First Reference company logo

Inside Internal Controls

News and discussion on implementing risk management

machine cogs image

risk and opportunity

New ERM Guidance from COSO

Creating and Protecting Value: Understanding and Implementing Enterprise Risk Management is based on COSO’s 2017 update of its 2004 ERM Framework. Their intent is to explain how effective ERM can add value to an organization, and to give some guidance on how to implement or upgrade it.

 

, , ,

A risk case study

I returned this week from a vacation in Mexico, including a day at the Copper Canyon. Our tour guide took about 20 of us down the mountain side to see some Tarahumara Indian homes. I decided that I wanted to come back ahead of the group, finding my way back up the path and steps to our hotel at the top. What might happen along the way? In other words, what would a risk manager put on a list or heat map?

 

, , , ,

The positive side of risk

So how should we talk about the good stuff if we reserve the word ‘risk’ for the bad?

 

, , ,

Talking about risk and opportunity

Some talk about opportunity as “the other side of the coin” from risk. COSO views the two words, risk and opportunity, as one is good and the other is bad. ISO seems them differently, defining risk as the effect on objectives. That effect could be positive or harmful.

 

, ,