CH 5: Risk Management framework and processes Flashcards
Compare and contrast ERM and traditional RM. (write it down)
Similarities:
- Both processes are cyclical and provide for continuous improvements
- Both have similar steps in identifying, analyzing, and treating risk
Differences:
1. Type of risk addressed:
TRM– hazard risk only w/ negative outcomes only
ERM– all 4 quadrants addressed w/ negative and positive potential.
- The development of an understanding of an organizational environment:
TRM– this understanding is implicit in the evaluation of risk
ERM– this understanding is the first step in its process.
Prompt for comparison: If fire damages the main corp. headquarters, how would that be assessed under both standards?
What is the purpose of framework?
Integrate RM throughout the organization!
What are the 4 components of COSO framework model?
- Lead and establish accountability
- Align and integrate
- Allocate resources
- Communicate and report
what are the 5 steps of the COSO process model (or enterprise-wide risk management process)?
- Scan the environment
- Identify risk
- Analyze risk
- Treat risk
- Monitor and review
List the techniques used to establish accountability!
- Identify risk owners and their role in the organization
- Establish key performance indicator (KPI)
- Establish key risk indicators (KRI)
- Develop risk criteria to evaluate the significance of risk.
Who is a risk owner?
An individual accountable identification, assessment, treatment, and monitoring of risk in specific environment.
What is key performance indicator?
it is a financial or non-financial measurement that defines how successful an organization is progressing towards it long term goals.
What is key risk indicator, bro?
It measures the uncertainty of meeting a strategic business objective.
Do please list the stages in designing and implementing a risk management framework and process?
- GAP analysis: gaps are the international framework and process components that are not found in the organization.
- Evaluation of internal and external environment
- Integration into existing processes
- Commitment of resources
- Communication and reporting
- Monitoring and improvement
What are the ways you can evaluate the internal environment of your organization?
- map the org. and identify
- Evaluate the resources needed to sustain the RM framework
- Evaluate communication channels and corp. culture
What is risk appetite?
The total exposed amount that an org. wishes to undertake on the basis of risk-return trade-offs for one or more desired and expected outcomes.
Give examples of external environment.
Economic Political Legal Technological Natural Competitive landscape
Under ERM process,and as a part of scanning the environment, what are the factors considered in defining risk criteria?
Causes of risk Effects of risk Measures of the effect of risk Timeframe of potential effect Methods to determine level of risk
Under ERM process, identifying risk might include what types of risks?
Existing risk
Key risk
Emerging risk
Under ERM process, list the various ways we can treat risk.
- Avoid the risk
- Modify the likelihood and impact of the risk
- Finance the risk (*- mentioned during session)
- Transfer risk*
- Retain the risk*
- Exploit the risk