Chapter 3: Risk Definition and Taxonomy Flashcards
Q: Is technology a risk?
A: No, technology is a resource. Risks linked to technology are potential incidents like system interruptions or application crashes.
Q: What is manual processing in the context of risk?
A: Manual processing is a cause or risk driver, increasing the probability of risks like input errors and omissions.
Q: How should compliance and regulatory change be viewed in risk management?
A: Compliance and regulatory change are obligations and constraints, not risks. They bring risks like compliance breaches due to oversight.
Q: Are inadequate supervision and insufficient training considered risks?
A: No, they are control failures. They can lead to risks like internal fraud and errors but are not risks themselves.
How do you perform risk management taxonomy?
Not only categorizing risks but also recording the causes, impacts and controls
as a MECE system: Mutually Exclusive and Collectively Exhaustive
The Basel definition of operational risk?
The risk of loss resulting from inadequate or failed internal processes, people and systems or from external events”
What are the 4 categories of operational risk?
Financial loss
Reputational damage
Reg non-compliance
Customer detriment
PPSE?
People, processes, systems, external events
What are the four main categories of controls?
Preventative - Mitigate possible causes
Detective - Takes place during or after to detect the issue
Corrective - how loss is compensated
Directive - structure of ops