Transcription of เรื่อง กรอบการบริหารความเสี่ยง 2017 (Enterprise Risk ...
1 ( ) 2017 (Enterprise Risk Management Integrating with Strategy and Performance: 2017 ) 6 2560 . F-310 2 3 : .. What s New under COSO-ERM 2017 Framework?Sillapaporn Srijunpetch, , CPANew COSO-ERM 2017223 Today s organizations are concerned about: Risk Management Governance Control Assurance (andConsulting)Please noteGovernance has beendropped to rankingnumber two.
2 COSO ERM 20044 COSO: The Committee of Sponsoring Organization of Treadway Commission56 ERM Defined: .. a process,effected by an entity's board of directors,management and other personnel,applied in strategy setting and across the enterprise,designed to identify potential events that may affect the entity, and manage risks to be within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives. Source: COSO Enterprise Risk Management Integrated Framework. 2 (Negative Effect) (Risk) (Positive Effect) (Opportunity)78 Why ERM Is Important [Exec Summary page 1]Underlying principles: Every entity, whether for-profit or not, exists to realize value for its stakeholders.
3 Value is created, preserved, or erodedby management decisions in all activities, fromsetting strategy tooperating the enterprise day-to-day. 9 Why ERM Is Important [Exec Summary page 1]ERM supports value creation by enabling management to: Deal effectivelywith potential future events that create uncertainty. Respondin a manner that reducesthe likelihood of downside outcomes and increases the upside. 10 This COSO ERM framework - defines essential components, - suggests a common language, and- provides clear direction and guidance for enterprise risk Framework Enterprise Risk Management - Integrated Framework 1: 2: 3.
4 11 Internal EnvironmentEvent IdentificationRisk AssessmentControl ActivitiesRisk ResponseInformation & CommunicationMonitoringObjective SettingSubsidiaryBusiness UnitDivisionEntity-Level1. 2. 3. 4. 5. 6. 7. 8. 1213 Internal Environment Establishes a philosophyregarding risk management. It recognizes that unexpectedas well as expectedevents may occur. Establishes the entity s risk culture. Considers all other aspectsof how the organization s actions may affect its risk Setting Is applied when management considers risks strategyin the setting of objectives.
5 Forms the risk appetiteof the entity - a high-level view of how muchrisk management and the board are willing to Identification Differentiates risksand opportunities. Events that may have a negative impactrepresent risks . Events that may have a positive impactrepresent natural offsets (opportunities), which management channels back to strategy Identification Involves identifying those incidents, occurring internally or externally, that could affect strategyand achievement of objectives. Addresses how internal and external factors combineand interactto influence the risk Assessment Allows an entity to understandthe extent to which potential events might impact objectives. Assesses risks from twoperspectives:- Likelihood-Impact18 Risk Assessment Employs a combination of both qualitativeand quantitativerisk assessment Response Identifiesand evaluatespossible responses to risk. Evaluates optionsin relation to entity s risk appetite, cost vs.
6 Benefit of potential risk responses, and degree to which a response will reduce impact and/or Activities Policiesand proceduresthat help ensure that the risk responses, as well as other entity directives, are carried out. Occur throughoutthe organization, at all levelsand in all functions. Include applicationand generalinformation technology Managementidentifies, captures, and communicatespertinent information in a formand timeframethat enables people to carry out their responsibilities. Communication occurs in a broadersense, flowing down, across, and upthe & Communication22 MonitoringEffectiveness of the other ERM components is monitored through: Ongoing monitoring activities. Separate evaluations. A combination of the two. 23 Internal ControlA strong system of internalcontrol is essential to effectiveenterprise risk management. This ERM Framework does not replacethe earlier Framework on Internal control, but Roles & Responsibilities Management The board of directors Risk officers Internal auditorsThere is now a CROC hief Risk Officer, in addition to CEO, COO, CFO & CIO.
7 25 Environmental risks Capital Availability Regulatory, Political, and Legal Financial Markets and Shareholder RelationsProcess risks Operations Risk Empowerment Risk Information Processing / Technology Risk Integrity Risk Financial RiskInformation for Decision Making Operational Risk Financial Risk Strategic RiskExample: Risk Model26 Key questions: What risks will the organization not accept? ( environmental or quality compromises) What risks will the organization takeon new initiatives? ( new product lines) What risks will the organization acceptfor competing objectives?( gross profit vs. market share?)DETERMINE RISK APPETITE27 Quantificationof risk exposure Optionsavailable:- Accept = monitor- Avoid = eliminate (get out of situation)- Reduce = institute controls- Share = partner with someone ( insurance)IDENTIFY RISK RESPONSES28 Impact vs. ProbabilityControlShareMitigate & ControlAcceptHigh RiskMedium RiskMedium RiskLow RiskLowHighHighIMPACTPROBABILITYCOSO ERM 2017 Enterprise Risk Management Integrating with Strategy and Performance 29 New COSO-ERM 201730 Questions Why update the 2004 ERM Integrated Framework?
8 Enterprise Risk Management Integrating with Strategy and Performance Update Approach31 What are key changes? Adopt a structure of components and principles Simplify the definition of ERM32 Key Changes Is the adoption of the Framework mandatory? How does the Updated Framework relate to COSO s 2013 Internal Control Integrated Framework?33 Key changes Emphasizes the relationship between risk and value Focus on the integration of ERM34 Key Changes Examine the role of culture Elevate discussion of strategy35 Key Changes Enhance the alignment between performance and ERM ERM and Internal Control36 ERM 20041. Internal Environment2. Objective Setting3. Event Identification4. Risk Assessment5. Risk Response6. Control Activities7. Information and8. CommunicationMonitoringERM 20171. Governance and Culture2. Strategy & Objective-Setting3. Performance4. Review & Revision5. Information, Communication & Reporting37 COSO ERM 2017 COSO Internal Control Framework 2013 3839 COSO 2013 COSO Overview Internal control publications199220062009201340 Internal Control - Integrated Framework 2: 1: 3: * COSO.
9 The Committee of Sponsoring Organization of Treadway Commission41 Original FrameworkCOSO s Internal Control Integrated Framework (1992 Edition)Refresh ObjectivesUpdated FrameworkCOSO sInternal Control Integrated Framework (2013 Edition)Broadens ApplicationClarifies RequirementsArticulateprinciples to facilitate effective internal control Why update what works The Framework has become the most widely adopted control framework worldwide. Updates ContextEnhancements Reflect changes in business & operating environmentsExpandoperations and reporting objectives42 Control EnvironmentRisk AssessmentControl ActivitiesInformation & CommunicationMonitoring ActivitiesUpdate articulates principles of effective internal control1. Demonstrates commitment to integrity and ethical values2. Exercises oversight responsibility3. Establishes structure, authority and responsibility4. Demonstrates commitment to competence5. Enforces accountability6.
10 Specifies suitable objectives7. Identifies and analyzes risk8. Assesses fraud risk9. Identifies and analyzes significant change10. Selects and develops control activities11. Selects and develops general controls over technology12. Deploys through policies and procedures13. Uses relevant information14. Communicates internally15. Communicates externally16. Conducts ongoing and/or separate evaluations17. Evaluates and communicates deficiencies43 1. (Control Environment2. (Risk Ass3. (Control Activites)4. (Information & Communication) 5. (Monitoring Activities)44 1. 2. 3. 454.))