I'm the IMA's COSO Board Member. I'd like to ask this group for any feedback on the COSO Internal Control or Enterprise Risk Management Frameworks. I know this is risky because the Frameworks are written with Public Companies as the target audience, though they endeavor to provide useful information to all organizations.
Do you use the COSO IC and ERM Frameworks?
What works and what doesn't? Are any updates needed?
What additional guidance would you like to see for smaller business to enhance use of them?
Additionally, COSO is initiating a project to create a Corporate Governance Framework (CGF). Again, its target primarily US public companies when a tough choice needs to be made. There may be the opportunity to create various types of supplemental or implementation guidance. The CGF effort is just beginning, so there is no reference material. But I would welcome your thoughts about smaller businesses need in the Governance area.
Would a COSO Governance Framework be useful for smaller businesses?
What additional guidance or implementation guidance might a COSO Corporate Governance Framework need to be more applicable to smaller businesses?
Thanks for any feedback you feel inclined to provide.
------------------------------
Larry White CMA,CFM,CSCA
------------------------------