M2 Enterprise Risk MGMT Frameworks Flashcards
What are the 5 components of Enterprise Riske MGMT
- Governance and Culture
- Strategy and Objective Setting
- Performance
- Review and Revision
- Information, Communication, and Reporting (ongoing)
What are inherent risks
Inherent risk is the risk that exists to an entity when MGMT takes no action to alter the severity of the risk.
What are the 5 components of COSO’s ERM?
Mnemonic GO PRO
Goverenance and Culture
Strategy and Objective-Setting
Performance
Review and Revision
Information, Communication, and Reporting (Ongoing)
The ERM Framework states that the organization must identify events both positive and negative, as part of risk MGMT program. At what point does the organization identify the event/risk?
Events/ Risks can only be identified AFTER the organizarional objectives are identified.
Which principles support the Governance and culture component?(Hint: Mnemonic DOVES)
Desired culture
exercised board Oversight
demonstrates commitment to core Values
Which principles support the Strategy and objective setting component? (Hint: Mnemonic SOAR)
evaluates alternative Strategies
formulates business Objectives
Analyzes business context
defines Risk appetite
Which principles support the Performance component? Hint: Mnemonic VAPIR
View
Assessess severity of risk
Prioritizes risks
Identifies risks
implements Risk
Which principles supports the Review and revision component? ( Hint Mnemonic SIR)
Substantial change
Pursues Improvement in the ERM
Reviews risk and performance
What are residual risks?
Risdual risk = Inherent risk- Impact of MGMT actions