Core Activity D - Evaluate and mitigate risks Flashcards
What are the key elements of the risk management cycle ?
Identify risks
Assess likelihood and impact
Design and implement internal control system
Check internal controls are appropriate and working
Report to management
Circle back with ongoing improvement and monitoring
What 5 key areas does ERM involve ?
Understanding how a business is run by its directors
Strategy for success
Positive and negative risks
Risk response
Information gathered on performance and how it responds to that information
What 5 key areas does ERM involve ?
Understanding how a business is run by its directors
Strategy for success
Positive and negative risks
Risk response
Information gathered on performance and how it responds to that information
What are the two main risk management frameworks ?
COSO ERM - Integrating strategy & performance
ISO 31000 - risk management guidelines
What are the 5 key components of the COSO ERM framework?
Governance & culture
Strategy and objective setting
Performance
Review and revisions
Information, communication and reporting
What are the four main classifications of risk the portfolio view establishes ?
Financial risks
Operation risks
Compliance risks
Customer risks
Describe the TARA framework
Transfer - low/high (insurance)
Accept - low/low
Reduced - high/low
Avoid - high/high
What stages might the identification of risks go through ?
Upside / downside risks
External or internal risks
Strategic or operational risk
How might the process for risk identification look?
Determine upside or downside risk
Then determine the source of the risk - ie internal or external
Then determine the level of risk - ie operational or strategic
What international risks are Rotomyne exposed to?
PESTEL
Transaction risk
Translation risk
Interest rate risk
Physical risk of uranium theft etc
Credit risk - non paying customers
How might Rotomyne mitigate exchange rate risk ?
Hedging via the use of forwards, options and futures
What other international risks exists?
National culture
Social grouping
Religious issues
Language
How might risks be identified from different areas of the business ?
Bottom up identification
Top down risk identification
What processes might be used to evaluate risks ?
Qualitative analysis
Quantitative analysis
Risk mapping
What quantitative techniques could be used to assess risk ?
Expected value
Standard deviation
Volatility / COV
Normal distribution
Regression / correlation
When assessing risk how can quantitative analysis be used to see how variables are related ?
Regression - analysis to obtain the relationship between two (or more) variables
Correlation / correlation coefficient - to see how strong that relationship is
How can sensitivity analysis be more efficiently managed?
‘Goal seek function’
How can a simulation be more efficiently managed ?
‘What if’ function
What visual tools can be used to manage risks ?
TARA model
Heat risk maps (5x5)
Risk bands .. graphs
What are the steps for determining risk appetite?
Need to check this - I think appetite is set and tolerance measured! Deloitte example
Understanding the
Risk tolerance - (Overall feeling of risk) How much risk are the board willing to tolerate?
Risk appetite - (The amount of risk the organisation is willing to take to achieve its long term objectives) perhaps more specific and always smaller than risk tolerance.
Risk capacity - How much downside risk can the organisation cope with to just survive (Berkshire has almost infinite resources)
Define risk capacity
Ability to shoulder the risks facing the organisation in relation to its goals and strategies
The risk capacity allows the organisation to take some risks but provide a cushion against downside risk
How might we gain an understanding of the organisation’s maturity of risk management?
Strong processes = greater maturity
What are the financial and non financial considerations of risk capacity?
Are funds available ?
Does the return meet the requirements of the risk ? Economic spread
Reputation risk
Political risk
Infrastructure
Staff and knowledge