【正文】
s risk assessments and the internal controls. ? Providing advice in the design and improvement of control systems and risk mitigation strategies. ? Implementing a riskbased approach to planning and executing the internal audit process. ? Ensuring that internal auditing’s resources are directed at those areas most important to the anization. ? Challenging the basis of management’s risk assessments and evaluating the adequacy and effectiveness of risk treatment strategies. Internal auditors can add value by: ? Facilitating ERM workshops. ? Defining risk tolerances where none have been identified, based on internal auditing39。Applying COSO’s Enterprise Risk Management — Integrated Framework September 29, 2023 Today’s anizations are concerned about: ? Risk Management ? Governance ? Control ? Assurance (and Consulting) ERM Defined: “ … a process, effected by an entity39。s board of directors, management and other personnel, applied in strategy setting and across the enterprise, designed to identify potential events that may affect the entity, and manage risks to be within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives.” Source: COSO Enterprise Risk Management – Integrated Framework. 2023. COSO. Why ERM Is Important Underlying principles: ? Every entity, whether forprofit or not, exists to realize value for its stakeholders. ? Value is created, preserved, or eroded by management decisions in all activities, from setting strategy to operating the enterprise daytoday. Why ERM Is Important ERM supports value creation by enabling management to: ? Deal effectively with potential future events that create uncertainty. ? Respond in a manner that reduces the likelihood of downside outes and increases the upside. This COSO ERM framework defines essential ponents, suggests a mon language, and provides clear direction and guidance for enterprise risk management. Enterprise Risk Management — Integrated Framework The ERM Framework Entity objectives can be viewed in the context of four categories: ? Strategic ? Operations ? Reporting ? Compliance The ERM Framework ERM considers activities at all levels of the anization: ? Enterpriselevel ? Division or subsidiary ? Business unit processes Enterprise risk management requires an entity to take a po