Risk Oversight
Risk Assessment and Oversight
Traditionally, audit committees have focused on understanding a company's financial reporting and the related risk management programs. Audit committees, today, have broadened their horizon to include an understanding of the broader risks affecting the company, as well as the company’s overall risk management program.
These risks may be related to the organization’s strategy, operations, and compliance with environmental, health, safety, legal, and regulatory requirements. Therefore, audit committees should develop a thorough understanding of the company's overall risk management processes across the enterprise.
There are a growing number of tools available for companies to use to support their management of enterprise risks, including risks associated with financial reporting; to assess the potential impact of risks and the degree of vulnerability; and to link risks to specific management areas and activities in the organization.
Authoritative Guidance
- Staff Audit Practice Alert No. 8, Audit Risks in Certain Emerging Markets (PCAOB, 22-page PDF file)
- Disclosure Guidance Addressing Cybersecurity Reporting Considerations (SEC)
- A Framework for Board Oversight of Enterprise Risk (CICA, 81-page PDF file)
- Board Proposes New Auditing Standards Related to the Auditor's Assessment of and Responses to Risk (PCAOB)
- COSO Enterprise Risk Management - Integrated Framework
Thought Leadership
- Sudden Death of a CEO: Are Companies Prepared When Lightning Strikes (Stanford Graduate School of Business, PDF)
- Risk Management in a Time of Global Uncertainty (Harvard Business Review, 2012/03, PDF)
- Contemporary Practices in Risk Management (The Institute of Internal Auditors, PDF)
- Risk Appetite & Tolerance Guidance Paper (Institute of Risk Management, 42-page PDF file)
- Boards and Risk: A summary of discussions with companies, investors and advisers (UK Financial Reporting Council, PDF)
- Calculated risk? The view from the boardroom (Korn/Ferry Institute, 16-page PDF file)
- Risk Oversight: Is it Broken? What are the New Expectations? (Risk OVersight, 8-page PDF file)
- Embracing Enterprise Risk Management: Practical Approaches for Getting Started (COSO, PDF)
- Developing Key Risk Indicators to Strengthen Enterprise Risk Management (COSO, 2PDF)
- Board Risk Oversight Survey Report (COSO, PDF)
- State of Enterprise Risk Management Survey Report (COSO, PDF)
- A Unified Approach to Risk Management (AICPA, PDF)
- 20 Questions Directors Should Ask about Risk (CICA, PDF)
- 20 Questions Directors Should Ask about Strategy (CICA, PDF)