12.1 Refer to the chapter opener, Meet the CFO. In your opinion, how could enterprise risk
management affect a company’s financial performance during an economic downturn?
Managing risk intelligently is about managing not only adverse risks, but also capitalizing
on risk that presents the enterprise with opportunities to create value, such as evaluating
risk associated with a new business acquisition or merging with another business.
Although the new acquisition may have risk associated with it, the venture also presents
the possibility of generating additional income. The venture is a rewarded risk. In an
economic downturn the business environment is much riskier, thus it presents more
opportunities for businesses. With an intelligence risk management, enterprises could
increase their business opportunities.
12.2 Refer to the chapter opener, Meet the CFO. In your opinion, why is the CFO
well-suited to advise about enterprise risk management?
The enterprise risk management allows the enterprise to take advantage of risks that are
associated with opportunities. By incorporating ERM as a parameter in the
decision-making processes, management would take advantage of opportunities that were
not considered without ERM.
12.3 Discuss how enterprise risk management, internal control, and IT controls are related.
As the figure 12.1 shows the enterprise risk management encompasses internal control and
IT control encompasses the IT control.
Enterprise risk management can be defined as integrating risk with concept of internal
control, SOX, and enterprise strategic planning. This makes the internal control a subset of
enterprise risk management. IT control can be defined as a set of specific tasks carried out
by the enterprise designed to ensure that business IT objectives are met, thus IT control is a
subset of Internal control
12.4 Discuss how opportunity and risk are related.
Some risks have only loss associated with them. But some others associated not only with
loss but also with opportunities. Consider investing in stocks. There is a risk that you lose
money on this investment, but also there is an opportunity to gain.
12.5 Discuss the difference between possibility and probability as related to risk.
In the context of ERM risk assessment, the terms possibility and probability can have
different definitions. Possibility may refer to assessing likelihood using qualitative
measures, such as high, medium, or low. Probability may refer to assessing likelihood
using a quantitative measure, such as percentages.
12.6 Discuss how governance, including the tone at the top of the organization and policies
and procedures, affect an organization’s risk management.
You learned in chapter 10 about the three zones in house of IT controls. These three zones
are:
1. Entity-level controls for top management
2. Application controls for business processes
3. IT general controls for IT services
The entity-level IT controls provide IT governance that sets the tone from the top of the
enterprise. Application controls are controls embedded in business processes where a
majority of security breaches occur. IT general controls within IT processes support
application controls and provide a reliable operating environment. Decisions made at the
top level of the organization would affect the application control and IT general control
and consequently the risk management associated with business processes.
12.7 Discuss the differences between risk management and risk intelligence.
Risk management is a coordinated implementation of the enterprise resources to minimize,
monitor, and control the possibility and probability of occurrence and impact of risk.
Risk intelligence goes beyond just risk management. Risk intelligence includes managing
not only adverse risks, but also capitalizing on risk that presents the enterprise with
opportunities to create value.
12.8 Discuss how incorporating sustainability practices supports an organization’s
enterprise risk management efforts.
Increasingly enterprises are faced with more regulation and growing challenges to obtain
scarce resources. Sustainability practices offer a solution to reduce risk. Focusing on
sustainable operations reduces the risk of dependence on dwindling natural resources that
may become cost prohibitive in the future. Furthermore, with the growing concerns about
the natural environment, sustainable practices may offer an enterprise advantages with
regard to reduced risk in an increasingly regulated environment with greater demand for
transparency. Sustainability related innovation could play an important role in
transforming risks into opportunities.
12.9 Discuss why the simple spreadsheet can represent a significant risk to organizations.
Spreadsheets introduce significant risks into the financial reporting process for some
organizations because they:
1. Might have thousands of spreadsheets in shadow data
2. Have no or limited controls over spreadsheets
Because of widespread spreadsheet use with limited controls, enterprises may integrate
controls into spreadsheet management to reduce risk.
12.10 Discuss the benefits of a global spreadsheet identification system.
The global identification system is suggested in the top 10 tips for improving spreadsheet
risk management. The global identification system provides an effective spreadsheet
control by tracking spreadsheet inventory, monitoring spreadsheets change, and
implementing spreadsheet security and integrity.
Key Terms Check
Exercises
Short Exercises
12.17 Compare and contrast COSO’s Enterprise Risk Management—Integrated
Framework and COSO’s Internal Control—Integrated Framework. (Q12.1)
Compare (Same) and Contrast (Different)
Both frameworks provide reasonable assurance in achieving internal control objectives
COSO’s ERM goes beyond COSO’s IC by integrating risk management into the
framework
Both frameworks introduce operations, reporting, and compliance objectives. COSO’s
ERM has the additional strategic objective and reporting objective includes both internal
and external reports
Both frameworks include the following components:
• Risk assessment
• Control activities
• Environment and communication
• Monitoring COSO’s ERM control environment changed to internal environment and
components related to risk are expanded to include objective setting, event identification,
and risk response
12.18 List and explain the four enterprise risk management objectives specified in the
ERM framework. (Q12.2)
The ERM framework specifies four categories of an enterprise’s objectives:
• Strategic objectives relate to goals that support the entity’s mission.
• Operational objectives relate to the effective and efficient use of the entity’s resources.