Skip to main content

Risk, control and compliance

How do enterprise risk management and internal control differ?

Enterprise risk management identifies, assesses and treats the risks to an organisation’s objectives and reports them to the board. Internal control is the narrower set of processes giving reasonable assurance over financial reporting, operations and compliance. COSO publishes a framework for each, and Sarbanes-Oxley makes internal control over financial reporting a legal obligation.

What does an operational readiness review check?

An operational readiness review checks that a system, site or service can actually be run before it goes live: that procedures exist and have been rehearsed, staff are trained and rostered, support and escalation paths are staffed, monitoring and backups work, and the handover from the project to the operating team has documented owners for every task.

Guides and toolkits in this area

Browse the full course catalogue