Sei sulla pagina 1di 13

• Chapter 7

Enterprise Risk Management


Enterprise Risk Management

ERM is process, effected by an entity’s board of directors, management and


other personnel , applied in strategy setting and across the enterprise,
designed to identity potential events thet may affect the entity, and
managed risk to be its risk appetite, to provide reasonable
assurance regarding the achievement of entity objectives.

Risk are defined here as the possibility that an event may occur that will
adversely affect the achievement of enterprise objectives.
An effective risk management process

1. Risk Identification
2. Quantitative / Qualitative assessment of documented risks
3. Risk prioritization and response planning
4. Risk monitoring
1. Enterprise-Wide Strategic Risks
1.1. External Factors Risks
1.2. Internal Factors Risks
2. Operation Risks 3. Finance Risks
2.1. Process Risks 3.1.Treasury Risks
2.2. Compliance Risks 3.2. Credit Risks
2.3. People Risks 3.3. Trading risks
4. Information Risks
4.1. Financial Risks
4.2. Operational Risks
4.3. Technological Risks
( 3 ) Prioritization and respone planning ; ( 4 ) Risk monitoring

3.1. Risk Response


(1) avoidance
(2) reduction
(3) sharing
(4) acceptance
With COSO ERM Key Elements, its to help internal auditors at all levels, from
the chief audit executive (CAE) to staff auditors, to better understand COSO
ERM and learn how it can help manage a wide range of internal audits risks
facing enterprises.
1.1.Risk management philosophy
1.2.Risk appetite
1.3.Board of directors’ attitudes
1.4.Integrity and ethical values
1.5.Commitment to competence
1.6.Organizational structure
1.7.Assignments of authority and responsibility
1.8.Human resources standards
( 2 ) Objectives Setting / exhibit 7.7.

( 3 ) Event Identification
3.1.External economic events
3.2.Natural environmental events
3.3.Political events
3.4.Social factors
3.5.Internal infrastructure events
3.6.Internal process-related events
3.7.External and internal technological events
( 4 ) Risk Assessment : 4.1.inherent risk ; 4.2.residual risk

( 5 ) Control Activities : 5.1.separation of duties


5.2.audit trail
5.3.security and integrity
5.4.documentation

( 6 ) Information and Communication / exhibit 7.9.

( 7 ) Monitoring
KESIMPULAN

1. VISI dari Audit Internal adalah membantu Manajemen untuk mencapai


tujuan yang telah ditetapkan
2. Dengan memahami COSO ERM serta me reviu pelaksanaan ERM dengan
memakai ERM Key Elements sebagai Tools, maka Audit Internal dapat
memberikan “assurance” kepada manajemen untuk mencapai tujuan yamg
telah ditetapkan.

Potrebbero piacerti anche