Chapter 2 - Risk strategy management Flashcards
CIMA’s risk management cycle (7 steps)
E IUD IIR
Establish a risk management group and set goals
Identify risk areas
Understand and assess the scale of risk
Develop a risk response strategy
Implement strategy an allocate responsibilities
Implement and monitor the suggested controls
Review and refine process and do it again
What is a risk register?
Recorded risks facing the company that are evaluated against the company’s risk apetite
Who analyses the risk? (4)
Senior management (top-down approach)
Lower-level staff (bottom-up approach)
External consultant
Risk manager employed by company
What is risk mapping
Revaluation, managing and reporting of risks
In the TARA risk map, what responses go with what level of risk?
Transfer - medium risk
Avoid - high risk
Reduce - medium risk
Accept - low risk
What is portfolio theory?
Theory that spreading investments reduces risk
What is a risk report?
Report containing key risks company faces, it’s responses to those risks and what is expected to be done in terms of managing the risks
This is requirement for PLC to include risk report as part of annual report to shareholders
What does COSO stand for
Commission of Sponsoring Organisations of the Treadway Commission
What is Enterprise Risk Management? (as defined by COSO)
A process, effected by an entity’s board of directors, management and other personnel,
applied in strategy setting and across the enterprise,
designed to identify potential events that may affect the entity,
and manage risk to be within it’s risk appetite,
to provide reasonable assurance regarding the achievement of entity objectives
List the ERM framework components (8)
Internal Environment Objective Setting Event Identification Risk Assessment Risk Response Control Activities Info & Communication Monitoring
List the ERM framework objectives (4)
Strategy - high-level goals with goal congruence
Operations - effective and efficient use of resources
Financial Reporting - reliability of operational and financial reporting
Compliance - compliance with applicable laws and regs