top of page


ENTERPRISE INTERNAL CONTROL & STANDARD OPERATING PROCEDURE MANUAL
Document Code: CO-ICM-2026-V1 Target Compliance Frameworks: COSO 2013, PCAOB AS 2201, SOX Section 404, IFRS / US GAAP Scope: Global Operations & Subsidiary Frameworks SECTION I: MANUAL ARCHITECTURE & COMPLIANCE METHODOLOGY 1. The COSO 2013 Control Environment This manual enforces the five integrated components of the COSO 2013 Internal Control-Integrated Framework: Control Environment: Foundation for all other components, driven by "Tone at the Top," ethical values, and organ
Nhung Nguyen
Jun 2712 min read


Risk Identification and Risk Management in the Insurance Sector
Insurance companies exist to absorb risk from individuals and businesses. Unlike most industries that seek to minimize risk exposure, insurers deliberately assume risks in exchange for premiums. Their success depends on accurately identifying, pricing, diversifying, and managing these risks while maintaining sufficient capital to meet future policyholder obligations. From natural catastrophes and cyberattacks to investment volatility and regulatory changes, insurers operate i
Nhung Nguyen
Jun 256 min read


Three Lines of Defense on Risk Management in a Corporation
Introduction Risk management has become one of the most critical components of corporate governance in modern organizations. Businesses face increasing operational, financial, regulatory, cybersecurity, and strategic risks that require structured oversight and accountability. One of the most widely adopted frameworks for managing corporate risk is the Three Lines of Defense Model. This model establishes clear responsibilities across different functions within an organization
Nhung Nguyen
Jun 64 min read
bottom of page