top of page
Search

How Mature Is Your Risk Assessment Component? Why COSO Should Start With Objectives

The COSO Internal Control—Integrated Framework is usually presented in this order:

  • Control Environment

  • Risk Assessment

  • Control Activities

  • Information and Communication

  • Monitoring Activities


That is COSO’s formal structure.


But from a practical management and auditing perspective, there is a strong argument that


Risk Assessment should be the first component considered when evaluating how an organization manages internal control.


Why?


Because COSO’s Risk Assessment component begins with objectives.


Before management can identify risks, design controls, monitor performance, or evaluate control effectiveness, it first needs to know:

What are we trying to accomplish?

COSO explicitly states that establishing suitable objectives is a precondition to risk assessment. The framework defines risk as the possibility that an event will occur and adversely affect the achievement of objectives. Risk assessment therefore forms the basis for determining how those risks should be managed.


That creates a simple but powerful logic:

Objectives

Risks

Controls

Information

Monitoring


This is why I believe Internal Auditors should consider beginning their practical COSO analysis with the Risk Assessment component.


The Four COSO Risk Assessment Principles

COSO establishes four principles within the Risk Assessment component:


  • Principle 6 — Specify suitable objectives

  • Principle 7 — Identify and analyze risks

  • Principle 8 — Assess fraud risk

  • Principle 9 — Identify and analyze significant change.


These four principles provide an excellent structure for assessing the maturity of an organization’s risk-management process.


A practical maturity model might use five levels:


Level 1 — Initial / Ad Hoc

Level 2 — Developing / Repeatable

Level 3 — Defined

Level 4 — Managed and Measured

Level 5 — Optimized


The objective is not to force every organization to Level 5. The target maturity should reflect the significance of the organization's risks, complexity, regulatory requirements, and objectives.


But management and governance should know:

Where are we today?

and

Where do we need to be?

Principle 6: Specify Suitable Objectives

COSO Principle 6 states that the organization specifies objectives with sufficient clarity to enable identification and assessment of risks relating to those objectives.


This may be the most important principle in the entire COSO Framework.


Why?


Because risk cannot be meaningfully evaluated without an objective.


Suppose someone asks:

“What is the risk?”

The first response should be:

“Risk to what?”

Consider this objective:

Process vendor payments accurately, completely, timely, and only to authorized vendors.

Now the risks become visible:

  • Fictitious vendors

  • Duplicate payments

  • Unauthorized payments

  • Incorrect bank information

  • Fraudulent vendor changes

  • Inaccurate invoice processing

  • Late payment penalties


Only after identifying those risks can management determine what controls are necessary.


That gives us:

Objective

Risk

Control


This is why starting with the objective changes the entire internal-control discussion.


Measuring the Maturity of Objective Setting


Level 1 — Initial

Objectives are informal, vague, or assumed.


Employees may understand generally what management wants, but objectives are not clearly documented.


Examples:

“Improve Accounts Payable.”
“Protect the company.”
“Make sure financial reporting is accurate.”

These statements are too vague to support disciplined risk assessment.


Level 2 — Developing

Major organizational objectives are documented.


Some departments establish operational objectives.


However, objectives may not consistently address:

  • Operations

  • Reporting

  • Compliance

or specific risk tolerances.


Level 3 — Defined

Objectives are formally established at organizational, business-unit, and process levels.


They are sufficiently specific to support risk identification.


Management understands the relationship:


Strategic Objective

Business Objective

Process Objective

Control Objective


Level 4 — Managed

Objectives include measurable expectations.


Performance measures are linked to them.


Risk tolerances are defined.


Changes to objectives trigger reassessment of related risks and controls.


Level 5 — Optimized

Objectives are dynamically integrated into strategy, risk management, budgeting, performance management, and internal control.


When strategy changes, the risk assessment automatically changes with it.


Management routinely asks:

“Has this objective changed, and what does that change mean for our risk and control environment?”

That is a mature control system.


Principle 7: Identify and Analyze Risk

Once objectives are defined, management needs to identify what could prevent their achievement.


COSO Principle 7 requires organizations to identify risks across the entity and analyze those risks as a basis for determining how they should be managed.


This should not be a once-a-year brainstorming session.


Risk assessment should be dynamic and iterative.


COSO guidance emphasizes considering risks across the organization and relative to established tolerances.


A good risk analysis asks:

What could go wrong?
Why could it happen?
How likely is it?
What would the impact be?
How quickly could it affect us?
What controls already exist?
What residual risk remains?
Is the residual risk acceptable?

Measuring Risk Identification Maturity


Level 1 — Initial

Risks are identified primarily after something goes wrong.

Risk management is reactive.

Different departments maintain informal lists.

No common methodology exists.


Level 2 — Developing

  • Formal risk assessments occur periodically.

  • Risk registers may exist.

  • Likelihood and impact are commonly used.

  • However, risk identification is often siloed by department.


Level 3 — Defined

  • A standardized methodology exists across the organization.

  • Risks are consistently linked to objectives.

  • Risk owners are identified.

  • Inherent and residual risk are distinguished.

  • Risk tolerances are documented.


Level 4 — Managed

  • Management uses multiple risk dimensions, potentially including:

    • Likelihood

    • Impact

    • Velocity

    • Persistence

    • Control Effectiveness

    • Residual Risk

  • Key Risk Indicators are monitored.

  • Risk assessments are updated when meaningful events occur.


Level 5 — Optimized

  • Risk information is embedded directly in decision-making.

  • Management evaluates interdependencies among risks and uses analytics, scenario modeling, and emerging-risk information.

  • Risk assessment is not an annual event.

  • It operates continuously.


The mature organization asks:

“What risk is changing right now?”

rather than:

“When is the next annual risk assessment?”

Don't Confuse a Risk Register With Risk Management

Organizations sometimes produce impressive spreadsheets containing:

  • Risk

  • Owner

  • Likelihood

  • Impact

  • Rating


That is useful.


It is not necessarily mature risk management.


The real question is what happens next.


For every significant risk:

  • What response was selected?

  • What controls address it?

  • What risk remains?

  • Who monitors it?

  • What happens if exposure increases?


A risk register that nobody uses to make decisions may be a compliance artifact rather than a functioning control.


Principle 8: Assess Fraud Risk

COSO makes fraud risk explicit.


Principle 8 requires the organization to consider the potential for fraud when assessing risks to achieving objectives.


COSO and the ACFE have subsequently reinforced this emphasis through the Fraud Risk Management Guide, which provides a structured framework for organizational fraud-risk management.


This principle matters because traditional business-risk assessments sometimes understate deliberate human behavior.


A normal operational risk question might be:

“Could this process fail?”

A fraud-risk question asks:

“Could someone intentionally make this process fail—or manipulate it for personal benefit?”

That requires a different mindset.


Fraud Risk Should Consider More Than Theft

The organization should consider risks involving:

  • Asset Misappropriation

  • Financial Statement Fraud

  • Corruption

  • Bribery

  • Conflicts of Interest

  • Management Override

  • Vendor Fraud

  • Payroll Fraud

  • Cyber-enabled Fraud

  • Collusion


Fraud risk should also consider incentives, opportunities, rationalizations, and the potential ability of senior management to override controls.


Measuring Fraud Risk Assessment Maturity


Level 1 — Initial

  • Fraud risk is considered primarily after a fraud occurs.


Management assumes:

“We trust our employees.”

Fraud is largely viewed as an Internal Audit or security problem.


Level 2 — Developing

  • Fraud risk is included in periodic risk assessments.

  • Hotlines and Codes of Conduct exist.

  • Some fraud scenarios are identified.


Level 3 — Defined

  • Formal fraud-risk assessments are conducted.

  • Management maps:

Fraud Scenario

Preventive Control

Detective Control

Control Owner

  • Fraud risks are documented by business process.


Level 4 — Managed

  • Fraud controls are tested.

  • Data analytics are used to detect unusual activity.

  • Management monitors:

    • Override activity

    • Hotline trends

    • Vendor anomalies

    • Journal entries

    • Conflicts of interest

    • Fraud losses

    • Repeat issues


Level 5 — Optimized

  • Fraud-risk assessment is integrated with cybersecurity, AML, compliance, Internal Audit, HR, and enterprise-risk information.

  • Advanced analytics and AI help identify emerging fraud patterns.


The organization continually asks:

“How would someone circumvent our existing controls?”

That is a mature fraud-risk culture.


Principle 9: Identify and Analyze Significant Change

This principle may be the one organizations most frequently underestimate.


COSO requires organizations to identify and assess changes that could significantly affect the system of internal control.


Deloitte notes that COSO calls for a dynamic risk-assessment program that considers changes in business operations and adapts to internal, external, and emerging risks.

Control environments do not remain static.


Consider changes involving:

  • New leadership

  • New employees

  • ERP implementations

  • Artificial intelligence

  • Acquisitions

  • New products

  • New regulations

  • Remote work

  • Cybersecurity threats

  • Organizational restructuring

  • Outsourcing

  • Economic conditions

  • New accounting standards


Every major change can create new risks or make existing controls obsolete.


Measuring Change-Risk Maturity

Level 1 — Initial

  • Control implications are considered only after problems emerge.

  • Change management is largely operational.


Level 2 — Developing

  • Major projects include some risk analysis.

  • Compliance or Internal Audit may become involved late.


Level 3 — Defined

  • Significant changes trigger formal risk assessments.

  • Major projects require evaluation of:

    • Internal-control impact

    • Technology impact

    • Compliance impact

    • Fraud risk

    • Financial-reporting impact


Level 4 — Managed

  • Change-risk assessments are embedded in project governance.

  • Risk and control functions participate early.

  • New systems and processes are tested before implementation.

  • Control owners formally acknowledge changes to responsibilities.


Level 5 — Optimized

  • The organization actively scans for external and internal change.

  • Emerging risks are continuously evaluated.

  • Management does not wait for a major project to ask whether controls are affected.


The question becomes:

“What has changed since our last assessment that could make our assumptions or controls wrong?”

That is a powerful risk-management question.


Build a COSO Risk Assessment Maturity Scorecard


Internal Audit can turn these four principles into a simple maturity dashboard:

COSO Risk Assessment Principle

Current

Target

Gap

6. Suitable Objectives

2

4

2

7. Risk Identification & Analysis

3

4

1

8. Fraud Risk Assessment

2

4

2

9. Significant Change

1

4

3

This tells management something far more useful than:

“The Risk Assessment component needs improvement.”

It identifies precisely where the maturity gap exists.


In this example:

Management’s largest weakness is its ability to recognize and respond to significant change.

Now management has something specific to improve.


Use Evidence to Support the Maturity Rating

A maturity assessment should not be based solely on interviews.


Internal Audit should look for evidence.


For Objectives:

  • Strategic plans

  • Department objectives

  • Performance measures

  • Risk tolerances

  • Board-approved priorities


For Risk Identification:

  • Risk registers

  • Risk assessments

  • Risk-owner assignments

  • KRIs

  • Scenario analyses

  • Risk Committee minutes


For Fraud Risk:

  • Fraud-risk assessments

  • Hotline information

  • Investigation trends

  • Conflict-of-interest disclosures

  • Fraud analytics

  • Control testing


For Significant Change:

  • Project-risk assessments

  • Acquisition due diligence

  • IT implementation governance

  • Regulatory-change processes

  • Emerging-risk reports

  • Post-implementation reviews


The rating should follow the evidence.


Measure Current Maturity and Desired Maturity

This is critical.


A maturity score is not very useful by itself.


Suppose the organization receives: Risk Assessment Maturity = Level 2.7


Is that good?


Maybe.


Maybe not.


The important question is:

What maturity level does the organization need given its risk?

For a small private company, perhaps Level 3 is appropriate.


For a large SEC registrant:


Level 4 may be necessary for important financial-reporting risks.


For a heavily regulated financial institution or insurer:

certain risk-assessment processes may need to approach Level 4 or 5.


The assessment therefore becomes:

Current State

vs.

Desired State


The difference is the maturity gap.


Don't Average Away a Major Risk

As with the Control Environment maturity model, Internal Audit should avoid blindly averaging maturity scores.


Suppose:

  • Objectives — 5

  • Risk Analysis — 5

  • Fraud Risk — 1

  • Significant Change — 5


Average: 4.0


Does that mean Risk Assessment maturity is Level 4?


No.


A catastrophic weakness in fraud-risk assessment should not disappear mathematically.


Certain deficiencies should operate as gating factors.


For example, an organization should not receive a high overall Risk Assessment maturity rating if:

  • Significant fraud risks are not assessed.

  • Major strategic objectives are undefined.

  • Management has no process for assessing major organizational changes.

  • Material risks have no identified owners.

  • Risk tolerance is undefined for significant exposures.


Professional judgment matters.


Risk Assessment Should Drive Control Activities

This is where the COSO sequence becomes particularly important.


COSO Principle 10 says control activities should contribute to mitigating risks to the achievement of objectives to acceptable levels.


That means control activities logically follow risk assessment.


The relationship is:

Objective

Risk

Risk Response

Control

Control Activity

Evidence

Monitoring


This supports the argument for putting practical emphasis on the Risk Assessment component first.


You cannot intelligently design the control until you understand the risk.


And you cannot intelligently assess the risk until you understand the objective.


Why I Would Begin a COSO Review With Risk Assessment

COSO formally begins with the Control Environment, and there are good reasons for that. The Control Environment establishes the governance, integrity, competency, authority, and accountability necessary for internal control to function.


But when performing a practical assessment, I would often begin by asking management:

What are your objectives?

Then:

What could prevent you from achieving them?

Then:

What controls address those risks?

That immediately establishes the context for evaluating every other COSO component.


My practical sequence would therefore be:

1. Objectives

2. Risk Assessment

3. Control Environment

4. Control Activities

5. Information and Communication

6. Monitoring


This is not a replacement for COSO's official structure.


It is a way of using COSO more effectively as an auditing and management tool.


The Audit Committee Should Ask About Risk Maturity

Boards and Audit Committees should not receive only a list of top risks.


They should ask about the process that generated that list.


For example:

How mature is our risk assessment process?
Are organizational objectives sufficiently clear?
Who owns the significant risks?
What risks exceed tolerance?
When was the fraud-risk assessment last updated?
What significant changes have occurred since the last assessment?
What emerging risks have been added?
What risks disappeared, and why?
What does Internal Audit believe management is underestimating?

That last question can be especially valuable.


AI Can Improve Risk Assessment—But It Can Also Create Noise

AI can help management and Internal Audit:

  • Brainstorm risks

  • Analyze large volumes of information

  • Identify emerging trends

  • Compare risks across business units

  • Develop scenarios

  • Analyze historical events

  • Identify potential fraud schemes

  • Challenge assumptions


But AI can also generate huge lists of generic risks.


A 200-item AI-generated risk register is not automatically useful.


The professional still needs to connect:

Objective

Relevant Risk

Significance

Response

Control


The mature use of AI is not:

“Give me every possible risk.”

It is:

“Given this specific objective, business model, operating environment, and risk tolerance, what material uncertainties could prevent achievement, and what evidence should management examine?”

That is a much better risk prompt.


The Bottom Line: Everything Starts With the Objective

If you cannot clearly state the objective, you cannot clearly state the risk.


If you cannot clearly state the risk, you cannot intelligently select the control.


That is why COSO Principle 6 deserves far more attention.


The maturity chain is:


Level 1 — We have vague objectives and react to risks.

Level 2 — We periodically identify risks.

Level 3 — Objectives and risks are formally linked.

Level 4 — Risks, tolerances, controls and indicators are actively measured.

Level 5 — Risk assessment is embedded continuously into strategy and decision-making.


A mature Risk Assessment component should allow management to answer:

What are we trying to accomplish?
What could prevent us from accomplishing it?
Could fraud interfere with the objective?
What has changed that could alter the risk?
What level of risk are we willing to accept?
What are we doing about the remaining risk?

That is why, from a practical auditing perspective, I believe the COSO conversation should begin with:


Objectives.

Because from the objective comes the risk.


From the risk comes the control.


And from the control comes the evidence necessary to determine whether the organization is actually managing the risk.

 
 
 

Recent Posts

See All
How Mature Are Your Monitoring Activities?

Measuring Whether Management Knows When Internal Controls Stop Working Every organization has internal controls. But here is the more difficult question: How does management know those controls are s

 
 
 

Comments


Contact Us

Please white list the email address johnb@cseminars.com to allow for CCS emails to reach you effectively.

Thanks for submitting!

Corporate Compliance Seminars is registered with the National Association of State Boards of Accountancy (NASBA) as a sponsor of continuing professional education on the National Registry of CPE Sponsors. State boards of accountancy have final authority on the acceptance of individual courses for CPE credit. Complaints regarding registered sponsors may be submitted to the National Registry of CPE Sponsors through its website: www.nasbaregistry.org.

In accordance with the standards of the National Registry of CPE Sponsors, CPE credits are granted based on a 50-minute hour.

National Registry of CPE Sponsors ID #108983

Complaints may also be forwarded to the company principals, David S. Marshall (708-205-2366davem@cseminars.com) and/ or John Blackshire (479-200-4373johnb@cseminars.com)

 

bottom of page