ERM - Enterprise RISK Management Flashcards

1
Q

ERM - Enterprise Risk Management FRAMEWORK

A

Balances Risk & Return

Has following THEMES:

Align Risk Appetite and Strategy
Enhance Risk Response Decisions
Reduce Operational Surprises & Losses
Identify & Manage Multiple & Cross-Enterprise Risks
Seize Opportunities
Improve Deployment of Capital
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

ERM - Ent. Risk Mgmt. Objectives (4) SORC

A

S - Strategic-Hi level goals designed to achieve mission
O - Operations-Achieve objectives thru effective & efficient use of resources
R - Reporting-Reliable & Consistent reporting
C - Compliance-Ensuring compliance with laws and regulations

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

COMPONENTS of ERM (Broader in Scope than just financial reporting objectives) remember “IS EAR AIM”

A

I - Internal environment (Tone at the top, C in “CRIME”
S-Setting Objectives (SORC)

E-Event ID
A-Assessment of Risk These are R in “CRIME”
R-Risk Response

A-Activities Control E in Crime (existing controls)
I-Information and Communications I in “CRIME”
M-Monitoring M in “CRIME”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Inherent Risk

  vs.

Residual Risk

A

Inherent Risk - is the risk if you do NOTHING

Residual Risk - is the risk that exists AFTER take action

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Order of ERM

A

First Identify the Objects (SORC)

Then identify possible positive & negative events

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Residual risk is defined as

A

the risk that an organization incurs after management takes whatever actions are needed to mitigate the adverse impact of a given event

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Inherent risk is defined as

A

the risk to an organization that exists if management takes NO action.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

A situation where a company implements new technology and hires an individual to help document new policies and procedures and develop training is an example of

A

change management.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

ERM according to COSO is

A

“a process, effected by an entity’s board of directors, management, and other personnel.”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

According to COSO, the position or internal entity that is best suited, as part of the enterprise risk management process, to devise and execute risk procedures for a particular department is:

A

The manager of a given department has a greater understanding of the risks and challenges associated with that department than would any other member of executive leadership. As such, the manager should be the individual tasked with devising and executing risk procedures for that department.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Criteria for evaluating Ent. Risk Mgmt.(ERM)

A

IS EAR AIM - The components of the enterprise risk management framework are the criteria used to evaluate its effectiveness. Each must be present & functioning.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly