Module 1 Unit 2 - Risk Management Standards Flashcards
Name five risk management processes
8R's & 4T's IRM2002 COSO ERM ISO 31000 The Orange Book
Which one of the following risk standards has ‘Control Activities’ as the feature in the risk process?
A. COSO ERM cube
B. ISO 31000(2018)
C. The Orange Book
D. IRM (2002) Standard
A. COSO ERM Cube
What is the definition of a ‘Risk Standard’
Guide for managing risk,
- risk framework
- risk process
What is the definition of a ‘Risk Framework’
Also known as risk management context.
This comprises of
- Risk strategy
- Risk architecture
- Risk protocols
and forms the Risk Standard(context) which helps drive the risk process
What is the definition of a ‘Risk Process’
The stages in the process of managing risk,
which is driven mainly by how you set up the framework (but is also affected by the internal and external environment)
What is the definition of ‘Risk Architecture’
Part of the risk framework, which focuses on answering the question ‘Who does what’ in the organisation in relation to risk management
What is the definition of ‘Risk Context’
This covers the three layers of the organisation which together drive the risk process; they are the
- external environment
- Internal environment
- the risk management framework (context)
What is the definition of ‘Risk Protocols’
A set of
- Tools
- Procedures
- Instructions
that an organisation has for managing risk
What is the definition of ‘Risk Strategy’
The agreed overriding purpose and aims of risk management in the organisation,
This involves the publication of a risk policy document and the setting of the risk appetite
List the 8R’s and 4T’s
8R’s
- Recognition of risks
- Rating of risks
- Ranking of risk against criteria
- Response to risk (see 4T’s)
- Resourcing controls
- Reaction Planning
- Reporting on risks
- Reviewing and monitoring
4T’s
- Tolerate
- Treat
- Transfer
- Terminate
Which one of the following definitions is the same as the definition of the risk management context.
A. Risk management strategy
B. Risk management process
C. Risk management framework
C. Risk Management Framework
Which part of the risk framework focuses on answering the question ‘who does what’ in the organisation in relation to risk management.
A. Risk architecture
B. Risk context
C. Risk protocols
A. Risk Architecture