
BÀI TẬP BỔ TRỢ 4 KỸ NĂNG TIẾNG ANH 9 GLOBAL SUCCESS - CẢ NĂM - BÁM SÁT FORM Đ...
PPTX
school management -TNTEU- B.Ed., Semester II Unit 1.pptx
PDF
Complications of Minimal Access Surgery at WLH
PPTX
Cell Structure & Organelles in detailed.
PPTX
PPH.pptx obstetrics and gynecology in nursing
PPTX
Introduction_to_Human_Anatomy_and_Physiology_for_B.Pharm.pptx
PDF
102 student loan defaulters named and shamed – Is someone you know on the list?
PDF
RMMM.pdf make it easy to upload and study
PPTX
Renaissance Architecture: A Journey from Faith to Humanism
PDF
VCE English Exam - Section C Student Revision Booklet
PDF
Classroom Observation Tools for Teachers
PDF
Insiders guide to clinical Medicine.pdf
PDF
Anesthesia in Laparoscopic Surgery in India
PDF
01-Introduction-to-Information-Management.pdf
PDF
Saundersa Comprehensive Review for the NCLEX-RN Examination.pdf
PPTX
master seminar digital applications in india
PDF
O7-L3 Supply Chain Operations - ICLT Program
2.FourierTransform-ShortQuestionswithAnswers.pdf
Supply Chain Operations Speaking Notes -ICLT Program
The Lost Whites of Pakistan by Jahanzaib Mughal.pdf
BÀI TẬP BỔ TRỢ 4 KỸ NĂNG TIẾNG ANH 9 GLOBAL SUCCESS - CẢ NĂM - BÁM SÁT FORM Đ...
school management -TNTEU- B.Ed., Semester II Unit 1.pptx
Complications of Minimal Access Surgery at WLH
Cell Structure & Organelles in detailed.
PPH.pptx obstetrics and gynecology in nursing
Introduction_to_Human_Anatomy_and_Physiology_for_B.Pharm.pptx
102 student loan defaulters named and shamed – Is someone you know on the list?
RMMM.pdf make it easy to upload and study
Renaissance Architecture: A Journey from Faith to Humanism
VCE English Exam - Section C Student Revision Booklet
Classroom Observation Tools for Teachers
Insiders guide to clinical Medicine.pdf
Anesthesia in Laparoscopic Surgery in India
01-Introduction-to-Information-Management.pdf
Saundersa Comprehensive Review for the NCLEX-RN Examination.pdf
master seminar digital applications in india
O7-L3 Supply Chain Operations - ICLT Program

Ais Romney 2006 Slides 06 Control And Ais Part 1

  • 1. HAPTER 6 Control and Accounting Information Systems
  • 2. INTRODUCTION Questions to be addressed in this chapter: What are the basic internal control concepts, and why are computer control and security important? What is the difference between the COBIT, COSO, and ERM control frameworks? What are the major elements in the internal environment of a company? What are the four types of control objectives that companies need to set? What events affect uncertainty, and how can they be identified? How is the Enterprise Risk Management model used to assess and respond to risk? What control activities are commonly used in companies? How do organizations communicate information and monitor control processes?
  • 3. INTRODUCTION Why AIS Threats Are Increasing Control risks have increased in the last few years because: There are computers and servers everywhere, and information is available to an unprecedented number of workers. Distributed computer networks make data available to many users, and these networks are harder to control than centralized mainframe systems. Wide area networks are giving customers and suppliers access to each other’s systems and data, making confidentiality a major concern.
  • 4. INTRODUCTION Historically, many organizations have not adequately protected their data due to one or more of the following reasons: Computer control problems are often underestimated and downplayed. Control implications of moving from centralized, host-based computer systems to those of a networked system or Internet-based system are not always fully understood. Companies have not realized that data is a strategic resource and that data security must be a strategic requirement. Productivity and cost pressures may motivate management to forego time-consuming control measures.
  • 5. INTRODUCTION Some vocabulary terms for this chapter: A threat is any potential adverse occurrence or unwanted event that could injure the AIS or the organization. The exposure or impact of the threat is the potential dollar loss that would occur if the threat becomes a reality. The likelihood is the probability that the threat will occur.
  • 6. INTRODUCTION Control and Security are Important Companies are now recognizing the problems and taking positive steps to achieve better control, including: Devoting full-time staff to security and control concerns. Educating employees about control measures. Establishing and enforcing formal information security policies. Making controls a part of the applications development process. Moving sensitive data to more secure environments.
  • 7. INTRODUCTION To use IT in achieving control objectives, accountants must: Understand how to protect systems from threats. Have a good understanding of IT and its capabilities and risks. Achieving adequate security and control over the information resources of an organization should be a top management priority.
  • 8. INTRODUCTION Control objectives are the same regardless of the data processing method, but a computer-based AIS requires different internal control policies and procedures because: Computer processing may reduce clerical errors but increase risks of unauthorized access or modification of data files. Segregation of duties must be achieved differently in an AIS. Computers provide opportunities for enhancement of some internal controls.
  • 9. INTRODUCTION One of the primary objectives of an AIS is to control a business organization. Accountants must help by designing effective control systems and auditing or reviewing control systems already in place to ensure their effectiveness. Management expects accountants to be control consultants by: Taking a proactive approach to eliminating system threats; and Detecting, correcting, and recovering from threats when they do occur.
  • 10. INTRODUCTION It is much easier to build controls into a system during the initial stage than to add them after the fact. Consequently, accountants and control experts should be members of the teams that develop or modify information systems.
  • 11. OVERVIEW OF CONTROL CONCEPTS In today’s dynamic business environment, companies must react quickly to changing conditions and markets, including steps to: Hire creative and innovative employees. Give these employees power and flexibility to: Satisfy changing customer demands; Pursue new opportunities to add value to the organization; and Implement process improvements. At the same time, the company needs control systems so they are not exposed to excessive risks or behaviors that could harm their reputation for honesty and integrity.
  • 12. OVERVIEW OF CONTROL CONCEPTS Internal control is the process implemented by the board of directors, management, and those under their direction to provide reasonable assurance that the following control objectives are achieved: Assets (including data) are safeguarded. This objective includes prevention or timely detection of unauthorized acquisition, use, or disposal of material company assets.
  • 13. OVERVIEW OF CONTROL CONCEPTS Internal control is the process implemented by the board of directors, management, and those under their direction to provide reasonable assurance that the following control objectives are achieved: Assets (including data) are safeguarded. Records are maintained in sufficient detail to accurately and fairly reflect company assets.
  • 14. OVERVIEW OF CONTROL CONCEPTS Internal control is the process implemented by the board of directors, management, and those under their direction to provide reasonable assurance that the following control objectives are achieved: Assets (including data) are safeguarded. Records are maintained in sufficient detail to accurately and fairly reflect company assets. Accurate and reliable information is provided.
  • 15. OVERVIEW OF CONTROL CONCEPTS Internal control is the process implemented by the board of directors, management, and those under their direction to provide reasonable assurance that the following control objectives are achieved: Assets (including data) are safeguarded. Records are maintained in sufficient detail to accurately and fairly reflect company assets. Accurate and reliable information is provided. There is reasonable assurance that financial reports are prepared in accordance with GAAP.
  • 16. OVERVIEW OF CONTROL CONCEPTS Internal control is the process implemented by the board of directors, management, and those under their direction to provide reasonable assurance that the following control objectives are achieved: Assets (including data) are safeguarded. Records are maintained in sufficient detail to accurately and fairly reflect company assets. Accurate and reliable information is provided. There is reasonable assurance that financial reports are prepared in accordance with GAAP. Operational efficiency is promoted and improved. This objective includes ensuring that company receipts and expenditures are made in accordance with management and directors’ authorizations.
  • 17. OVERVIEW OF CONTROL CONCEPTS Internal control is the process implemented by the board of directors, management, and those under their direction to provide reasonable assurance that the following control objectives are achieved: Assets (including data) are safeguarded. Records are maintained in sufficient detail to accurately and fairly reflect company assets. Accurate and reliable information is provided. There is reasonable assurance that financial reports are prepared in accordance with GAAP. Operational efficiency is promoted and improved. Adherence to prescribed managerial policies is encouraged.
  • 18. OVERVIEW OF CONTROL CONCEPTS Internal control is the process implemented by the board of directors, management, and those under their direction to provide reasonable assurance that the following control objectives are achieved: Assets (including data) are safeguarded. Records are maintained in sufficient detail to accurately and fairly reflect company assets. Accurate and reliable information is provided. There is reasonable assurance that financial reports are prepared in accordance with GAAP. Operational efficiency is promoted and improved. Adherence to prescribed managerial policies is encouraged. The organization complies with applicable laws and regulations .
  • 19. OVERVIEW OF CONTROL CONCEPTS Internal control is a process because: It permeates an organization’s operating activities. It is an integral part of basic management activities. Internal control provides reasonable , rather than absolute, assurance, because complete assurance is difficult or impossible to achieve and prohibitively expensive.
  • 20. OVERVIEW OF CONTROL CONCEPTS Internal control systems have inherent limitations, including: They are susceptible to errors and poor decisions. They can be overridden by management or by collusion of two or more employees. Internal control objectives are often at odds with each other. EXAMPLE: Controls to safeguard assets may also reduce operational efficiency.
  • 21. OVERVIEW OF CONTROL CONCEPTS Internal controls perform three important functions: Preventive controls Deter problems before they arise.
  • 22. OVERVIEW OF CONTROL CONCEPTS Internal controls perform three important functions: Preventive controls Detective controls Discover problems quickly when they do arise.
  • 23. OVERVIEW OF CONTROL CONCEPTS Internal controls perform three important functions: Preventive controls Detective controls Corrective controls Remedy problems that have occurred by: Identifying the cause; Correcting the resulting errors; and Modifying the system to prevent future problems of this sort.
  • 24. OVERVIEW OF CONTROL CONCEPTS Internal controls are often classified as: General controls Those designed to make sure an organization’s control environment is stable and well managed. They apply to all sizes and types of systems. Examples: Security management controls.
  • 25. OVERVIEW OF CONTROL CONCEPTS Internal controls are often classified as: General controls Application controls Prevent, detect, and correct transaction errors and fraud. Are concerned with accuracy, completeness, validity, and authorization of the data captured, entered into the system, processed, stored, transmitted to other systems, and reported.
  • 26. OVERVIEW OF CONTROL CONCEPTS An effective system of internal controls should exist in all organizations to: Help them achieve their missions and goals Minimize surprises
  • 27. CONTROL FRAMEWORKS A number of frameworks have been developed to help companies develop good internal control systems. Three of the most important are: The COBIT framework The COSO internal control framework COSO’s Enterprise Risk Management framework (ERM)
  • 28. CONTROL FRAMEWORKS A number of frameworks have been developed to help companies develop good internal control systems. Three of the most important are: The COBIT framework The COSO internal control framework COSO’s Enterprise Risk Management framework (ERM)
  • 29. CONTROL FRAMEWORKS COBIT Framework Also know as the Control Objectives for Information and Related Technology framework. Developed by the Information Systems Audit and Control Foundation (ISACF). A framework of generally applicable information systems security and control practices for IT control.
  • 30. CONTROL FRAMEWORKS The COBIT framework allows: Management to benchmark security and control practices of IT environments. Users of IT services to be assured that adequate security and control exists. Auditors to substantiate their opinions on internal control and advise on IT security and control matters.
  • 31. CONTROL FRAMEWORKS The framework addresses the issue of control from three vantage points or dimensions: Business objectives To satisfy business objectives, information must conform to certain criteria referred to as “business requirements for information.” The criteria are divided into seven distinct yet overlapping categories that map into COSO objectives: Effectiveness (relevant, pertinent, and timely) Efficiency Confidentiality Integrity Availability Compliance with legal requirements Reliability
  • 32. CONTROL FRAMEWORKS The framework addresses the issue of control from three vantage points or dimensions: Business objectives IT resources Includes: People Application systems Technology Facilities Data
  • 33. CONTROL FRAMEWORKS The framework addresses the issue of control from three vantage points or dimensions: Business objectives IT resources IT processes Broken into four domains Planning and organization Acquisition and implementation Delivery and support Monitoring
  • 34. CONTROL FRAMEWORKS COBIT consolidates standards from 36 different sources into a single framework. It is having a big impact on the IS profession. Helps managers to learn how to balance risk and control investment in an IS environment. Provides users with greater assurance that security and IT controls provided by internal and third parties are adequate. Guides auditors as they substantiate their opinions and provide advice to management on internal controls.
  • 35. CONTROL FRAMEWORKS A number of frameworks have been developed to help companies develop good internal control systems. Three of the most important are: The COBIT framework The COSO internal control framework COSO’s Enterprise Risk Management framework (ERM)
  • 36. CONTROL FRAMEWORKS COSO’s Internal Control Framework The Committee of Sponsoring Organizations (COSO) is a private sector group consisting of: The American Accounting Association The AICPA The Institute of Internal Auditors The Institute of Management Accountants The Financial Executives Institute
  • 37. CONTROL FRAMEWORKS In 1992, COSO issued the Internal Control Integrated Framework : Defines internal controls. Provides guidance for evaluating and enhancing internal control systems. Widely accepted as the authority on internal controls. Incorporated into policies, rules, and regulations used to control business activities.
  • 38. CONTROL FRAMEWORKS COSO’s internal control model has five crucial components: Control environment The core of any business is its people. Their integrity, ethical values, and competence make up the foundation on which everything else rests.
  • 39. CONTROL FRAMEWORKS COSO’s internal control model has five crucial components: Control environment Control activities Policies and procedures must be established and executed to ensure that actions identified by management as necessary to address risks are, in fact, carried out.
  • 40. CONTROL FRAMEWORKS COSO’s internal control model has five crucial components: Control environment Control activities Risk assessment The organization must be aware of and deal with the risks it faces. It must set objectives for its diverse activities and establish mechanisms to identify, analyze, and manage the related risks.
  • 41. CONTROL FRAMEWORKS COSO’s internal control model has five crucial components: Control environment Control activities Risk assessment Information and communication Information and communications systems surround the control activities. They enable the organization’s people to capture and exchange information needed to conduct, manage, and control its operations.
  • 42. CONTROL FRAMEWORKS COSO’s internal control model has five crucial components: Control environment Control activities Risk assessment Information and communication Monitoring The entire process must be monitored and modified as necessary.
  • 43. CONTROL FRAMEWORKS A number of frameworks have been developed to help companies develop good internal control systems. Three of the most important are: The COBIT framework The COSO internal control framework COSO’s Enterprise Risk Management framework (ERM)
  • 44. CONTROL FRAMEWORKS Nine years after COSO issued the preceding framework, it began investigating how to effectively identify, assess, and manage risk so organizations could improve the risk management process. Result: Enterprise Risk Manage Integrated Framework (ERM) An enhanced corporate governance document. Expands on elements of preceding framework. Provides a focus on the broader subject of enterprise risk management.
  • 45. CONTROL FRAMEWORKS Intent of ERM is to achieve all goals of the internal control framework and help the organization: Provide reasonable assurance that company objectives and goals are achieved and problems and surprises are minimized. Achieve its financial and performance targets. Assess risks continuously and identify steps to take and resources to allocate to overcome or mitigate risk. Avoid adverse publicity and damage to the entity’s reputation.
  • 46. CONTROL FRAMEWORKS ERM defines risk management as: A process effected by an entity’s board of directors, management, and other personnel Applied in strategy setting and across the enterprise To identify potential events that may affect the entity And manage risk to be within its risk appetite In order to provide reasonable assurance of the achievement of entity objectives.
  • 47. CONTROL FRAMEWORKS Basic principles behind ERM: Companies are formed to create value for owners. Management must decide how much uncertainty they will accept. Uncertainty can result in: Risk The possibility that something will happen to: Adversely affect the ability to create value; or Erode existing value.
  • 48. CONTROL FRAMEWORKS Basic principles behind ERM: Companies are formed to create value for owners. Management must decide how much uncertainty they will accept. Uncertainty can result in: Risk Opportunity The possibility that something will happen to positively affect the ability to create or preserve value.
  • 49. CONTROL FRAMEWORKS The framework should help management manage uncertainty and its associated risk to build and preserve value. To maximize value, a company must balance its growth and return objectives and risks with efficient and effective use of company resources.
  • 50. CONTROL FRAMEWORKS COSO developed a model to illustrate the elements of ERM.
  • 51. CONTROL FRAMEWORKS Columns at the top represent the four types of objectives that management must meet to achieve company goals. Strategic objectives Strategic objectives are high-level goals that are aligned with and support the company’s mission.
  • 52. CONTROL FRAMEWORKS Columns at the top represent the four types of objectives that management must meet to achieve company goals. Strategic objectives Operations objectives Operations objectives deal with effectiveness and efficiency of company operations, such as: Performance and profitability goals Safeguarding assets
  • 53. CONTROL FRAMEWORKS Columns at the top represent the four types of objectives that management must meet to achieve company goals. Strategic objectives Operations objectives Reporting objectives Reporting objectives help ensure the accuracy, completeness, and reliability of internal and external company reports of both a financial and non-financial nature. Improve decision-making and monitor company activities and performance more efficiently.
  • 54. CONTROL FRAMEWORKS Columns at the top represent the four types of objectives that management must meet to achieve company goals. Strategic objectives Operations objectives Reporting objectives Compliance objectives Compliance objectives help the company comply with applicable laws and regulations. External parties often set the compliance rules. Companies in the same industry often have similar concerns in this area.
  • 55. CONTROL FRAMEWORKS ERM can provide reasonable assurance that reporting and compliance objectives will be achieved because companies have control over them. However, strategic and operations objectives are sometimes at the mercy of external events that the company can’t control. Therefore, in these areas, the only reasonable assurance the ERM can provide is that management and directors are informed on a timely basis of the progress the company is making in achieving them.
  • 56. CONTROL FRAMEWORKS Columns on the right represent the company’s units: Entire company
  • 57. CONTROL FRAMEWORKS Columns on the right represent the company’s units: Entire company Division
  • 58. CONTROL FRAMEWORKS Columns on the right represent the company’s units: Entire company Division Business unit
  • 59. CONTROL FRAMEWORKS Columns on the right represent the company’s units: Entire company Division Business unit Subsidiary
  • 60. CONTROL FRAMEWORKS The horizontal rows are eight related risk and control components, including: Internal environment The tone or culture of the company. Provides discipline and structure and is the foundation for all other components. Essentially the same as control environment in the COSO internal control framework.
  • 61. CONTROL FRAMEWORKS The horizontal rows are eight related risk and control components, including: Internal environment Objective setting Ensures that management implements a process to formulate strategic, operations, reporting, and compliance objectives that support the company’s mission and are consistent with the company’s tolerance for risk. Strategic objectives are set first as a foundation for the other three. The objectives provide guidance to companies as they identify risk-creating events and assess and respond to those risks.
  • 62. CONTROL FRAMEWORKS The horizontal rows are eight related risk and control components, including: Internal environment Objective setting Event identification Requires management to identify events that may affect the company’s ability to implement its strategy and achieve its objectives. Management must then determine whether these events represent: Risks (negative-impact events requiring assessment and response); or Opportunities (positive-impact events that influence strategy and objective-setting processes).
  • 63. CONTROL FRAMEWORKS The horizontal rows are eight related risk and control components, including: Internal environment Objective setting Event identification Risk assessment Identified risks are assessed to determine how to manage them and how they affect the company’s ability to achieve its objectives. Qualitative and quantitative methods are used to assess risks individually and by category in terms of: Likelihood Positive and negative impact Effect on other organizational units Risks are analyzed on an inherent and a residual basis. Corresponds to the risk assessment element in COSO’s internal control framework.
  • 64. CONTROL FRAMEWORKS The horizontal rows are eight related risk and control components, including: Internal environment Objective setting Event identification Risk assessment Risk response Management aligns identified risks with the company’s tolerance for risk by choosing to: Avoid Reduce Share Accept Management takes an entity-wide or portfolio view of risks in assessing the likelihood of the risks, their potential impact, and costs-benefits of alternate responses.
  • 65. CONTROL FRAMEWORKS The horizontal rows are eight related risk and control components, including: Internal environment Objective setting Event identification Risk assessment Risk response Control activities To implement management’s risk responses, control policies and procedures are established and implemented throughout the various levels and functions of the organization. Corresponds to the control activities element in the COSO internal control framework.
  • 66. CONTROL FRAMEWORKS The horizontal rows are eight related risk and control components, including: Internal environment Objective setting Event identification Risk assessment Risk response Control activities Information and communication Information about the company and ERM components must be identified, captured, and communicated so employees can fulfill their responsibilities. Information must be able to flow through all levels and functions in the company as well as flowing to and from external parties. Employees should understand their role and importance in ERM and how these responsibilities relate to those of others. Has a corresponding element in the COSO internal control framework.
  • 67. CONTROL FRAMEWORKS The horizontal rows are eight related risk and control components, including: Internal environment Objective setting Event identification Risk assessment Risk response Control activities Information and communication Monitoring ERM processes must be monitored on an ongoing basis and modified as needed. Accomplished with ongoing management activities and separate evaluations. Deficiencies are reported to management. Corresponding module in COSO internal control framework.
  • 68. CONTROL FRAMEWORKS The ERM model is three-dimensional. Means that each of the eight risk and control elements are applied to the four objectives in the entire company and/or one of its subunits.
  • 69. CONTROL FRAMEWORKS ERM Framework Vs. the Internal Control Framework The internal control framework has been widely adopted as the principal way to evaluate internal controls as required by SOX. However, there are issues with it. It has too narrow of a focus. Examining controls without first examining purposes and risks of business processes provides little context for evaluating the results. Makes it difficult to know: Which control systems are most important. Whether they adequately deal with risk. Whether important control systems are missing.
  • 70. CONTROL FRAMEWORKS ERM Framework Vs. the Internal Control Framework The internal control framework has been widely adopted as the principal way to evaluate internal controls as required by SOX. However, there are issues with it. It has too narrow of a focus. Focusing on controls first has an inherent bias toward past problems and concerns. May contribute to systems with many controls to protect against risks that are no longer important.
  • 71. CONTROL FRAMEWORKS These issues led to COSO’s development of the ERM framework. Takes a risk-based, rather than controls-based, approach to the organization. Oriented toward future and constant change. Incorporates rather than replaces COSO’s internal control framework and contains three additional elements: Setting objectives. Identifying positive and negative events that may affect the company’s ability to implement strategy and achieve objectives. Developing a response to assessed risk.
  • 72. CONTROL FRAMEWORKS Controls are flexible and relevant because they are linked to current organizational objectives. ERM also recognizes more options than simply controlling risk, which include accepting it, avoiding it, diversifying it, sharing it, or transferring it.
  • 73. CONTROL FRAMEWORKS Over time, ERM will probably become the most widely adopted risk and control model. Consequently, its eight components are the topic of the remainder of the chapter.