CH 6: Risk Identification Flashcards
What is Risk Identification and what is its purpose?
- According to COSO, it is management identifying “potential events affecting an entity’s ability to successfully implement strategy and achieve objectives”.
Its purpose is to optimize risk management by identifying emerging risks.
Step in RM after scanning
List risk identification tools
- checklists
- interviews and workshops
- threshold triggers
- process flow analysis
- Audits
Holistic approach to Risk Identification: 2 ways!
List their adv. and disadv.!
top down
Adv: high-level view of the organization and its risk.
Dis: a. Dependence on reports from middle mngmt.
b. Limited view of risk.
bottom up
Adv: realistic view of the organization’s operations
Dis: a. takes time
b. possibility of details obscuring the desired holistic view.
Ways to implement team approaches to risk identification
- Facilitated workshops: brainstorm
- Delhi technique– take expert opinions on possible risk exposures.
- Scenario analysis: find out possibilities
- HAZOP: Hazard and Operability study: “comprehensive review of a process or system”
- SWOT.
What is a risk register?
A tool developed at the risks owner level that links specific activities, processes, projjects, or plans to a list of identified risks and results of risk analysis and evaluation and that is ultimately consolidated at the enterprise level.
** It provides a matrix to record the likelihood of a scenario and its associated risk.
What is a risk map? describe its composition!
A template depicting the likelihood and potential consequences of risk.
- Horizontal: Likelihood (Rare -[3]-> almost certain)
- Vertical: Consequences (negligible -[3]-> Extreme)
@ the_Position (almost certainextreme) lies Inherent risk(red)
@ the_Position (rareextreme) lies residual risk (yellow)
@ the_Position (rare*negligible) lies optimum (green)
what is optimum risk?
The level of risk that is within an organization’s risk appetite.
List the methods of loss exposure identification!
- Document analysis
- Compliance review
- Personal inspection
- Expertise within and beyond the org.