Do you use COSO ERM for Sarbanes Oxley? 996



  • What about ERM? Do you use it?



  • ERM is not mandatory for SOX compliance, and implementing ERM is no small undertaking. You need time, money and commitment to culture change and all are typically in short supply at most companies. %0A Enterprise Risk Management %0A’Enterprise’ means an elimination of functional, departmental or cultural barriers. To move from the current fragmented risk management approach to the enterprise wide approach. To identify correlations of risks that may be overlooked in a single-focused risk management framework. Not easy at all.%0AThat is why only 10-15% of companies needing to comply with Sarbanes Oxley, (and being busy satisfying the requirements of Sarbanes-Oxley) are implementing ERM.%0AERM is the next step for many companies. Compliance with Sarbanes-Oxley lays a foundation for implementing Enterprise Risk Management (ERM) capabilities.



  • Hi,
    Though COSO is the most popular framework available for Sarbanes Oxley internal control evaluation, there are other control frameworks also available like CoCo from canadian institute of chartered accountants, Kontrag which is a framework used in germany and so on.
    Over a period of time, COSO has however become the most popular and accepted framework. It is endorsed by many professional organizations. Hope this helps.
    Regards
    big4guy



  • Lekatis- I agree with you about ERM being the next step for companies.
    James Bruno- Here is a link to more information about ERM:

    The webinar is also very helpful.



  • Let’s not forget that implementing an ERM based on COSO’s ERM framework generates a lot of consulting fees for internal control and risk consultants. This may be just the latest management or consultant’s fad after lean management, business process engineering, total quality management, etc.
    An analysis of the type of internal control framework used by the management of UK, German, French, Italian, Dutch, Swiss and Austrian issuers for the assessment of the effectiveness of internal control over financial reporting (i.e. from their annual reports on form 20-F) shows that only three issuers use a different framework than COSO’s internal control - integrated framework. British Petroleum and the British Telecom use the Turnbull framework and HSBC Holdings uses both COSO’s internal control - integrated framework and Turnbull.
    In conclusion, the use of other control frameworks for SOX assessments of internal control over financial reporting is extremely rare among European foreign private issuers.



  • TeganZimm - could you post up that link again, just do www (dot) and then the rest of the address…not sure why the admin didn’t do that for you for your first post.
    Anyway, ERM is big in the financial industry sector, but all the other sectors are lagging behind. Since there isn’t much more than concepts freely available, it’s very hard to benchmark or even generate ERM for non-financial industry companies. Definitely going to be a huge area for personal growth for myself. I’m spearheading our ERM project at my company.
    Anyway, if anyone else is involved in ERM, I’d love to bounce some ideas around and benchmark with anyone who’d be interested.


Log in to reply