Module 1 - Unit 2 Risk Management Standards Flashcards
What is the definition of Risk Management Framework?
Also known as the risk management context. Consist in activities to do to manage the risk across the organisation. This comprises the (RASP)
Risk
Architecture
Strategy and
Protocols
What is Risk Management Process?
The process to follow to minimise risk in the organisation which is driven by how the framework is set up (it can also be affected by internal/external environment)
What is Risk Standard?
A published guide for managing risk. Usually comprising a risk Framework and a risk Process.
What Is Risk Architecture?
Risk Architecture - focuses on answering the question of who does what in relation to risk management.
What is Risk Strategy?
Risk Strategy - the agreed overriding purpose and aims of risk management in the organisation
What is Risk Protocols?
Risk Protocols - the set tools, procedures and instructions that the organisation has for managing risk. Involves publication of risk policy document and setting of risk appetite.
What is Risk Context?
Risk Context - described as RASP or the risk management framework within the organisation.
What are the 3 elements relating to risk context?
RASP
Internal context - relates to the organisation’s structure, objectives, policies, strategies, process and culture.
a) the org. divisions, departments,structures
b) internal stakeholders
c) corporate governance
d) factors that influence how the org will set and achieve its objectives
External context - is the environment within which the organisation exists.
a) social and cultural
b) the industry, products
c) key drivers
d) relationship with stakeholders
Basel III (3 Pillars) - applies to banks
Pillar 1 - Capital adequacy
Pillar 2 - Supervisory requirements to review Risk Capital (ICAAP)
Pillar 3 - Disclosure of information (Market discipline)
Solvency II (3 Pillars) - applies to insurers
Pillar 1 - Quantitative Requirement (Solvency Capital Requirement (SCR)
Pillar 2 - Qualitative Requirements (Governance, supervisory Review (ORSA)
Pillar 3 - Reporting & Disclosure Requirements
What does ICAAP stands for?
Internal Capital Adequacy Assessment Process
What does ORSA stands for?
Own Risk and Solvency Assessment
What are the 3 Risk Management Standards?
IRM
COSO ERM CUBE
ISO31000 (2018)
Name 3 steps in Risk Management Process
- Identify risks
- Evaluate risk
- Manage risk
COSO 4 categories of organisational objectives
Strategy
Operations
Reporting
Compliance
ISO31000 - 3 components
Principles + Framework + Process
ISO31000 - 8 Principles
- Customised to the organisation
- Inclusive
- Structured & Comprehensive approach
- Integrated approach
- Dynamic
- Best available information
- Human & cultural factors influence all aspects of RM
- Continual Improvement through learning and experience
What are the steps to implement ISO31000 Framework?
Leadership & commitment at board
Design of framework
Implement risk management
Monitor and review framework
Improve framework
What are the elements of the ISO31000 risk management process?
- Scope, context, criteria
- Risk Assessment ( identify, analise, evaluate)
- Risk Treatment
These are bordered by communication, monitoring and recording.
COSO ERM cube sides
Front - RM process
Top - Organisational objectives
Side - Implementation process
COSO 4 implementation elements
- Entity level
- Division
- Business Unit
- Subsidiary