Chapter 3 - Risk Definition and Taxonomy Flashcards

1
Q

Is technology a risk or resource

A

a resource

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

is manual processing considered a risk

A

it’s a cause/risk driver- increases
probability of risk e.g. input errors and omissions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

what are the Risks due to
manual processing

A

errors in the valuation of funds, errors in accounting records, omitting to send reports to clients

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

are Inadequate supervision or insufficient training considered risks

A

they are control failures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

solution to control failiures

A

fix the control. Or add a secondary control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

what can Inadequate supervision lead to

A

internal fraud, sub-standard productivity resulting in customer dissatisfaction or loss.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

how should Risks be defined as

A

negative events, uncertainties, incidents or accidents. They should be specific and concrete

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

simple question to define risks

A

“What could go wrong?”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Basel category level 1

A

Event-type
category

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Basel category level 2

A

categories (sub categories of level 1)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Basel category level 3

A

Activity examples

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Level 2 categories of Internal fraud (level 1)

A
  • Unauthorised activity
  • Theft and Fraud
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Level 2 categories of external fraud (level 1)

A
  • Systems security
  • Theft and Fraud
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Risk of too much detail in risk identification

A

detrimental to quality of information and is difficult to review- drains effort without benefits

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How many levels of regulatory categories does basel commitee recognise

A

2 levels of category, level 3 is just for detail/examples

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

what is required when for firms to categorise risks

A

firms are required to map risk categories to the Basel categories

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

what do firms not have to do when classifying risks

A

n doesn’t have to define a firm’s risk taxonomy these days

15
Q

When was the basel classification drafted

A

almsot 20 years ago

16
Q

what has led to tncrease in cybercrime

A

mass digitization

17
Q

what has multiplied the risks of outsourcing project/change management, and information management

A

Business transformation and wider international operations

18
Q

what have business practices been renamed as

19
Q

what did 08 highlight the need for higher focus on

A

“conduct,” anti-money laundering (AML),
international sanctions and preventing tax-evasion

20
Q

how many risk classification’s do Basel have

21
Q

dictionary definition of taxonomy

A

a “scheme of classification.”

22
Q

what does taxonomy mean in terms of risk management

A

categorizing risks and recording causes, impacts and controls as a MECE system

23
Q

whats a mece system

A

Mutually Exclusive and Collectively Exhaustive

24
Q

Basel definition of operational risk

A

“The risk from failed internal processes, people, systems or external events”

25
Q

What was initially counted as a loss from operational risk in the 1990s - what did this grow to include

A

At first only financial, now reputational is included

26
Q

What are the current four commonly used
categories for the impacts of operational risks

A

financial, reputation , regulatory non-compliance and customer detriment

27
Q

Which firms find continuity of services important

A

online financial services or trading platforms

28
Q

a common category of impact for firms where continuity of service is important

A

service disruption

29
Q

PPSE/ causes of risk in a mece taxonomy

A

people, processes, systems or external events

30
Q

The four main categories of controls in a mece taxonomy

A

Preventive, Detective, Corrective, Directive

31
Q

Preventive control

A

reduce likelihood of risks by mitigating their causes

32
Q

Detective control

A

during the event/soon after, early detection to reduce impact

33
Q

Corrective control

A

reduces impacts caused by incidents. Damage is repaired /loss compensated by using backup and redundancies

34
Q

Directive control

A

comprises guidelines and procedures that structure the mode of operations to reduce risks.

35
Q

When does detective control have a preventative element

A

if detection also identifies the cause of an incident

36
Q

4 parts of a mece taxonomy

A

Causes
Risks
Impacts
Controls

37
Q

4 impacts of risks in a mece taxonomy

A

Financial loss
Reputation damage
Regulatory breach
Customer detriment

38
Q

Operations risk L1 code

39
Q

Information security risk L1 code