Corporate governance and the information system: how a framework for IT governance supports ERM

被引:28
作者
Rubino, Michele [1 ]
Vitolla, Filippo [1 ]
机构
[1] LUM Jean Monnet Univ, Dept Econ & Management, Casamassima, Italy
来源
CORPORATE GOVERNANCE-THE INTERNATIONAL JOURNAL OF BUSINESS IN SOCIETY | 2014年 / 14卷 / 03期
关键词
Corporate governance; Internal control; IT governance; COBIT; 5; framework; COSO ERM;
D O I
10.1108/CG-06-2013-0067
中图分类号
F [经济];
学科分类号
02 ;
摘要
Purpose - The purpose of this paper is to illustrate how information technology (IT) governance supports the process of enterprise risk management (ERM). In particular, the paper illustrates how the Control Objectives for Information and related Technology (COBIT) framework helps a company reach its objectives by integrating and supporting the Enterprise Risk Management by the Committee of Sponsoring Organizations (COSO ERM) framework. Design/methodology/approach - This paper explains how the integration between the two frameworks (COSO ERM and COBIT 5) can represent, for any organization, a good way to achieve the objectives of internal control and risk management and, more generally, corporate governance. Findings - The paper identifies some gaps in the COSO ERM and illustrates how the COBIT framework facilitates the implementation of an adequate system of internal control. Originality/value - The originality of the work presented here is in analyzing the COBIT 5 together with the COSO ERM framework. This paper highlights that is not enough to apply only an internal control framework for achieving the risk management and internal control system objectives. An IT governance framework, such as COBIT 5 is proposed as a tool that support risk management in order to develop an adequate system of internal control.
引用
收藏
页码:320 / +
页数:21
相关论文
共 117 条
[1]   Information technology, an enabler in corporate governance [J].
Abraham, Sherly Elizabeth .
CORPORATE GOVERNANCE-THE INTERNATIONAL JOURNAL OF BUSINESS IN SOCIETY, 2012, 12 (03) :281-+
[2]  
[Anonymous], 2007, COB 4 1
[3]  
[Anonymous], [No title captured]
[4]  
[Anonymous], 2004, GOVERNO EC IMPRESE
[5]   Risk Management and the Global Banking Crisis: Lessons for Insurance Solvency Regulation [J].
Ashby, Simon .
GENEVA PAPERS ON RISK AND INSURANCE-ISSUES AND PRACTICE, 2011, 36 (03) :330-347
[6]  
Beasley M., 2006, STRATEGIC FINANCE, V87, P49
[7]  
Beasley M.S., 2007, J ACCOUNTING AUDITIN, V23, P311
[8]  
Beasley M. S., 2005, J ACCOUNT PUBLIC POL, V24, P521, DOI [DOI 10.1016/J.JACCPUBPOL.2005.10.001, https://doi.org/10.1016/j.jaccpubpol.2005.10.001]
[9]  
Beasley M, 2008, J ACCOUNT AUDIT FINA, V22, P311
[10]  
Beretta S., 2007, ANALISI VALUTAZIONE