Question

ERM specialists should not have the authority and responsibility to both identify specific enterprise risks and...

  1. ERM specialists should not have the authority and responsibility to both identify specific enterprise risks and actually help implement corrective actions to minimize those identified risks. T/F
  2. An enterprise risk function generally should be a corporate-level function with authority covering the entire enterprise. T/F
  3. A Risk Assessment Review (RAR) is designed to improve on the risk environment and enhance internal controls. T/F
  4. After existing in a published draft form for some time, the Committee of Sponsoring Organizations’ enterprise risk management (COSO ERM) became “official” in very late 1999. T/F
  5. An ERM specialist with strong IT skills may assess system access vulnerabilities in the firewall perimeter surrounding an area of IT network operations. T/F
  6. The Institute of Internal Auditors’ (IIA) professional standards do not allow internal auditors to act as consultants as well as reviewers. T/F
  7. The development and release of International Organization for Standardization (ISO) guidelines standards is usually a rapid process involving minimal levels of documented controls and procedures. T/F
  8. Auditing software packages provide many ways to present and display your results, such as ACL’s “Crystal Reports.” T/F
  9. COSO internal controls were launched before the pervasive use of Internet technology and applications. T/F
  10. Analytical skills are not required when carrying out an auditing project if specialized auditing software is used. T/F
0 0
Add a comment Improve this question Transcribed image text
Answer #1

1. FALSE. Enterprise resource manager is the person who has the authority and the responsibility to identify the risks and take the corrective actions.

2. TRUE. Enterprise risk is associated with whole of the organisation. Thus it is a corporate level function.

3. TRUE. Risk assessment review is done so that the various risky areas can be identified and the corrective action can be taken.

4.FALSE. COSO ERM framework published in 1992 and amended in 1994.

5.FALSE. An ERM specialist cannot assess the system access vulnerabilities.

6.TRUE. As per IIA standards a professional cannot act in both the reviewer and consultant capacity.

7.TRUE. The ISO guidelines are the predefined standards for documented controls and procedures.

8.TRUE. Auditing software packages help to present the data in different formats and reports.

9.TRUE. COSO internal controls were launched in 1992.

10.FALSE. Analytical skills are required to carry out the audit.

Add a comment
Know the answer?
Add Answer to:
ERM specialists should not have the authority and responsibility to both identify specific enterprise risks and...
Your Answer:

Post as a guest

Your Name:

What's your source?

Earn Coins

Coins can be redeemed for fabulous gifts.

Not the answer you're looking for? Ask your own homework help question. Our experts will answer your question WITHIN MINUTES for Free.
Similar Homework Help Questions
  • The Committee of Sponsoring Organizations’ enterprise risk management (COSO ERM) framework calls for a formal and...

    The Committee of Sponsoring Organizations’ enterprise risk management (COSO ERM) framework calls for a formal and comprehensive approach to risk-based thinking and encourages internal auditors to give much more attention to risk management when planning for and performing many of their reviews. T/F The chief audit executive should establish risk-based plans to determine the priorities of the internal audit activity, consistent with the organization’s goals. T/F Internal audit departments always have sufficient time and resources to cover all their auditable...

  • A major area of concern for companies is the risks surrounding the telecommunications networks that support...

    A major area of concern for companies is the risks surrounding the telecommunications networks that support many of today’s enterprises. T/F In the United States, the American Society for Quality (ASQ), under its earlier name of American Society for Quality Control, played a leading role in setting standards and promoting best practices in quality control. T/F The risk management function may identify governmental actions that may place some foreign country operations at risk. T/F An important difference between an ERM...

  • Operations Brony’s Bikes was incorporated more than 30 years ago to manufacture ten-speed touring bikes. An...

    Operations Brony’s Bikes was incorporated more than 30 years ago to manufacture ten-speed touring bikes. An exercise bike and mountain bikes later added to the product line. Currently, the company manufactures the following products: Grand Prix:   Ten-speed touring bike Phoenix:          Deluxe eighteen-speed racing bike Pike’s Peak:     Twelve-speed mountain bike Himalaya:        Eighteen-speed deluxe mountain bike Waistliner:       Stationary exercise bike All of these products are manufactured in a single facility, which is located in eastern Texas. Derailleurs (front and rear) comprise a...

ADVERTISEMENT
Free Homework Help App
Download From Google Play
Scan Your Homework
to Get Instant Free Answers
Need Online Homework Help?
Ask a Question
Get Answers For Free
Most questions answered within 3 hours.
ADVERTISEMENT
ADVERTISEMENT
ADVERTISEMENT