Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 9 pages
Other

NTU AC3104 Final Exam Summary COSO ERM Framework & Compliance Risk Management 2026 new update exam tips

Document preview thumbnail
Preview 2 out of 9 pages

NTU AC3104 Final Exam Summary COSO ERM Framework & Compliance Risk Management 2026 new update exam tips

Content preview

NTU AC3104 Final Exam Summary COSO ERM Framework & Compliance Risk
Management 2026 new update exam tips

, 1


Question One


COSO ERM Framework: Compliance Risk Management — Exam Summary


Core Definitions
Compliance Risk — possibility that violations of laws, regulations, contractual terms, standards, or internal policies
occur, causing financial/nonfinancial harm to the organisation.

ERM (COSO definition) — "the culture, capabilities, and practices, integrated with strategy-setting and its
performance, that organisations rely on to manage risk in creating, preserving, and realising value."

Risk (COSO definition) — "the possibility that events will occur and affect the achievement of strategy and business
objectives."




The 5 COSO ERM Components → 20 Principles
1. Governance & Culture (Principles 1–5)
Principle Key Idea

1. Board Risk Board oversees C&E program; direct CCO-board communication line; board
Oversight should have compliance expertise

2. Operating CCO [Chief Commercial Officer] must be independent, senior-level, peer to
Structures other executives; compliance separate from legal

3. Desired Culture Code of conduct, compliance metrics tied to performance evaluations, risk
awareness culture

4. Core Values Tone from the top cascading down; zero retaliation for reporting; consistent
discipline at all levels

5. Capable Background checks; risk-based due diligence on third parties; role-tailored
Individuals training



2. Strategy & Objective-Setting (Principles 6–9)
Principle Key Idea

6. Business CCO involved in strategy-setting; monitor internal (people/process/tech) and
Context external (regulatory/competitive) drivers

7. Risk Appetite Organisations cannot eliminate all compliance risk; appetite defined at broad
level; consider by risk type, business unit, location

Document information

Uploaded on
August 14, 2026
Number of pages
9
Written in
2026/2027
Type
Other
Person
Unknown
$13.89

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
smartzone
3.6
(622)
Sold
3425
Followers
2298
Items
14815
Last sold
7 hours ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their exams and reviewed by others who've used these revision notes.

Didn't get what you expected? Choose another document

No problem! You can straightaway pick a different document that better suits what you're after.

Pay as you like, start learning straight away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and smashed it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions