Skip to Content
Governance, Risk, and Compliance Handbook: Technology, Finance, Environmental, and International Guidance and Best Practices
book

Governance, Risk, and Compliance Handbook: Technology, Finance, Environmental, and International Guidance and Best Practices

by Anthony Tarantino
March 2008
Intermediate to advanced
1127 pages
33h 30m
English
Wiley
Content preview from Governance, Risk, and Compliance Handbook: Technology, Finance, Environmental, and International Guidance and Best Practices

CHAPTER 2

A RISK-BASED APPROACH TO ASSESS INTERNAL CONTROL OVER FINANCIAL REPORTING (ICFR)

Tim J. Leech, FCA-CIA-IT, CFE, CCSA

Jeffrey C. Thomson, MS

2.1 A RISK-BASED APPROACH TO ASSESSING ICFR

(a) Introduction

2.2 DETERMINE KEY STAKEHOLDERS

2.3 ESTABLISH THE RISK MANAGEMENT CONTEXT

(a) General

(b) Risk Criteria—Big Picture Corporate Level

(c) Risk Criteria—Subsidiary Level

(d) Risk Criteria—Account/Note Disclosure Level

2.4 RISK RATING AND RISK IDENTIFICATION

(a) Risk Rating Assurance Contexts for ICFR

(b) Identifying Risks to Assurance Contexts Selected for Additional Analysis

2.5 ANALYZE AND EVALUATE RISKS

2.6 TREAT/MITIGATE RISKS

(a) Treat Risks Using COSO 1992 Control Criteria

(i) Using COSO 1992 for Control Criteria Centric Assessments

(ii) Using COSO 1992 for Risk-Based ICFR Assessments

(b) Treat Risks Using CARD®model, a COSO-Linked Framework

(c) Treat Risks Using COBIT/ISO 17799/ITIL

(d) Treat Risks Using the OCEG Foundation Framework

2.7 IDENTIFY, ASSESS, AND REPORT ON RESIDUAL RISK STATUS

(a) Types of Residual Risk Status Information

2.8 CONCLUDING REMARKS

NOTES

Note: This guide is a condensed version of a more comprehensive Institute of Management Accountants (IMA) discussion paper titled "A Global Perspective on Assessing Internal Control over Financial Reporting" circulated for comment globally and filed with the SEC in September 2006. The full text can be found at www.imanet.org/pdf/IMAmanagementguidancetoSEC906.pdf.

2.1 A RISK-BASED APPROACH TO ASSESSING ICFR

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Information Governance, 2nd Edition

Information Governance, 2nd Edition

Robert F. Smallwood
Enterprise Risk Management, 2nd Edition

Enterprise Risk Management, 2nd Edition

John R. S. Fraser, Rob Quail, Betty Simkins

Publisher Resources

ISBN: 9780470095898