Control Intelligence

AI Analysis Results

Enterprise Risk AssessmentEntity-Level Controls (COSO ELC)

Back to Sub-Process
58
/ 100
Needs Improvement
Overall Sub-Process Rating
Needs ImprovementControl is partially in place or inconsistently operated.
1 control evaluated3 strengths identified3 gaps identified
Executive Summary

The Enterprise Risk Assessment process exhibits controls that are partially in place or inconsistently operated. Several gaps in design effectiveness and operating consistency were identified that, if left unaddressed, could elevate residual risk beyond the organization's tolerance. Prompt remediation is recommended.

Strengths
  • An annual enterprise risk assessment drives the SOX... has been partially implemented
  • Management review is performed on a regular cadence
  • Exception reporting is generated and reviewed timely
Gaps
  • No automated alerting for control threshold breaches
  • Monitoring controls are not formally documented or tested
  • Evidence of review lacks timestamp and reviewer identity
Recommendations
  1. 1Implement a workflow tool that captures reviewer identity and timestamp for all approvals
  2. 2Develop a remediation tracker with defined SLAs and escalation paths
  3. 3Establish a quarterly monitoring schedule with documented results and sign-off
Framework Mapping
COSO 2013
Principle P6Principle P7Principle P8Principle P9
SOX 404
ICFR.ELC.RA.01
IIA Standards 2024
IV.9.1

Control-Level Breakdown (1)

ELC-RA-01AdequateScore: 67/100
An annual enterprise risk assessment drives the SOX and internal audit plans.
Key Finding

The control is in place and generally operating as intended. An annual enterprise risk assessment drives the SOX and internal audit plans. Minor documentation or timeliness gaps were noted but do not represent material risk.

Recommendation

Enhance documentation and monitoring for: an annual enterprise risk assessment drives the sox and internal audit plans. Ensure review evidence includes timestamps and reviewer identity.

Framework Tags
COSO P6COSO P7COSO P8COSO P9ICFR.ELC.RA.01IIA IV.9.1