Integration and leveraging of new and existing technologies, processes and competencies into the way business is done. Read More
Identifying the different ways technology can be leveraged to create value, categorized as external or internal opportunities. Read More
Collecting and analyzing customer interaction data to gain insights about customer behavior. Read More
Marketing that uses electronic devices to convey promotional messaging and measure its impact. Read More
Which major trends are we now observing in the risk management industry? In this article, we outline five trends and discuss how they will change risk management in 2023. Read More
The process of detecting risks that could endanger a healthcare organization, its patients, personnel, or anybody else in the institution is known as risk management. Read More
2nd Floor, Tamimah Building, Al Nahdah Road, Al Wattayah, PO Box 395, Muscat 118.
Muscat, Sultanate of Oman
For organizations who wish to define internal controls driven by business objectives, COSO is the framework to follow. An organisation can use COSO to define policies, procedures and processes for the all aspects of business, thereby helping to move from people-dependent to system approach of governance that ensure ethics, integrity and protection against fraud.
Starting with business objectives, the framework allows you to define and continually improve organisational processes, with the ultimate goal of ensuring the interest of the stakeholders.
In Coral we have advised several organizations in implementing COSO, and that lead them to manage proactively enterprise risk. We have a structured approach that starts with determining the business objectives,
A typical COSO implementation involves rolling out 30+ policies across the organisation that gets measured monthly using an annual compliance plan.
COSO is supported by five supporting organizations: the Institute of Management Accountants (IMA), the American Accounting Association (AAA), the American Institute of Certified Public Accountants (AICPA), the Institute of Internal Auditors (IIA), and Financial Executives International (FEI).
We have a structured approach to determine the applicable list of risks and controls that are required to achieve SOC 2 attestation. Our approach ensures that the service organisation has adequate ‘internal controls’ over applicable security criteria, to assure any Certified Public Accountant (CPA) for issuance of SOC 2 reports.
This phase involves determining key business objectives, that will drive the COSO framework implementation.
This phase involves performing gap analysis on COSO – 17 requirements as well as defining risk and control matrix for areas that have opportunities for fraud.
This phase involves our methodology that involves distribution of objectives, risks, and control responsibility to internal stakeholders. This also includes nomination of key roles such as risk and compliance officer – who will drive the ongoing compliance. Each business function has control framework.
This phase involves tracking the client risks, documentation and self-declarations till all internal controls are adequately implemented.
This phase involves measuring internal control changes on a scale of 0-100%. This gives assurance to internal stakeholders that the processes implemented are adequate (or at risk). If there are deviations or risks identified, they are treated. We have a structured methodology for implementation.
Internal audit involved an independent verification of risk and control implementation as a project and an assurance of the ongoing program.
WhatsApp Us