COSO Internal Control - Integrated Framework (2013)
Risk Assessment – COSO Internal Control - Integrated Framework (2013)

COSO Internal Control - Integrated Framework (2013) P6: Principle 6: Specifies suitable objectives

The organization sets objectives clearly enough for the risks relating to them to be identified and assessed. Points of focus (15). Operations objectives (reflecting management's choices, taking account of risk tolerances, including operating and financial performance goals, serving as the basis for committing resources): they express management's choices, state how much risk is tolerated, carry goals for operating and financial performance and form the basis on which resources are committed. External financial reporting objectives (following the applicable accounting standards, considering materiality, reflecting the entity's activities): they apply accounting principles that suit the entity, take materiality into account in presentation, and reflect the transactions and events behind them with their qualitative characteristics and assertions. External non-financial reporting objectives (following external standards and frameworks, considering the precision required, reflecting the entity's activities): they follow the standards or frameworks that govern them, to the precision users need, and reflect what the entity does. Internal reporting objectives (reflecting management's choices, considering the precision required, reflecting the entity's activities): they support management's decisions to the precision needed and reflect the entity's activities. Compliance objectives (reflecting external laws and regulations, taking account of risk tolerances): laws and regulations lay down the least the entity must do, and the entity builds this into its compliance objectives with its risk tolerance stated. Approaches the framework suggests for external financial reporting: identifying the assertions in the financial statements; setting objectives for financial reporting; judging materiality; reviewing and refreshing knowledge of the applicable standards; considering the full range of the entity's activities.

Maintained by Gerard BlokdykControl text last updated

What else in your programme already covers this

This control maps to 1 controls across 1 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

COBIT 2019 · 1 control

  • DSS06.01 DSS06.01 Align control activities embedded in business processes with enterprise objectives

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Other controls in Risk Assessment – COSO Internal Control - Integrated Framework (2013)

Query this from an agent

The graph holds this control, the 1 it maps to, and the evidence behind each claim, over MCP and REST.