In these 2012 COSO papers, Risk Assessment was discussed as a critical component of the ERM process.
The new guidance is of particular interest to companies with informal risk management processes that
are eager to demonstrate adequate internal controls through establishing a uniform framework of
internal controls in their organizations through ERM. One development was an expansion of the risk
assessment process flow diagram. The risk assessment process flow diagram breaks the system of ERM
implementation into six steps. The six steps are to identify risk, develop assessment criteria, assess risk,
assess risk interactions, prioritize risks and respond to risk. Especially in the early stages of ERM
implementation, the main focus of the system is on the four middle steps of the process. Developing risk
assessment criteria is a process that is unique for each firm. By spending additional time thinking about
proper risk assessment criteria, a proper tone is set for long range planning for the business. In
assessing risk interactions, greater priority may be given to the risks that impact numerous factors of the
business. This paper will critique the new guidance and suggest next steps for development