7.02
Risk Assessment
Principle 7 - Identify, Analyze, and Respond to Risks
Attribute 7.02 - Management identifies risks throughout the entity on a periodic and ongoing basis to provide a basis for analyzing risks. Risk is the possibility that an event will occur and adversely affect the achievement of objectives. Risk assessment is the identification and analysis of risks related to achieving the defined objectives to form a basis for designing risk responses. Periodic risk assessments are performed at specific times and at regular intervals, such as annually. Management considers entity objectives, risk tolerances, and other factors when determining the scope and frequency of these assessments. Ongoing risk assessments are performed as needed, on a real-time basis, such as when significant internal or external change occurs or significant emerging risks are identified. Management also considers performing ongoing risk assessments when internal control deficiencies, improper payments, potential fraud, or information security breaches are detected.
>>>Navigational Buttons<<<
- Index of Attributes
- Previous Attribute - 7.01
- Next Attribute - 7.03
