Dergiler / Denetişim / 2021 / Sayı: 22

COSO BİLGİ VE İLETİŞİM BİLEŞENİNİN KALKINMA AJANSLARI ÜZERİNDEN ANALİZİ

COMPARISON OF ISO 31000 AND COSO ENTERPRISE RISK MANAGEMENT: UNDERSTANDING FRAMEWORKS

Sayfa
69–88
DOI
—

Özet

Araştırmamızda COSO çerçevesine uygun bir iç kontrol sistematiğinin uygulanması durumunda pek çok sorunun ortadan kaldırılabileceği iddia edilmektedir. Sistem teorisi ışığında kurgulanan COSO çerçevesi sadece sistem kurulmasını değil, sistemlerde dört başlık altında belirtilmiş olan iç kontrol amaçlarının beş adet iç kontrol bileşenlerine göre sağlanması amaçlanmaktadır. Plan, politika, süreç, uygulama ve fonksiyonlar bu yaklaşımla kapsanmaktadır. Buna göre; bir iç kontrol sistemi raporlamaların doğruluk ve güvenilirliğini, faaliyetlerin etkinlik ve verimliliğini, yasa ve düzenlemelere uygunluğunu ve varlıkların korunmasını elde etmesini sağlamayı hedeflemektedir. Bu çalışmada, iç kontrol amaçları sırasıyla bölgesel kalkınma ajansları (KA) dinamikleriyle ilişkilendirilerek analiz edilmektedir. 2018 yılında Cumhurbaşkanlığı sistemine geçiş süreciyle birlikte değişen kamu kurumlarının yeni yapıdaki işleyişi iç kontrol bağlamında değerlendirilmektedir. Daha sonra ise bu amaçların gerçekleştirilebilmesi için gerekli olan iç kontrol sistemi bileşenlerinden sadece bilgi ve iletişim incelenerek KA dinamiklerinde analizler yapılmakta ve çözümleyici öneriler geliştirilmektedir

Abstract

Enterprise risk management (ERM) has emerged as the new paradigm in risk management with the goal of holistically managing all risks facing an organization. Yet organizations still manage risks in a piece-meal fashion and struggle to effectively implement ERM and manage complex strategic risks. Therefore, given the devastating changes in environmental factors and the dynamic nature of the sectors, organizations must stay up-to-date with new risks and monitor ERM processes constantly. Although the issue of ERM has been extensively researched in the literature, only a few studies have focused on the analysis of frames to highlight potential implementation problems. İn this study proposes a solution to this problem; ERM implementation using a system dynamics approach, which enables integrating risks in a causal modeling environment that includes feedback and delays. The methodology of implementation is described using the ISO 31000 Risk Management Standard and COSO ERM Framework updates. Users need to understand the extent of the changes and identify their potential impact on how their organization manages risk. The article aims to contribute to the widening of the knowledge on the subject by emphasizing the important managerial results. The concepts, approach and guidance outlined in this article provide useful information on the implementation of ERM processes. The study also includes various suggestions for continuous improvement efforts, evaluating opportunities for more connectivity, and integrating organizations’ ERM activities with strategy formulation and operational processes.

Anahtar kelimeler: İç kontrol sistemi, COSO, kalkınma ajansları, bilgi ve iletişim bileşeni, e-devlet,