ERM Flashcards
ERM Manual
A document outlining policies and procedures for managing risks and carrying out ERM processes at PC Limited, applying to all sub-functional areas within the ERM function.
Risk Appetite
A guide used to determine the acceptable level of risk at PC Limited,
PC Limited’s approach to measuring identified risks related to its business processes
Risk Assessment Approach
Four Risk Treatment Approaches adopted by PC Limited for risk treatment
Tolerate (Acceptance)
Treat (Reduce)
Transfer (Share)
Terminate (Avoid)
Risk Map
Illustrates the effect of implemented mitigation plans on gross risk, resulting in residual risk moving towards the bottom left-hand corner of the grid.
Quality Assurance and Improvement Program
Involves ongoing assessment and monitoring of GRC’s performance and effectiveness at PC Limited, covering all main aspects of quality assurance.
How often QAQC assessments are carried out
internal assessments conducted annually and
external assessments every three years.
PC Quality Assurance Review Tool
A key tool used to
- check the quality assurance of the GRC Function at PC Limited,
- documenting variance analysis results and
- defining next steps for each GRC team member involved in reviews.
Investigation Processes and Procedures
Established for conducting investigations into alleged incidents of bribery, corruption, fraud, and misconduct,
Whistle-blower Policy
Outlines the requirements for reporting whistle-blower complaints to the GRC Function at PC Limited.
Investigation Planning Phase
Includes
- protocols for information storage and sharing,
- report distribution lists at PC Limited. - Third parties need to be notified of certain allegations to be investigated.
> regulators,
> external auditors, and
> law enforcement agencies may
PC Risk approach is based on
likelihood ranking criteria provided in the ERM manual.
How is the level of risk obtained?
A combination of likelihood of occurrence and magnitude of impact
Approach adopted by PC Limited to improve risk management
Enterprise risk management (ERM)
How is the company risk apetite derived
derived from annual strategy/goal setting processes and based on strategic, operational, compliance, and reporting objectives.
Responsible for investigations processes and procedures with review and administration.
GRC Function and the Chief Compliance Officer
Risk is
The probability that the occurrence of an event may positively or
negatively impact the achievement of the organization’s objectives.
Four (4) key elements
of PC Limited’s ERM model:
a) Risk strategy and appetite;
b) Risk culture;
c) Risk governance; and
d) Risk management process.
Purpose of ERM manual
Sets out policies, guidelines and practices to be adopted in
managing risks and carrying out ERM processes.