EVENT IDENTIFICATION
Potential events that can affect the organization’s objectives are identified. These events can be from internal or external sources, and that may represent risk or opportunity, or both. Risks and opportunities should be distinguished so that management can take appropriate action to mitigate the risk or capitalize on the opportunity.
The COSO Framework identifies events as the main triggers of risk. However, having such a narrow view of risk may obscure the organization’s view of the entire universe of risks, and leave it susceptible to risks which are not caused by a single triggering event, or those caused by events that have no precedents.