Chapter 12. Risk Management & Internal Controls Flashcards

1
Q

What is risk*

A

The effect of uncertainty on objectives (positive or negative)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Corporate governance role in risk* (5)

A

D.M.U.C.C.

  1. DEFINE risk appetite
  2. Ensure risks are MANAGED and understood
  3. Ensure robust INTERNAL CONTROLS to manage risks
  4. Create a RISK culture.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Why is risk becoming more important?

A
  1. Speed of change in environment in which companies operate.
  2. Increased transparency (social media)
  3. More intangible risks (rep/Cyber)
  4. More interconnection of risks
  5. Risk isn’t just a compliance discipline (it is building relationships within the business/developing behaviours and a culture of risk management)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What are the 3 main types of internal controls, and what do they seek to provide?**

A
  1. Preventative controls
  2. Detective controls
  3. Corrective controls

According to COSO, they seek to provide reasonable assurance regarding the achievement of objectives in the following areas:

  1. Effectiveness and efficiency of operations
  2. Reliability of financial reporting
  3. Compliance with laws/regulations
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the risks associated with internal controls?**

A

They may fail to achieve their purpose of preventing /detecting and risk which can occur due to:

  1. Badly designed
  2. Not properly applies
  3. Circumvention of control (op risk)

An internal control system must have procedures to identify weak/ineffective internal controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Types of risks**

A

BUSINESS RISKS
Lower anticipated profit due to:
1. Reputation risk (loss of loyalty/support)
2. Competition risk
3. Business environment risk (politicial/regulatory changes)
4. Liquidity (not enough cash to settle liabilities)

GOVERNANCE RISKS
1. Structure (board/policies)
2. Processes (new proolducts/strategic planning)
3. Informstion (financial reporting/MI)
4. People and culture (leadership/accountability/transparency)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

UKCGC and RISK / Internal controls

A

(O) Board should establish procedures to manage risk, oversee internal control framework & and determine nsture/extent of principle risk its willing yo take to achieve its long term strategic objectives

(28) assess emerging/principle risks and confirm in AR&A Inc description of main risks, procedures to identify risks & how they’re being managed/mitigated.

(29) board should monitor risk management/internal controls. At least annually, review their effectiveness and report in AR&A. Monitoring and controls should include material controls- finance, operational and compliance.

See also (25) AC role/responsibility. And 31 Viability

Code/guidance doesn’t require reporting of failure/weakness of internal controls but DTR requires in annual report details of internal control and risk management systems.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the 5 steps of developing a risk management system?**

A
  1. DEFINE AND IDENTIFY
    > What is the risk? i.e. liquidity/ competition / reputation
    > How to identify (mind mapping / process mapping / stress testing/ internal docs)
  2. ASSESS
    to see if it’s a principle risk… liklihood x impact provides rating.
    Consider risk appetite/ risk tolerance
  3. RESPONSE
    Avoid
    Reduce
    Transfer
    Accept
  4. MONITOR
    Process to monitor response to risk I.e.
    > stress testing
    > internal audit reviews
    > SMART (specific, Measurable. Achievable, relevant, time based)
  5. REPORT
    Board: via risk register/dashboard
    Shareholders: via strategic report - risks/ uncertainties / management and mitigation.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are internal controls?**

A

The structure, policies, procedures in a company to manage finance, operational and compliance risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Role of the company secretary in risk

A

Develop strategic objectives relating to risk.

Identify principle risks company is willing to take to achieve objectives and those which could threaten the business.

Robust assessment of principle risks

Explain how principle risks are being managed/mitigated

Monitor and annually review the effectiveness of the risk management and internal control system

Annual Viability assessment (code 31) for period determined by Board

Report on above in AR&A

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the 3 main types of internal controls?

A
  1. Preventative controls
  2. Detective controls
  3. Corrective controls
How well did you know this?
1
Not at all
2
3
4
5
Perfectly