{"catalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","kind":"record","record":{"attributes":{"category":"financial_reporting","domain":["Governance, Policy & Oversight","Financial Reporting Controls (SOX)","Compliance, Audit & Assurance"],"inherent_rating":"high","taxonomy":["coso-erm-risk"]},"canonicalUrl":"https://controlsmap.com/?v=1&node=risk%3Agov-weak-internal-control","description":"Because the internal control environment is weak - segregation of duties absent, authorization frameworks inadequate, and tone at the top poor - fraudulent and erroneous transactions can be initiated and concealed, resulting in material misstatement and financial, regulatory, and reputational loss.","details":{"category":"financial_reporting","impact":"high","inherent_rating":"high","likelihood":"medium","risk_id":"gov-weak-internal-control","taxonomies":["coso-erm-risk"],"treatment":"mitigate"},"id":"risk:gov-weak-internal-control","mapUrl":"https://controlsmap.com/?v=1&node=risk%3Agov-weak-internal-control","sourceIds":["cobit-2019","coso-erm","coso-ic","iia-2024","iso-27001","nist-800-53","nist-csf-2","nydfs-500","soc2","sox"],"sourceUrl":null,"title":"Weak internal control environment enabling fraud and error","type":"risk"},"relationships":[{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:04d838a2ebd498b71989710ebb6e860e4c16b5116cc025be852189625f8c67c8","properties":{"rationale":"Selecting and developing control activities and general technology controls (COSO P10/P11) directly builds the control environment.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-access-15-84699cae.json","sourceId":"uc:UC-ACCESS-15","targetDetailPath":"/data/v1/records/risk-gov-weak-internal-control-7acb9117.json","targetId":"risk:gov-weak-internal-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0e550dd633dbb6dc9bc2ffe433848c5bc7afe9030aaf7c9f09c44ad32576255e","properties":{"rationale":"Segregating conflicting duties directly remedies the absent segregation of duties the risk names.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-08-187d37c0.json","sourceId":"uc:UC-GOV-08","targetDetailPath":"/data/v1/records/risk-gov-weak-internal-control-7acb9117.json","targetId":"risk:gov-weak-internal-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:0f98dfff9e7c236405279a2b7c455b809852b2e7309ed031b969fb1b5294074e","properties":{"rationale":"Selecting and tailoring a risk-based control baseline with SoD and a preventive/detective mix directly builds adequate controls.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-16-694834ac.json","sourceId":"uc:UC-GOV-16","targetDetailPath":"/data/v1/records/risk-gov-weak-internal-control-7acb9117.json","targetId":"risk:gov-weak-internal-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:2c3e20ed5fcf27ed6f8116af3fccee3c07e168c7c739011a9479932db24ddef9","properties":{"rationale":"Maintained, approved system security plans keep each system's control set defined and current.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-18-680359d2.json","sourceId":"uc:UC-GOV-18","targetDetailPath":"/data/v1/records/risk-gov-weak-internal-control-7acb9117.json","targetId":"risk:gov-weak-internal-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:377aea5cc666e9614be5df39392487bbbaee8e5260d8ee58794965c61e28b828","properties":{"rationale":"Accountable security leadership with authority and resources strengthens the control environment.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-09-3b622881.json","sourceId":"uc:UC-GOV-09","targetDetailPath":"/data/v1/records/risk-gov-weak-internal-control-7acb9117.json","targetId":"risk:gov-weak-internal-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3ca60babefbe4859cb18c547ec062fd1e55efbe54db55980034fd45c3b5fd5fa","properties":{"rationale":"Ongoing and separate assessments of controls, with deficiencies routed for corrective action, directly detect and remediate a weak control environment.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-21-6406caa4.json","sourceId":"uc:UC-AUDIT-21","targetDetailPath":"/data/v1/records/risk-gov-weak-internal-control-7acb9117.json","targetId":"risk:gov-weak-internal-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:3f20ac84d57f6fc3147a14ecb7f441b37893c6231eb7e5cfe210b41db70ae38c","properties":{"rationale":"Tone at the top, ethics, and an adopted code of conduct are the control-environment foundation the risk names as poor.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-04-849a3e91.json","sourceId":"uc:UC-GOV-04","targetDetailPath":"/data/v1/records/risk-gov-weak-internal-control-7acb9117.json","targetId":"risk:gov-weak-internal-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:461dd4eca218116bdc0824e8ae26fb2450ca2159955c714ef75a5d97ab523c5f","properties":{"rationale":"Resourcing controls commensurate with risk enables the control environment to function.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-11-a13b60d3.json","sourceId":"uc:UC-GOV-11","targetDetailPath":"/data/v1/records/risk-gov-weak-internal-control-7acb9117.json","targetId":"risk:gov-weak-internal-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:5d7ef943dc31ebf7300c980223b0ee4c4b83c958432e3347d1e13a8b329d4470","properties":{"rationale":"Communicating results and tracking action plans meaningfully strengthens a weak control environment.","strength":"related"},"sourceDetailPath":"/data/v1/records/uc-uc-audit-16-03aa1161.json","sourceId":"uc:UC-AUDIT-16","targetDetailPath":"/data/v1/records/risk-gov-weak-internal-control-7acb9117.json","targetId":"risk:gov-weak-internal-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:9301ca2d3b6247b77f710c9a4e2ab2d8e34007516a7bf2c7a06e1e0ae25041e9","properties":{"rationale":"Holding individuals accountable for control responsibilities (COSO P5) directly strengthens the control environment.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-07-2a8998f7.json","sourceId":"uc:UC-GOV-07","targetDetailPath":"/data/v1/records/risk-gov-weak-internal-control-7acb9117.json","targetId":"risk:gov-weak-internal-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:bfcbb845f0f69a2ec465c1bccfb5050a28fa0c121ce5389e36c715c1a069b2e5","properties":{"rationale":"The supporting management framework (structures, policies, processes, culture) operationalizes the control environment the risk finds weak.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-gov-01-e1e2136d.json","sourceId":"uc:UC-GOV-01","targetDetailPath":"/data/v1/records/risk-gov-weak-internal-control-7acb9117.json","targetId":"risk:gov-weak-internal-control","type":"mitigates"},{"expectedCatalogRevision":"24028ffcfc2b295fa1b08ee6caa84b765f0731b321496bf4f548c49ad2177028","id":"rel:f5b43883746d220554d0183dc6d26d938826b9d85875d2289b3f2c69534a689f","properties":{"rationale":"Formally approved control-activity policies with assigned owners strengthen the control environment against weakness.","strength":"primary"},"sourceDetailPath":"/data/v1/records/uc-uc-fin-01-bb3ef2cd.json","sourceId":"uc:UC-FIN-01","targetDetailPath":"/data/v1/records/risk-gov-weak-internal-control-7acb9117.json","targetId":"risk:gov-weak-internal-control","type":"mitigates"}],"schemaVersion":1}
