Enterprise Risk Management Flashcards

1
Q

Silo Risk Management

A

Lack of communication where departments handle their risks separately.
This results in a lack of the bigger picture for the interrelations between departments, and the CEO might lack sufficient information to make strategic decisions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Enterprise Risk Management

A

Consists of three components:

  • Governance
    • Communication (information flow & reporting)
    • Responsibility (accountability & authority)
    • Monitor and review (KRIs)
  • Strategic
    • Strategically manage risk
  • – Identify sweet spot for risk taking, risk management not minimization)
  • – Identify risk profile, tolerance, appetite, and capacity
    • Management of strategic risks
  • – Strategy development and the risk management process
  • Integrated
    • Across integration – portfolio view
    • Top down integration – integrating risk culture into organisational culture
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

The Risk Management Process

A

Identify
Analyse (probability x consequence)
Act/Risk Response (avoid, transfer, mitigate, accept)
Monitor (monitor the risk response)
Control (assess effectiveness and efficiency)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Categories of Risk

A
  • Diversifiable (idiosyncratic) VS non-diversifiable (systematic)
  • Core (must bear to operate and thus information in needed) VS non-core (not in the business of bearing).
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Event driven risks

A

A way of defining risks, where a type of event triggers loss or gain

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Typical risk event classifications

A
  • Financial events
  • Operational events (supplier problems, loss of personnel, IT system failure)
  • Strategic events (demand changes, those that affect or are created by strategic business decisions)
  • Compliance events
  • Hazard events (political, terrorism, natural disasters)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How does traditional versus modern risk management view risks in relation to uncertainty and opportunity, and how are they focused on core versus non-core risks?

A
  • Traditional – risks as calculable (probability based) and negative. Focus on non-core risks
  • Modern – risks are beyond those that are calculable, are negative AND positive. Focus on core business/strategic risks.
    (Both uses event driven definitions)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Operational Risks

A

What’s going to stop us from operating properly
“Bottom up”
Short to medium term scope
Often calculable

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Strategic risks

A

What’s going to stop us from pursuing the strategy we’ve set and achieve our objectives
“Top down”
Long term scope, often on the more uncertain side

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Strategic Risk Management process

A
  1. Assess existing strategic risks
  2. Reassess strategy and objectives
  3. Set new strategy and objectives
  4. Identify new strategic risks
    (Do we have the appropriate strategy and business model given the risks we’re facing?)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

The two aspects of Strategic Risk Management

A
  1. Strategically managing risks
    - Identifying the “sweet spot” for risk taking (risk management NOT minimization)
    - Firms should identify risk their profile and determine tolerance, appetite and capacity
  2. Management of strategic risks
    - Strategy development and the risk management process
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

A portfolio view allows organisations to observe risks that: (INTEGRATED)

A
  • Increase in severity when consolidated
  • Decrease in severity when consolidated
  • Offset other risks by acting as natural hedges
  • Demonstrate a positive or negative correlation to changes occurring in the severity of other risks
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Two aspects of Integrated Risk Management

A
  • “Across” integration – portfolio view

- “Up and down” integration – integrating risk culture into organisational culture

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How is risk culture formed? (INTEGRATION)

A

Risk attitudes of the individuals (averse, neutral, seeking) shapes risky behaviour, which in turn forms risk culture. Risk culture then influences both risk attitude and behaviour

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Mutually amplifying risks (INTEGRATED)

A

When a risk does not seem too bad by its own. However, when considering the risk’s interrelation to other risks the impact is more frightening

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What is important when assessing risk culture?

A

Looking at measurable behaviours that can be objectively assessed

17
Q

Key Risk Indicator

A

A measure to indicate the potential presence, level or trend of a risk (forward looking)

18
Q

Three components of Governed Risk Management

A
  • Communication (reporting & information flow)
  • Responsibility (accountability & authority)
  • Monitoring and review (KRIs)
19
Q

What is important to realise in terms of core and non-core risks?

A

If a firm has a competitive advantage in their core risks will minimize non-core risks in order to take on more core risks.

20
Q

Risk appetite

A

Broad level, the amount of risk an organisation is willing to accept in pursuit of value
(desired level of risk)

21
Q

Risk tolerance

A

Acceptable variation of outcomes related to performance measures linked to objectives

22
Q

Risk capacity

A

The maximum risk a firm may bear and remain solvent

23
Q

Risk profile

A

The existing level and distribution of risks across categories (financial, market, operational, etc.)