This lesson examines the application of internal controls in managing enterprise and strategic risks, with a specific focus on cyber risk. It explores how internal controls are used to identify, assess, and mitigate risks, and how they contribute to the overall governance framework. This is a key area of the CIMA P3 syllabus, which includes internal controls for risk management and cyber risk as separate topics .

  • Internal Controls as a Risk Management Tool: Internal controls are the primary mechanism for managing risks. They are the policies and procedures that are put in place to mitigate identified risks and ensure that the organisation can achieve its objectives. The risk assessment component of the COSO framework is the starting point for identifying the risks that need to be controlled. The control activities component is where the specific controls are designed and implemented .

  • Strategic Risk and Governance: Strategic risk is a key focus of the CIMA P3 syllabus, covering “where strategic risks emanate from, how to evaluate them and understand how oversight of these risks is critical to the governance of the organisation” . Internal controls play a critical role in strategic risk management by ensuring that the organisation’s strategy is aligned with its risk appetite and that there are controls in place to monitor and manage the risks associated with strategic decisions. This includes governance risks and risks to the strategic direction .

  • Cyber Risk Management: The CIMA P3 syllabus explicitly identifies cyber risk as a key area for internal controls . Cyber risk refers to the risk of financial loss, disruption, or damage to an organisation’s reputation resulting from a failure of its information technology systems. Internal controls for cyber risk include both preventive controls (firewalls, access controls, encryption) and detective controls (intrusion detection systems, security monitoring). The COSO framework can be applied to cyber risk by ensuring that the risk assessment component considers cyber threats and that the control activities include appropriate cybersecurity measures.

  • Use of Other Frameworks: While COSO’s frameworks are the gold standard for reliable reporting, organisations may also use other frameworks to supplement their internal control systems. For example, COBIT (Control Objectives for Information and Related Technology) is a framework developed by ISACA that focuses on IT governance and management, recognising that information is a resource for organisations . ITIL (Information Technology Infrastructure Library) is a framework for IT service management that is widely followed as a standard in Europe . The use of these frameworks can help organisations address the increasing complexity of technology-enabled processes .

  • Â