consideration. Ideally, risk assessments are a continuous process whereby central owners consistently monitor and adapt to the fraud environment with periodic "refreshes" of the risk assessment and plan for response. Public companies have sox $404 as a mandated type of this iterative process.