ERM Flashcards

You may prefer our related Brainscape-certified flashcards:
1
Q

Concept of value

A

For-profit commercial entities: value is usually shaped by strategies that balance market opportunities against the risks of pursuing those opportunities.

Not-for-profit and governmental entities: value may be shaped by delivering goods and services that balance the opportunity to serve the broader community against any associated risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is ERM

A

Enterprise risk management: the culture, capabilities, and practices, integrated with strategy-setting and performance, that organizations rely on to manage risk in creating, preserving, and realizing value.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is risk

A

Risk is defined as the possibility that events will occur and affect the achievement of strategy and business objectives.
Risk include 3 elements:
Event
Severity
Uncertainty

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Benefits of ERM

A

Companies that effectively integrate enterprise risk management are likely to benefit in their overall ability to realize value. Benefits may include the ability to:
1. Increase the range of opportunities by considering all reasonable possibilities.
2. Increase the positive outcomes and reduce negative or unexpected outcomes.
3. Better manage entity-wide risk.
4. Reduce performance variability by better anticipating risks and minimizing their impact.
5. Improve and optimize the use of resources.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Mission, Vision, and Core Values

A

Mission/Objective: The core purpose of the entity (Why the company exists and what it hopes to accomplish)

Vision/Strategy: The aspirations of the entity and what it hopes to achieve over time.

Core values: An organization’s beliefs and ideals about what is good or bad, acceptable and unacceptable, and impact on the behavior of the organization.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Integration of ERM

A

Managing Risk Linked to Value
Risk appetite: the types and amounts of risk expressed in mission and vision, an organization is willing to accept in pursuit of value. Risk appetite is a range and must be flexible enough to adapt to changing business conditions
ERM seeks to align anticipated value creation with risk appetite and capabilities for managing risk over time.

Entity-wide risks with a portfolio view: A composite view of risk the entity faces, consider the types, severity, and interdependencies of risk and how they may affect the entity’s performance relative to its strategy and business objectives.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Components and principles of ERM

A
  1. Governance and culture
  2. Strategy and objective-setting
  3. Performance
  4. Review and revision
  5. Information, communication and reporting
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

governance and culture includes principles(5) of:

A

D Defines desired culture
O Exercises board oversight
V Demonstrates commitment to core values
E Attracts, develops, and retains capable individuals (employees)
S Establishes operating structure

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Strategy and Objective-Setting includes principles (4) of

A

S Evaluates alternative strategies
O Formulates business objectives
A Analyzes business context
R Defines risk appetite

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Performance includes principles (5) of:

A

V Develops portfolio view
A Assesses severity of risk
P Prioritizes risk
I Identifies risks (events)
R Implements risk responses

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Review and revision includes principles (3) of:

A

S Assesses substantial change
I Pursues improvement in enterprise risk management
R Reviews risk and performance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Information, communication and reporting includes principles (3) of

A

T Leverages information and technology
I Communicates risk information
P Reports on risk, culture, and performance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

the board of directors should

A

Be independent of management
Primary responsibility (fiduciary responsibility) for risk oversight
To understand the potential organizational biases in decision-making and challenge management to overcome them.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Business objective

A

(SMARt)
Specific
Measurable or observable
Attainable
Relevant

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Authority delegated to________ to design and implement practices that support the achievement of strategy and business objectives.

A

management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

When organizations assess the severity of risk, they should consider:

A
  • Inherent risk - risk in the absence of any actions
  • Target residual risk - risk preferred to pursue strategy and business objectives if actions taken by MGT
  • Actual residual risk - risk remaining after actions taken by MGT
17
Q

Criteria for prioritizing of risks:

A

Adaptability: capability of adapting & responding to risks
Complexity: scope and nature of risk to entity’s success
Velocity: speed of risks’ impact on entity
Persistence: time horizon of risks’ impact on entity.
Recovery: capacity of entity’s returning to tolerance.

18
Q

Risk response:

A
  • Accept: No action is taken to change the severity of the risk. Acceptance is most
    appropriate as a risk response when risk to strategy and business objectives is within the entity’s risk appetite.
  • Avoid: Action is taken to remove the risk (leaving a line of business, etc.). Avoidance is appropriate when an entity cannot devise a risk response that will mitigate the risk to objectives.
  • Pursue: Action is taken that accepts increased risk to achieve improved performance.
    Pursuit of risk is appropriate when management understands the nature and extent of any changes required to achieve desired performance while not exceeding the boundaries of acceptable tolerance.
  • Reduce: Action is taken to reduce the severity of the risk. Management designs risk
    mitigation techniques to reduce risk to an amount of severity aligned with the target risk profile and risk appetite.
  • Share: Action is taken to reduce the severity of the risk. Sharing risk with such techniques as outsourcing and insurance lower residual risk in alignment with risk appetite
19
Q

ESG-Related Risks

A

Environmental Issues: ESG values include positive efforts contributing to environmental protection.

Social Issues: ESG values include positive efforts contributing to socially responsible behavior and outcomes.

Governance Issues: ESG values include positive efforts within an entity’s governance to produce sustainable outcomes.