Chapter 1 - Introduction Flashcards
What is the difference between risk and uncertainty?
Risk can be measured using probability, whereas uncertainty refers to unknown probabilities of an event happening.
What is the ISO definition of risk?
The effect of uncertainty on objectives.
What must risk be mapped to in order to be relevant?
Risk must be mapped to a firms objectives, otherwise it is irrelevant.
What is the definition of risk (Basel Committee)?
The risk of loss resulting from inadequate or failed internal processes, people and systems or from external events
What are the 7 types of operational risk categories?
Internal fraud
External fraud
Workplace safety
Clients and products
Damage to physical assets
System failures
Process management and execution
What is a non-official way of looking at operational risk?
Operational is all risk, excluding market or credit risk (and liquidity risk). Operational risk is all risk excluding any financial risk.
Operational risk is just noted as risk in other industries.
What is the international risk framework published by ISO?
ISO 31000
What does a risk framework leverage?
Actions, techniques and tools used to manage the risks of an entity.
What does ISO and COSO stand for?
International Organisation for Standardisation and Committee of Sponsoring Organsiations
What was COSOs framework called and what risk did it focus on? What did this framework do?
The cube framework focused on enterprise risk. This framework places its vision, risk culture and mission in common circles and details 23 tools and actions for performing enterprise risk management
What are the 4 main activities within risk managemenrt?
Identification
Assessment
Mitigation
Monitoring
What are the alternative representations of risk?
Sequence: cause - event - impact
Actions - identification - assessment - mitigation - monitoring
Techniques - the tools used for each risk management action
What are the 3 parts of sequential risk?
Cause - Event - Impact
Under sequential risk management, what are the elements under the cause?
Exposure - what is the overall exposure, i.e. number of employees with access to high value transactions
Environment - Internal and external - external could be expanding. Internal could be risk culture, training
Strategy - business strategy - any major strategy change will lead to a risk appetite change
What is a risk event?
A risk event is when potential risk actually materialises.
What is a risk impact?
The overall result of the risk materialising - there always be a financial impact as non-financial impacts will eventually lead to a financial impact
What are the