COSO框架仍有待完善
Why the COSO frameworks need improvement
来源:天和网
核心提示:鉴于COSO框架的广泛使用,作者详细分析COSO两个框架的缺陷,说明了发展框架的必要性。
By Matthew Leitch; first appeared on in March 2005
天和网天和财务频道消息:作者为马修•雷奇,首次发表于2005年3月。
• Identifies specific problems with the Evaluation Tools of COSO's internal control framework.
• And more problems with COSO's ERM framework
•识别COSO内部控制框架中评估工具的具体问题。
•更多的COSO企业风险管理(ERM)框架问题
I can’t think of a document that has had more influence on thinking about internal control than COSO’s internal Control-Integrated Framework. It is endlessly quoted and paraphrased in control and governance documents for different sectors and has recently become the de facto standard for controls over financial reporting thanks to the SEC’s interpretation of the Sarbanes-Oxley Act 2002. Thousands of people have written hundreds of thousands of pages about their internal controls using formats taken from this framework.
考虑到内部控制文件时,我想不出有比COSO的内部控制-综合框架更有影响力的文件。不同部门的控制和监管文件中不断地引用和转述这一文件,由于美国证券交易会对萨班斯 - 奥克斯利法案2002的解释,此框架最近已成为事实上的控制财务报告标准。成千上万的人已经写了很多有关使用该框架中的格式进行内部控制的文章。
More recently COSO has published enterprise Risk Management Integrated Framework which some are already calling COSO II. This looks set to be as influential as the internal control framework.
最近,COSO发布了企业风险管理综合框架,有些人称其为COSO II。这样看起来和内部控制框架一样有影响力。
So, even quite small technical weaknesses in these documents could have huge practical implications.
所以,这些文件中的技术缺陷即使非常小都可能产生巨大的实际影响。
In this article I will show that weaknesses do exist and they are far from small. The practical implications are huge and we need to press for improvements with the minimum of delay.
在这篇文章中,我将说明COSO框架中确实存在缺陷,而且完全不算小缺陷。其实际影响是巨大的,我们迫切需要尽可能减少耽搁时间来改进此框架。
What’s wrong with COSO’s internal control framework?
COSO的内部控制框架有什么问题?
COSO’s internal control framework was an exciting breakthrough in internal control thinking. Suddenly internal controls became a system instead of just a list of objectives or controls. There were definitions that expanded and defined the concept in an exciting new way.
COSO内部控制框架在内部控制思想方面是令人兴奋的一大突破。内部控制突然成为一个系统,而不仅仅是一个目标或控制列表。此框架扩展了内部控制的定义,并用令人兴奋的新方式定义了内部控制概念。
At the time it seemed a great step forward but with the benefit of time and experience we can see the practical implications of some of its conceptual weaknesses.
当时,这似乎是很大的进步,但随着时间推移以及我们的经历,我们可以看到其部分概念上的缺陷产生的实际影响。
The definition of internal control is so wide that almost every aspect of management is arguably part of management control. The definition reads:
Internal control is broadly defined as a process, effected by an entity's board of directors, management and other personnel, designed to provide reasonable assurance regarding the achievement of objectives in the following categories:
• Effectiveness and efficiency of operations.
• Reliability of financial reporting.
• Compliance with applicable laws and regulations.
内部控制的定义非常广,几乎管理的每个方面都可以说是管理控制的一部分。内部控制的定义如下:
内部控制被广泛定义为一个过程,受实体的董事会、管理人员和其他人员的影响,旨在为实现以下类型的目标提供合理的保证:
•操作的有效性和效率。
•财务报告的可靠性。
•遵守适用的法律和法规。
When the internal control framework was launched its most ardent supporters (in Coopers & Lybrand for example) saw it as a complete guide to management. The idea was that for business success you just define some objectives and the rest is internal control.
当该内部控制框架推出时,其最热心的支持者(例如,永道国际会计公司)将其视为一个完整的管理指南。当时的想法是,对于商业成功,你只需要定义一些目标,剩下的就是内部控制。
The framework divided risks into three categories: operational, financial reporting, and first this seems clear enough, but what about financial reporting that must be reliable to be compliant? Where do you draw the line between data processing for doing business and data processing for financial reporting?
该框架将风险分为三大类:营运风险,财务报告风险以及合规风险。起初,这看起来够清晰,但必须可靠且符合规定的财务报告怎么样呢?你在什么地方划定经营业务的数据处理和财务报告的数据处理之间的界限呢?
Most confusing of all for most people are the five components of internal control. The control activities component is straightforward enough but who can honestly say they aren’t just a tiny bit hazy on information and communication, monitoring, risk assessment, and of course control environment?
对于大多数人来说最令人困惑的是内部控制的五个组成要素。控制活动要素很简单,但谁能诚实地说,他们对信息和交流、监测、风险评估以及控制环境这五要素的理解,不仅仅是一点点的不清楚?
All these problems are minor compared to a part of the framework that isn’t even mentioned in the executive summary. One of the books in the COSO set is called the Evaluation Tools. It includes a large number of illustrative control matrices showing what controls might be in place for every major process in a typical business. In effect these matrices are lists of control objectives, with controls next to them.
与执行摘要中没有提到的部分框架内容相比,所有这些问题还是次要的。COSO系列书籍中有一本书叫做评估工具。其中包含了大量解说性的控件矩阵,用来表现典型业务的每个主要过程中可能有什么合适的控件。实际上,这些矩阵是控制目标的列表,以及随后的控件。
This format has been taken up by auditors and companies desperate to comply with s404 of the Sarbanes-Oxley Act 2002 ,so there are already hundreds of thousands of such matrices around the world.
为了遵守萨班斯-奥克斯利法案2002的404条,审计师和公司不顾一切地采用这种格式,所以世界各地已经有成千上万个这样的矩阵了。
And that’s a pity because, for reasons I will now explain, the format is unreliable and impractical. When COSO’s internal control framework was written and consultation was in progress who at that time had any inkling of the use to which these matrices might be put? How many reviewers had the interest or patience to even comment on them?
这是件遗憾的事情,我现在要解释其原因,因为该格式是不可靠而且不切实际的。在编写COSO的内部控制框架过程中,以及进行磋商时,那时有谁或多或少暗示了这些矩阵的可能用途了吗?有几个评论者甚至还有兴趣和耐心评论这些矩阵?
If people had known at the time what use would be made of these matrices, I don’t think they would have been published, at least in their current form.
如果人们当时已经知道用这些矩阵能做什么,我认为就不会发布这些矩阵,至少在其当前形势下不会发布。
Those matrices
那些矩阵
Unless you use a computer system that can display controls in other ways too ,the COSO matrix will produce the following problems:
• Gaps in control objectives. The COSO matrices are based on abstract models of business processes with no concrete details about the systems or people involved. In reality a process like raise a bill may be split across half a dozen computer systems and a vast number of interfaces. There is massive scope for missing controls and this is not visible on the COSO matrices. Beyond this, there is no consistent framework by which the objectives are derived and which gives assurance that the objectives are complete.
• No usable list of controls. Controls are noted on the matrix, but not all controls and not just once. Many controls will appear more than once because they address more than one objective. In practice it is common to find that the same control appears with different wording. De-duplication is not easy.
• Systematic understatement of controls. The duplication tends to deter people from writing a control down every time it applies to an objective/risk. Consequently, the extent of control is systematically understated. In fact control systems tend to be multi-layered and there are certain controls that apply across very many control objectives. To appreciate the control system’s design we need to see that structure.
• Gaps in controls. Many controls are not mentioned at all, nor is their absence visible. I have conducted several experiments where I have rewritten COSO style matrices in a form that structures the controls into different types and this has always shown large gaps in the control structure documented, usually important.
除非你使用的计算机系统可以以其他方式显示控制,否则COSO矩阵会产生以下问题:
•控制目标的缺口。 COSO矩阵是基于业务流程的抽象模型,没有涉及系统或人的具体细节。在现实中,这样的过程像提出一项法案一样,可能会在半打计算机系统中被分割,产生大量的接口。消失的控制范围相当大,在COSO矩阵中看不到这些内容。除此之外,没有可以衍生出目标以及保证完成目标的一致框架。
•没有可用的控件列表。矩阵中标注了控件,但并非所有的控件都标注了,而且这种情况不只一次。许多控件会出现不止一次,因为他们要解决一个以上的目标。在实践中经常能发现,相同的控件会出现不同的用语。删除重复不是件容易的事。
•轻描淡写的控制系统。重复往往阻止人们每次将控件用于目标/风险时就记录该控制的行为。因此,系统上低估了控制的程度。事实上,控制系统往往是多层次的,有某些控件适用于很多的控制目标。为了理解控制系统的设计,我们需要看到那个结构。
•控件的缺口。许多控件根本没有被提到,或者看不到他们的“缺席”。我已经进行了多次实验,我重写了COSO式矩阵,将控件构造为不同类型,结果一直显示文件控制结构有较大的缺口,通常是很重要的缺口。
In short, COSO matrices are very hard to review properly, are rarely of good quality, and don’t give a usable list of sooner this situation is corrected the better. The most practical thing to do in the short term is simply to remove the Evaluation Tools from the framework.
总之,COSO矩阵是很难正确审查,很少出现好质量的情况,并且没有提供一个可用的控件列表。这种情况越早纠正越好。在短期内要做的最实际事情只能是将该评估工具从框架中删除。
What’s wrong with COSO’s ERM framework?
COSO的企业风险管理框架有什么问题?
COSO is to be congratulated on a document that was produced with public consultation and tries hard to recognise a wide variety of alternative ways to manage risk. It shows great knowledge of risk management techniques and contains many interesting examples.
该文件参考了公众磋商意见,并努力识别很多种其他的管理风险方法,在这点上应该祝贺COSO。它显示出极好的风险管理技术和知识,并且包含了许多有趣的例子。
Unfortunately, with two volumes totalling 246 pages, it is so large that it is hard to see how every part of it can have received adequate comment during the consultation phase. Although the published documents reveal that there were 78 responses to the consultation the responses themselves have not been made public so we cannot know how much of the documents was seriously considered.
遗憾的是,COSO有两卷共246页,它是如此庞大,以至于很难看到在磋商阶段中其每一部分是如何能被充分解释的。公布的文件显示,有78个回应意见并没有被公开,所以我们无法知道这些文件中有多少内容是经认真考虑过的。
My impression of the two volumes is that there are a lot of ideas there that are new or different from usual practice, and some distinctions that will not be understood by most readers. For example, many people will not notice on initial reading that risk tolerances do not relate to risks (because there is no element of uncertainty). The distinction between risk responses and control activities will also be confusing.
这两卷给我的印象是,其中有很多想法是新的,或者有别于惯常做法,有些区别大多数读者都不理解。例如,许多人在第一次阅读时不会注意到风险承受能力不涉及到风险(因为没有不确定性的因素)。风险应对和控制活动之间的区别也是令人困惑的。
In short, the ERM framework is far too big for a first version. Not surprisingly, it contains some obvious technical flaws.
总之,COSO企业风险管理框架的第一个版本是太庞大了。毫不意外,它还有一些明显的技术缺陷。
For example, although keen to talk about opportunities it doesn’t have the logic worked out properly and the crucial paragraphs on what to do with them are unclear. For example, the document explains that if an event happens that is favourable then this is an opportunity that is sent to strategic planning so that plans can be made to take the opportunity. There is no such comment on what happens if an event happens that is unfavourable. Does that mean plans are left unchanged?
例如,虽然热衷于谈论机会,但它并没有制定出正确的逻辑关系,涉及如何利用机会的关键段落也不清楚。例如,文件中解释说,如果发生了有利的事件,然后就将其纳入在战略计划范围,那么计划就能利用这一机会。文件中没有评论如果发生不利的事件会产生什么情况。是否意味着保持计划不变?
The crucial paragraphs on what happens to upside risks are unclear. My best guess is that some get taken out of risk management to be looked at elsewhere, while others stay in risk management. This appears to exclude the possibility of integrated uncertainty management that deals with both unexpected good and bad events in one approach.
涉及上升风险发生的情况的关键段落也不清楚。我最好的猜测是,有些内容不在风险管理版块,需要在其他地方找,而其他内容是在风险管理版块里的。这似乎排除了综合不确定度管理用一种方法同时处理意外的好事件和坏事件的可能性 。
Another problem is the many examples of rating risk items for their probability and impact.
另一个问题是评级风险的项目,其可能性和影响的例子很多。
When risk register items are rated using (1) a number for probability of occurrence, and (2) a number for impact on occurrence, their risk is systematically understated. It is hard to see the problem when ratings are as rough as High/Medium/Low, but when numbers are given the fault is obvious.
使用(1)风险发生的概率数,和(2)风险发生的影响数来评估风险登记项目时,其风险被系统地低估了。当风险级别简单地被分为高/中/低时,很难看到这一问题,但当给出数字时错误就很明显了。
Imagine that at an early stage in a project the risk of overspend due to client originated changes was rated as Probability = and Impact = 10m. By this method the possibility of an impact other than 10m has been excluded and we should be particularly concerned that the risk of impact greater than 10m has disappeared from view.
试想一下,在项目的早期阶段由于客户端引起的变化导致风险超支,风险被评为概率= ,影响= 10M。这种方法就排除了影响不等于10m的可能性,我们应该特别关注的是从视野中消失的影响大于10m的风险。
For an item like this there may well be a 20% chance of an overspend of more than 15m, for example, and this is obviously something people need to know!
对于这样的项目,例如超过15m的机会可能是20%,这显然是人们需要知道的东西!
The framework is also overly narrow, something else that would have been less likely to happen with a shorter document. For example:
• The framework effectively excludes use of risk management methods that do not involve explicit event identification and risk assessment. In practice most risk responses are put in place without explicit event identification and risk assessment, and this is an efficient and reliable approach.
• The framework has no place for methods of designing risk responses that do not involve writing responses against a list of risks. This unnatural method leads to piecemeal design. Would an architect design a building by listing the required windows, doors, and walls? Hardly. This way leads to rooms without doors, walls that do not join up, and main entrances that open directly into the kitchens.
• The framework is written on the basis that risk management is a way to be more confident of reaching objectives that are givens. (Yes, I know it acknowledges that risk management is not a linear thought process, but having done so it goes on for hundreds of pages as if it is.) Uncertainty should be considered in setting and revising objectives.
该框架也过于狭隘,较简短的文件就不太可能发生一些其他的问题。例如:
•该框架有效地排除使用不涉及明确事件识别和风险评估的风险管理方法。在实践中,大多数风险反应处于没有明确事件识别和风险评估的状态,这是一个高效、可靠的方法。
•该框架有没有地方设计不涉及编写的一个列表对风险的反应的风险应对措施的方法。这种反常的方法会导致头痛医头,脚痛医脚的设计。一个建筑师会通过列出所需的窗户、门和墙来设计建筑吗?几乎没有。这种方法会导致出现房间的门和墙没有连接,主要入口直接开向厨房。
•该框架编写的基础是:风险管理是一种更有信心达到既定目标是的方式。 (是的,我知道它承认风险管理不是一个线性的思维过程,但这样做数百个页面,如果它是。)在制定和修改目标时应该考虑不确定性。
Should we tolerate a document with the influence of COSO’s framework containing logical flaws and being excessively prescriptive? The current version says that the Internal Control framework remains the document for internal controls assessment (. for Sarbanes-Oxley purposes) but the ERM framework is clearly designed to supersede it one day. Sooner or later we will face the prospect of the ERM framework having virtually the same status as law.
我们是否应该容忍受COSO框架影响,并存在逻辑缺陷和规定多度的文件呢?目前的版本说,内部控制框架仍然针对内部控制评估的文件(即以萨班斯 - 奥克斯利法案为目的),但设计企业风险管理框架的目的显然是要在将来取代它。我们迟早将面临的前景是,企业风险管理框架具有几乎相同的法律地位。
What now may seem trivial theoretical gripes will in time emerge as major barriers to spreading the word about the benefits of great risk management.
现在可能看起来微不足道的理论性抱怨,最后将成为传播风险管理好处的主要障碍。
Conclusions
结论
COSO’s internal control framework urgently needs updating, and the Evaluation Tools in particular should be removed until something better is available.
COSO内部控制框架迫切需要更新,特别是应该删除评估工具,直到有更好的评估工具时再使用。
The ERM framework is new but before it becomes the basis for some future regulatory paper-chase we should press for it to become shorter, more open, and less flawed.
企业风险管理框架是新的,但在成为未来争相追逐的监管文件基础之前,我们应该精简它,使其变得更开放,缺陷更少。
译者:孙亚琦
文章来源:
PAGE
PAGE 2