DOMAIN I: Organizational Governance Related to Risk Management Flashcards

1
Q

Define Risk?

A

The possibility of an event occurring that will impact objectives.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Define Risk Severity?

A

The product of likelihood and impact.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Are all risks damaging?

A

No - negative impacts are known as “risks” or “downsides” and positive impacts are known as “opportunities”.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Risk management should be aligned with what?

A

Strategic priorities of an organization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is 1st step in risk management process?

A

Must consider how well those processes support organizational aims.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

The 4 main processes of risk management are what?

A
  1. Analysis
  2. Risk Response
  3. Monitoring
  4. Reporting
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q
  1. Describe Risk Analysis
A

all current and emergent risks must be identified and assessed for relevance to the organization - this leads to the determination of key risks that need management’s urgent attention.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q
  1. Describe Risk Response
A

There are many ways to respond to risks, depending o risk appetite, available resources, and perceived priorities.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q
  1. Describe Monitoring Risk
A

Potential for change requires routine monitoring over

  1. System of internal controls (control objectives) remain relevant
  2. Changes to internal or external environment that may alter the risk profile
  3. Adjustments to strategy of organization, causing objectives and risks to change.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q
  1. Describe Report on Risk
A

Management and the board (directly or via audit committee or other body such as risk committee) require updates and assurance on risk profile of organization and its state of preparedness with respect to internal controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What are the Risk Management Processes described in COSO?

A
  1. Aligning risk appetite and strategy
  2. Enhancing risk response decisions
  3. Reducing operational surprises and losses
  4. Identifying and managing multiple and cross-enterprise risks
  5. Seizing opportunities
  6. Improving deployment of capital
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Define Enterprise Risk Management (ERM) by COSO?

A

Process, effected by an entity’s board of directors, management, and other personnel, across enterprise, designed to identify potential events that may affect the entity, and manage risk to be within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Define Risk Management Framework?

A

The sum total of all elements of risk management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What does a Risk Management Framework help determine?

A
  • Risk Appetite
  • Responses to particular risks
  • Overall risk culture of organization, enabling it to be progressively more risk mature
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

The effectiveness of risk management framework and processes is often reflected in terms of an organizations what?

A

Overall risk maturity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Risk management objectives should be closely aligned with what?

A

Organizational objectives

17
Q

ERM is interrelated with corporate governance by providing information to the board of directors on what?

A

Most significant risks and how they are being managed.

18
Q

Because risks and opportunities may arise in all areas of activity, risk management should be what?

A

Enterprise-wide

19
Q

Benefit of risk management?

A

It increases the probability of success and reduces both the probability of failure and the level of uncertainty associated with achieving the objectives of the organization.

20
Q

Risk Management calls for what?

A

A coordinated and consistent set of processes to ensure that its contribution is maximized.

21
Q

(ISO 31000) A systematic, timely, and structured approach to risk management contributes to what?

A

Efficiency and to consistent, comparable and reliable results.

22
Q

If there is no reason to accept a risk or to incur the costs associated with controls, the risk should be what?

A

Minimized or removed.

23
Q

Requirements for effective risk management

A
  • Risk management exists to serve the organization, not vice versa.
  • It needs to be enterprise wide.
  • It requires a coordinated and consistent framework.
  • It is not designed to be a brake on ambition.
  • It needs to be cyclical and iterative.
24
Q

Define risk culture of organization

A

Overall attitude and approach to dealing with risks either more or less mature or risk adverse.

25
Q

Define risk maturity

A

A measure of the level of risk culture

26
Q

Define risk appetite

A

An expression of how much risk the organization is prepared to accept or tolerate. BROAD

27
Q

Define risk capacity

A

Ability to accept risk as a consequence of skills and resources at the orgs disposal.

28
Q

Levels of risk maturity from least to most

A
  • Risk naive
  • Risk aware
  • Risk defined
  • Risk managed
  • Risk enabled
29
Q

Who is responsible for setting the risk appetite?

A

Board of Directors or equivalent body

30
Q

Define risk tolerance

A

Relates to risk appetite - represents the application of risk appetite to specific objectives. TACTICAL and PRACTICAL

31
Q

Risk tolerance guide operating units as they implement risk appetite within their operation.

A

Risk tolerance guide operating units as they implement risk appetite within their operation.

32
Q

A complete risk management framework should do what?

A

Assess a risk as both inherent and residual.

33
Q

Define inherent risk

A

Represents impact and likelihood of a risk event if no responses have been applied to manage the risk.

34
Q

Define residual risk

A

Impact and likelihood of a risk event after responses have been applied