Risk Assessment Is No Longer Optional: Stronger Controls Start with a Stronger View of Risk

The Committee of Sponsoring Organizations of the Treadway Commission (COSO) Internal Control – Integrated Framework, updated in 2013, remains the predominant framework used by public companies to evaluate internal control over financial reporting (ICFR). However, for today’s executive teams and audit committees, the framework is no longer just a compliance reference point. It is a governance tool for understanding whether internal controls are keeping pace with business change, regulatory scrutiny, technology transformation, cybersecurity risk, third-party dependence, and increasingly complex financial reporting judgments. Item 308 of SEC Regulation S-K continues to require management to identify the framework used to evaluate the effectiveness of ICFR, reinforcing the need for a risk assessment process that is current, well-supported, and clearly connected to management’s ICFR conclusions.

COSO remains the most widely used internal control framework among public companies, but its value today extends beyond satisfying compliance requirements. For executives, audit committees, and finance leaders, COSO provides a practical structure for asking whether the company’s control environment is keeping pace with the way the business actually operates. Risk assessment is one of COSO’s five components. It is often the point where an ICFR program is either anchored in current business reality or begins to drift into a static, check-the-box exercise. Within the risk assessment component, COSO includes four principles that are especially relevant in today’s environment:

  1. Set clear objectives. Management should define financial reporting, operational, compliance, and strategic objectives with enough clarity to identify where material risk could arise and how those risks may affect ICFR.
  2. Identify and analyze risks across the enterprise. Companies should evaluate risks across entities, locations, systems, processes, service providers, and reporting streams, then determine how those risks should be managed through appropriately designed controls.
  3. Consider fraud risk. Risk assessment should explicitly address incentives, pressures, opportunities, and areas of judgment or override that could affect financial reporting, including risks heightened by growth, liquidity pressure, restructuring, or significant changes in personnel or systems.
  4. Assess change continuously. Management should identify and evaluate changes that could significantly affect internal control, including new systems, automation, cybersecurity events, artificial intelligence use cases, third-party arrangements, acquisitions, new accounting standards, regulatory developments, and shifts in business strategy.

While the COSO framework establishes the foundation for effective risk assessment, its application in practice is where companies often struggle. The question is no longer simply whether a company performed an annual scoping exercise. Management, auditors, regulators, and audit committees are increasingly focused on whether the risk assessment is current, evidence-based, responsive to contradictory information, and connected to the actual design and operation of controls.

Key Takeaway

A risk assessment should not be a once-a-year scoping file. It should be a living management tool that connects business change, financial reporting risk, control design, disclosure obligations, and audit readiness.

Despite the guidance embedded in COSO, there continue to be differing perspectives on what is sufficient to demonstrate an effective risk assessment for ICFR. In a typical ICFR evaluation program, the first step annually is to perform a risk assessment that considers both quantitative and qualitative factors. In practice, we still see companies treat scoping as a static exercise, particularly in Section 404(a) environments or in newly public companies building their first formal SOX program. That approach can miss the point. An ICFR program without a thoughtful, current risk assessment is like building a house without a supporting foundation. Lack of a solid risk assessment exposes a company to several potential risks:

  1. The company may be unable to defend its ICFR evaluation to regulators, auditors, audit committees or shareholders. 
  2. Management may not effectively align current or future efforts with the external auditors, which can create inefficiency, late changes, or unnecessary testing burden.
  3. The ICFR program may include unnecessary documentation and testing if it is not appropriately scaled to the company’s industry, locations, size, systems, transaction volume, complexity, and maturity.
  4. The company may miss opportunities to streamline processes, improve systems and controls, and focus resources on the most significant risk areas.

A strong ICFR program should include at least an annual risk assessment addressing the quantitative factors, such as balances, activity, materiality, and fluctuations, as well as qualitative factors, such as accounting complexity, subjectivity, susceptibility to error or fraud, transaction volume, system changes, process centralization, third-party involvement, and the maturity of the control environment. The risk assessment should be revisited if major changes or events occur during the year. This will allow Management to pivot and reassess the nature, timing, and extent of testing being conducted for a given period. A comprehensive risk assessment is crucial as it identifies vulnerabilities, prioritizes risks, supports and enhances decision-making, and creates a more resilient and defensible ICFR program.  

SEC Perspective

In August 2023, SEC Chief Accountant Paul Munter issued a statement, The Importance of a Comprehensive Risk Assessment by Auditors and Management, reinforcing that management and auditors cannot evaluate ICFR through a narrow financial reporting lens alone. The SEC cautioned against treating broader business, operational, regulatory, technology, cybersecurity, governance, or third-party issues as isolated events when those matters may also affect financial reporting, disclosures, or the internal control environment. For today’s executive audience, the message is clear: risk assessment must be holistic, continuous, and evidence based. Effective processes should consider the company’s objectives, strategy, and related business risks; evaluate contradictory or disconfirming information; and ensure management deploys the right resources and controls to respond to risks as they evolve.

The statement concludes with the comment by former SEC Chair Gary Gensler that “there’s a basic bargain in our capital markets: investors get to decide what risks they wish to take,” while “companies that are raising money from the public have an obligation to share information with investors on a regular basis.” Timely and transparent reporting by management, and informative, accurate, and independent reports by auditors, are critical components of the system that help companies maintain their end of the bargain, their commitment to provide high-quality financial information and clear insight into the effectiveness of their ICFR to investors. When business risks change, a robust, iterative risk assessment process and strong entity and process-level controls are essential to transparent and high-quality financial reporting.”

Centri Perspective

The SEC’s message is clear: management’s risk assessment should be holistic, iterative, and connected to control design, disclosure, and governance. This is especially important when companies experience changes in strategy, financing, systems, cyber events, business conditions, leadership, operations, regulatory exposure, or third-party arrangements. These events may not always begin as financial reporting issues, but they can become ICFR issues if they affect the control environment, risk assessment, information and communication, monitoring, or the completeness and accuracy of information used in financial reporting.

A clear example is the quarterly disclosure requirement under Item 308(c) of Regulation S-K and management’s Section 302 certification under the Sarbanes-Oxley Act. Together, these requirements call for disclosure of any material changes in ICFR that occurred during the fiscal quarter. The SEC’s cybersecurity disclosure rules further reinforce this expectation. Companies must describe their processes for assessing, identifying, and managing material cybersecurity risks, as well as the board’s oversight and management’s role in those processes. Taken together, these requirements highlight the importance of maintaining a risk assessment process that is current, responsive, and aligned with changes in the company’s operations, technology environment, and regulatory obligations.

How Centri Can Help

Conducting a thorough risk assessment is not just a best practice; it’s a regulatory and operational necessity. We reinforce the importance of performing this assessment at least annually, and more frequently when business conditions change, to ensure your ICFR program remains effective, relevant, and defensible. A well-executed risk assessment lays the foundation for a scalable and efficient internal control environment that aligns with both COSO principles, SEC expectations, external audit planning, and management’s need to make risk-informed decisions.

Clients are increasingly asking practical questions such as: What changed this quarter? Did that change affect ICFR? Are we over-testing low-risk areas? Are we under-documenting emerging risks? Are cyber, AI, and third-party risks being considered through a financial reporting lens? A strong risk assessment should help answer those questions clearly.

Editor’s note: This article was originally published on July 8, 2025. It was updated on August 7, 2026.

Gareth Montague-Smith headshot.

Gareth Montague-Smith

Managing Director | CPA

Gareth is a Managing Director at Centri Business Consulting. He has more than 28 years of finance and accounting experience, providing financial, auditing, and internal audit services across multiple industries. View Gareth Montague-Smith's Full Bio

About Centri Business Consulting, LLC

Centri Business Consulting provides the highest quality advisory consulting services to its clients by being reliable and responsive to their needs. For 15 years, Centri has delivered trusted expertise to help companies meet their evolving reporting demands. Centri specializes in financial reportinginternal controlstechnical accounting research, outsourced accounting, valuationmergers & acquisitions, and tax, CFO and HR advisory services for companies of various sizes and industries. From complex technical accounting transactions to monthly financial reporting, our professionals can offer any organization the specialized expertise and multilayered skillsets to ensure the project is completed timely and accurately.

Philadelphia
3 Logan Square
26th Floor
1717 Arch Street
Philadelphia, PA 19103
New York City
530 Seventh Avenue
Suite 2201
New York, NY 10018
Raleigh
4509 Creedmoor Rd
Suite 206
Raleigh, NC 27612
Boston
50 Milk St.
18th Floor
Boston, MA 02109
Tysons Corner
1775 Tysons Blvd
Suite 4131
McLean, VA 22102
Denver
One Tabor Center
1200 17th St.
Floor 10
Denver, CO 80202
Tampa
615 Channelside Drive
Suite 207
Tampa, FL 33602
Atlanta
1175 Peachtree St. NE
Suite 1000
Atlanta, GA 30361
Dallas
1920 McKinney Avenue
Dallas, TX 75201
Minneapolis
8481 Jefferson Hwy.
Minneapolis, MN
55369-4588

06/27/2025

Surviving Uncertainty: Why Your Business Needs an Incident Response Plan Now

In today’s volatile economic and political landscape, businesses face unprecedented challenges. Cyber...

Read More

09/12/2024

Be Prepared: Why A Disaster Recovery and Business Continuity Plan is Crucial For Your Organization

September is National Preparedness Month, the perfect time to re-evaluate the necessity...

Read More

01/28/2022

Why is Risk Advisory Important for Businesses?

Risk is an unavoidable part of doing business, but it can be...

Read More

07/02/2025

Cryptocurrency as a Treasury Asset: Are Your Controls and Policies in Place?

As digital assets like Bitcoin continue to gain mainstream traction, companies such...

Read More

Related Services