NTU AC3104 Final Exam Summary COSO ERM Framework & Compliance Risk
Management 2026 new update exam tips
, 1
Question One
COSO ERM Framework: Compliance Risk Management — Exam Summary
Core Definitions
Compliance Risk — possibility that violations of laws, regulations, contractual terms, standards, or internal policies
occur, causing financial/nonfinancial harm to the organisation.
ERM (COSO definition) — "the culture, capabilities, and practices, integrated with strategy-setting and its
performance, that organisations rely on to manage risk in creating, preserving, and realising value."
Risk (COSO definition) — "the possibility that events will occur and affect the achievement of strategy and business
objectives."
The 5 COSO ERM Components → 20 Principles
1. Governance & Culture (Principles 1–5)
Principle Key Idea
1. Board Risk Board oversees C&E program; direct CCO-board communication line; board
Oversight should have compliance expertise
2. Operating CCO [Chief Commercial Officer] must be independent, senior-level, peer to
Structures other executives; compliance separate from legal
3. Desired Culture Code of conduct, compliance metrics tied to performance evaluations, risk
awareness culture
4. Core Values Tone from the top cascading down; zero retaliation for reporting; consistent
discipline at all levels
5. Capable Background checks; risk-based due diligence on third parties; role-tailored
Individuals training
2. Strategy & Objective-Setting (Principles 6–9)
Principle Key Idea
6. Business CCO involved in strategy-setting; monitor internal (people/process/tech) and
Context external (regulatory/competitive) drivers
7. Risk Appetite Organisations cannot eliminate all compliance risk; appetite defined at broad
level; consider by risk type, business unit, location
Management 2026 new update exam tips
, 1
Question One
COSO ERM Framework: Compliance Risk Management — Exam Summary
Core Definitions
Compliance Risk — possibility that violations of laws, regulations, contractual terms, standards, or internal policies
occur, causing financial/nonfinancial harm to the organisation.
ERM (COSO definition) — "the culture, capabilities, and practices, integrated with strategy-setting and its
performance, that organisations rely on to manage risk in creating, preserving, and realising value."
Risk (COSO definition) — "the possibility that events will occur and affect the achievement of strategy and business
objectives."
The 5 COSO ERM Components → 20 Principles
1. Governance & Culture (Principles 1–5)
Principle Key Idea
1. Board Risk Board oversees C&E program; direct CCO-board communication line; board
Oversight should have compliance expertise
2. Operating CCO [Chief Commercial Officer] must be independent, senior-level, peer to
Structures other executives; compliance separate from legal
3. Desired Culture Code of conduct, compliance metrics tied to performance evaluations, risk
awareness culture
4. Core Values Tone from the top cascading down; zero retaliation for reporting; consistent
discipline at all levels
5. Capable Background checks; risk-based due diligence on third parties; role-tailored
Individuals training
2. Strategy & Objective-Setting (Principles 6–9)
Principle Key Idea
6. Business CCO involved in strategy-setting; monitor internal (people/process/tech) and
Context external (regulatory/competitive) drivers
7. Risk Appetite Organisations cannot eliminate all compliance risk; appetite defined at broad
level; consider by risk type, business unit, location