risk
Weak internal control environment enabling fraud and error
Because the internal control environment is weak - segregation of duties absent, authorization frameworks inadequate, and tone at the top poor - fraudulent and erroneous transactions can be initiated and concealed, resulting in material misstatement and financial, regulatory, and reputational loss.
Record JSON · Open in map · Data retrieval guide
Catalog revision: 24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028. A connection does not establish full coverage.
Attributes
- category
- financial_reporting
- domain
- Governance, Policy & Oversight
- Financial Reporting Controls (SOX)
- Compliance, Audit & Assurance
- taxonomy
- coso-erm-risk
- inherent_rating
- high
Details
- risk_id
- gov-weak-internal-control
- category
- financial_reporting
- likelihood
- medium
- impact
- high
- inherent_rating
- high
- treatment
- mitigate
- taxonomies
- coso-erm-risk
Source
No record-specific source URL is provided.
Connections
- UC-ACCESS-15 — Design control activities over technology access mitigates Weak internal control environment enabling fraud and error
- strength
- primary
- rationale
- Selecting and developing control activities and general technology controls (COSO P10/P11) directly builds the control environment.
- UC-GOV-08 — Segregate conflicting duties and areas of responsibility mitigates Weak internal control environment enabling fraud and error
- strength
- primary
- rationale
- Segregating conflicting duties directly remedies the absent segregation of duties the risk names.
- UC-GOV-16 — Select and tailor a risk-based control baseline mitigates Weak internal control environment enabling fraud and error
- strength
- primary
- rationale
- Selecting and tailoring a risk-based control baseline with SoD and a preventive/detective mix directly builds adequate controls.
- UC-GOV-18 — Document and approve system security and privacy plans mitigates Weak internal control environment enabling fraud and error
- strength
- related
- rationale
- Maintained, approved system security plans keep each system's control set defined and current.
- UC-GOV-09 — Appoint accountable security leadership (CISO) mitigates Weak internal control environment enabling fraud and error
- strength
- related
- rationale
- Accountable security leadership with authority and resources strengthens the control environment.
- UC-AUDIT-21 — Assess control effectiveness through testing and monitoring mitigates Weak internal control environment enabling fraud and error
- strength
- primary
- rationale
- Ongoing and separate assessments of controls, with deficiencies routed for corrective action, directly detect and remediate a weak control environment.
- UC-GOV-04 — Set tone at the top: integrity, ethics, and risk-aware culture mitigates Weak internal control environment enabling fraud and error
- strength
- primary
- rationale
- Tone at the top, ethics, and an adopted code of conduct are the control-environment foundation the risk names as poor.
- UC-GOV-11 — Allocate adequate resources and budget for security mitigates Weak internal control environment enabling fraud and error
- strength
- related
- rationale
- Resourcing controls commensurate with risk enables the control environment to function.
- UC-AUDIT-16 — Communicate final engagement results to stakeholders mitigates Weak internal control environment enabling fraud and error
- strength
- related
- rationale
- Communicating results and tracking action plans meaningfully strengthens a weak control environment.
- UC-GOV-07 — Hold individuals accountable for control responsibilities mitigates Weak internal control environment enabling fraud and error
- strength
- primary
- rationale
- Holding individuals accountable for control responsibilities (COSO P5) directly strengthens the control environment.
- UC-GOV-01 — Establish and maintain the enterprise governance framework mitigates Weak internal control environment enabling fraud and error
- strength
- primary
- rationale
- The supporting management framework (structures, policies, processes, culture) operationalizes the control environment the risk finds weak.
- UC-FIN-01 — Deploy financial control activities through policies mitigates Weak internal control environment enabling fraud and error
- strength
- primary
- rationale
- Formally approved control-activity policies with assigned owners strengthen the control environment against weakness.