ISO31000 - further details Flashcards
Name the ISO31000 principles
8 Principles
Integrated
Structured and comprehensive
Customised
Inclusive
Dynamic
Best available info
Human and cultural factors
Continual improvement
PACED combines eight principals in ISO31000 to provide five ATTRIBUTES of RM - Proportionate, Aligned, Comprehensive, Embedded and Dynamic.
Name the five ATTRIBUTES (Parts) of RM for ISO31000 (Acronym)
PACED - Proportionate, Aligned, Comprehensive, Embedded and Dynamic.
Name 4 OBJECTIVES of RM (Acronym)
MADE2 - mandatory, assurance, decision making, effective and efficient processes
How many ISO31000 Principles are they. Can you name them
ISO31000: 8 principles
1. Framework and processes should be customized and PROPORTIONATE.
2. APPROPRIATE and TIMELY involvement of stakeholders is necessary.
3. Structured and COMPREHENSIVE approach is required.
4. Risk management is an INTEGRAL part of all organisational activities.
5. Risk management anticipates, detects, acknowledges and responds to changes.
- Risk management explicitly considers any limitations of available information.
- Human and cultural factors influence all aspects of risk management.
- Risk management is continually improved through learning and experience.
Summarise the ISO31000 Principals
PACED
What does the P mean in PACED
Proportionate - STRUCTURED approach TAILORED to suit org and activity
One size does not fit all
Consistency in process and language used in org to build common understanding of RM
What does A mean in PACED
Aligned - INTEGRATED with other org activities which allows BAU to continue with ERM as a touchpoint throughout org and an ESCALATION mechanism to allow effective management of REPORTING
What does C mean in PACED
Comprehensive - Process encourages CONSISTENCY in RM PROCESS, and includes risk and controls in org and outside of it.
Gives effective OVERSIGHT OF RISK PROFILE and improves understanding of the existing, new and emerging risks INTERNALLY AND EXTERNALLY
What does the E mean in PACED
Embedded - Embedded in Org - encourages CHANGE in risk attitude, behaviour and culture to progress RM MATURITY and awareness of its value to org.
What does the D mean in PACED
Dynamic - Process doesn’t stop once risk is collated to register. This is only risk register writing.
Needs to continue to invest time in RM to keep process alive for Org so it can continue to support decision making and add value.
How does 31000 help build a RM Framework
Continuous improvement model PIML
What’s the difference between plan–do–check–act (PDCA) and Plan, Implement, Measure and Learn (PIML)
PDCA emanates from QUALITY RM
PIML puts emphasis on measuring and learning and distinguishes RM from quality management.
What’s the planning element of PIML contain
identifying and assess benefits (to new RM process or upgrading of current)
Scoping initiative (develop common taxonomy or improvements needed)
Establishing strategy, FW and R&R’s in a Risk Manual
What’s the implementing element of PIML contain
Produce RM guidelines and classification systems
Risk Protocols - FIRM, PESTLE and SWOT
Risk Assessment workshops - registers etc
Agreeing RA and Tolerance levels
What’s the Measuring element of PIML contain
Evaluate effectiveness of controls (so goes beyond the ‘check’ phase of PDCA as measures existing controls)
Align RM with other activities (and existing process)
Embed risk aware culture
What’s the learning element of PIML contain
Learning from ‘measurement’ activity
Monitor risk perf (KPI’s) - to measure ERM contribution
Internal audit team to review learning from any self assessment or audit reports.
Report in line with obligations - boards etc
What is ISO31000 definition of risk
effect of uncertainty on objectives
What is ISO31000 definition of rM
coordinated activities to direct and control an org about risk
What is ISO31000 definition of Stakeholder Management
person or org that can affect, be affected by, or perceive themselves to be affected by a decision or activity
What is ISO31000 definition of risk source
an element which alone or in combination has the potential to give rise to a risk
What is ISO31000 definition of event
occurrence of change of a particular set of circumstances
What is ISO31000 definition of consequences
outcome of an event affecting objectives
What is ISO31000 definition of likelihood
chance of something happening
What is ISO31000 definition of control
a measure that maintains and or modifies risk