Internal control systems need to be continuously monitored, Risk Management

Assignment Help:

QUESTION

(a) Internal control systems need to be continuously monitored. This is a process that assesses the quality of the performance of a system over time and is accomplished by two approaches. Describe those two approaches.

(b) The auditors of a healthcare company found that the company is in breach of the Data Protection Act following an investigation into the online application system for refund of claims. This function of online application was outsourced to an IT company a year ago. The security breach meant that the personal data of customers applying for refunds was potentially visible to others visiting the website. The IT Company was asked to immediately stop the online application facility. Further investigations revealed that the IT Company did not have any experience in developing and hosting such IT systems.

i. Identify and explain the controls that should have been in place to possibly avoid the breach.

ii. The healthcare company could have made use of indicators to provide an early warning signal that a risk is emerging to enable management to take proactive action. What is this indicator and how would it have helped the company?


Related Discussions:- Internal control systems need to be continuously monitored

Risk management and financial institutions, On September 25,2008 a portfoli...

On September 25,2008 a portfolio worth $10 million consisting of investments in four stock indices: DJIA, FTSE 100, CAC 40 and NIKKEI 225. The value of the investment in each index

Display screen equipment risk assessment, Question 1: (a) Describe the ...

Question 1: (a) Describe the aspects that should be considered when assessing the fit between a person and his work. (b) Display Screen Equipment (DSE) risk assessment shoul

Develop strategies to eliminate risk, Develop strategies to eliminate, miti...

Develop strategies to eliminate, mitigate, deflect or accept risk • Risk treatment strategies: Risk avoidance, reduction, transfer and retention • The types of controls that can

Risk management strategy, The risk register and risk management strategy sh...

The risk register and risk management strategy should justify and report on the rationale of the register, priority and its management . Guidelines Risk  is assessed

Explain mechanisms of financial system for risk transferred, Explain about ...

Explain about the mechanisms of financial system for risk to be transferred. Financial systems also give mechanisms for risk to be transferred. For instance insurance contracts

Determine a process for communicating, Determine a process for communicatin...

Determine a process for communicating, resourcing and managing risk management strategies Establish a communication plan to implement the risk management framework that has been

What is a safe system of work, Question 1: Employers should conduct pro...

Question 1: Employers should conduct proper health risk assessment in order to identify and control health risks before they lead to losses. Describe the four stages involved i

Overtrading, What are the solution for over trading that has caused for exp...

What are the solution for over trading that has caused for expanding operation

What is the objective of risk management, Question: (a) What is the obj...

Question: (a) What is the objective of risk management? (b) Define the term risk avoidance. (c) Define and describe the Methodology of process approach in ISO 9000. (d

coon position is quite substantial part, A former alumna of the University...

A former alumna of the University, who originated Racoon.com ((ticker: COON1), recently passed away. In her Will, she named X-University as the beneficiary of her assets, which was

Write Your Message!

Captcha
Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd