Question

In: Accounting

Compare and contrast the COBIT and the COSO Enterprise Risk Management Frameworks.

Compare and contrast the COBIT and the COSO Enterprise Risk Management Frameworks.

Solutions

Expert Solution

COBIT is a framework for IT control and allows benchmarking of environment within an organization and meaningful comparison with other organizations. The COBIT framework is comprehensive and hence provides assurance that IT security and controls do indeed exist. Most importantly COBIT framework allows auditors to substantiate their opinions with regards to a company’s internal controls.

COBIT enables a holistic approach and effectively separates governance from management.

COSO’s Enterprise Risk Management Framework is a new and improved version of the Integrated Control Framework. It is the process the board of directors and management use to set strategy, identify events that may affect the entity, assess and manage risk, and provide reasonable assurance that the company achieves its objectives and goals. The basic principles behind ERM are:

1. Companies are formed to create value for their owners.

2. Management must decide how much uncertainty it will accept as it creates value.

4. The ERM framework can manage uncertainty as well as create and preserve value.

ERM adds three additional elements to COSO’s IC framework:

1. Setting objectives

2. Identifying events that may affect the company

3. Developing a response to assessed risk.


Related Solutions

Compare and contrast the COBIT and the COSO Enterprise Risk Management Frameworks. (more details minimum provide...
Compare and contrast the COBIT and the COSO Enterprise Risk Management Frameworks. (more details minimum provide 7 differences/similarities).
discuss on COSO and COBIT frameworks for Internal controls
discuss on COSO and COBIT frameworks for Internal controls
Enterprise Risk Management. The enterprise risk management (ERM) framework was developed by COSO to provide managers...
Enterprise Risk Management. The enterprise risk management (ERM) framework was developed by COSO to provide managers a formalized methodology to evaluate risk in their businesses. Required: Explain how management would use the ERM framework to manage business risk.
The purpose of the COSO Enterprise Risk Management framework is A) to improve the organization's risk...
The purpose of the COSO Enterprise Risk Management framework is A) to improve the organization's risk management process. B) to improve the organization's financial reporting process. C) to improve the organization's manufacturing process. D) to improve the organization's internal audit process
According COSO, which of the following components of Enterprise Risk Management defines an entity’s Risk Appetite?...
According COSO, which of the following components of Enterprise Risk Management defines an entity’s Risk Appetite? A. Governance & Culture B. Performance C. Strategy&ObjectiveSetting D. Information, Communication & Reporting
Contrast and compare the different approaches to building a comprehensive strategic risk management process.
Contrast and compare the different approaches to building a comprehensive strategic risk management process.
- What are the legal frameworks of enterprise in Canada?
- What are the legal frameworks of enterprise in Canada?
Differentiate between COSO and COBIT in terms of their purpose and application. Why do organizations need...
Differentiate between COSO and COBIT in terms of their purpose and application. Why do organizations need to apply both of them not only one.
Compare and contrast different local and international sustainable reporting frameworks in terms of Australia.
Compare and contrast different local and international sustainable reporting frameworks in terms of Australia.
What distinguishes enterprise risk management from more traditional approaches to risk management?
What distinguishes enterprise risk management from more traditional approaches to risk management?
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT