Current active course description (last updated 2026/27)
Risk Management and Internal Control
ECO5015
Current active course description (last updated 2026/27)

Risk Management and Internal Control

ECO5015
This course focuses on the establishment and use of internal control systems in modern organizations. The course introduces main components of internal control systems and discusses practical aspects of their application as tools for business administration. International frameworks for risk management (for example, COSO) will be given a central place in the course program.

The course consists of three main interrelated parts.

Part 1. Risk Management: history and theory

This part will start with historical and theoretical foundations of modern risk management, its definitions, tools and main approaches. Special focus will be given to presentation of COSO framework and Enterprise Risk Management as playing a leading role today in guiding risk management practices in a systematic way. This part also incorporates the implications of recent technological advancements, including artificial intelligence, in the context of internal control and risk management.

Part 2. Critical reflections on Risk Management

This part will be devoted to critical reflections on the principles of modern risk managementas risk management of nothing. Based on the empirical research literature and practical examples, we will challenge the widely established trends of ambitious all-encompassing risk management, consider potential collision between risk management and internal control and open discussion for alternative perspectives and opportunities for progress. This part implies active participation from students based on the studied materials and group work.

Part 3. Governance and internal control

This part will focus on the introducing the concepts of governance and internal control. During lectures based on empirical studies of big organizations, we will study the link between organization’s control environment and particular mechanisms of internal control.

The course is only open to students in the Master of Science in Business and Master of Science in Accounting, Auditing and Sustainability study program.

Knowledge:

  • Have in-depth knowledge within the field of Management Control, with a special focus on relations between business administration, risk management and design of internal control systems, knowledge about various international and internal control frameworks as, for instance, COSO/ISO.
  • Have extensive knowledge on risk typologies, evaluations of organizational capabilities to deal with risks, response strategies, operational registering, measuring and reporting of risks and internal auditing, as well as ethical dilemmas associated with risk management.
  • Have overview of empirical research literature that addresses challenges related to utilization of international internal control framework in practice in various types of organizations.
  • Have in-depth knowledge on how risks can be managed in a systematic way, including application of digital tools as a part of Enterprise Risk Management (ERM) systems.
  • Acquire knowledge on external and internal drivers for internal control systems’ change.

Skills:

  • Critically analyze and evaluate contents of international framework for internal control.
  • Based on own analysis of organizations, be able to conclude whether internal control system is established in an organization, how it functions and formulate suggestions for improvements.
  • Be able to use elements of ERM systems to outline measures for managing of different types of risks as on organizational so on operational levels.

General competences:

  • Conduct advanced assignments related to analysis of internal control systems in groups.
  • Discuss in groups and communicate academic research problems related to development of internal control systems.
  • Apply and easy learn skills of work with new ERM digital tools.
  • Realize needs for and provide suggestions for potential changes in internal control systems in different types of organizations in public and private sector.
In addition to the semester fee and required reading materials, it is assumed that the student has access to a laptop computer.
Compulsory
Lectures, group work, group presentations.
The study programme is evaluated annually by students by way of course evaluation studies. These evaluations are included in the universitys quality assurance system.

A combination of group and individual performance. All participants will be required to submit and present a group wrtitten paper and take a written exam during semester:

  • The assignment (based on the collection of empirical data - optional) must be carried out in groups (passed/not passed.
  • Individual 4-hours written school examination (A-F, counts for 100 % of the final grade)

Simple calculator. Two bilingual paper dictionaries are allowed.

Generating an answer using ChatGPT or similar artificial intelligence and submitting it wholly or partially as one's own answer is considered cheating. Students must otherwise comply with Nord University's guidelines for the use of generative artificial intelligence (AI) in studies.