Module 2 - Unit 2 Risk Strategy And Framework Flashcards

1
Q

What is RIMS?

A

Risk Maturity Model (RIMS) it’s a model used to assess an organisation’s risk maturity. Uses five leves:
•Ad-hoc
•Initial
•Repeatable
•Manager
•Leadership

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Explain the 3 Lines of Defence model

A

It’s a common risk governance structure

First Line - functions that own and manage risk ( service managers)
Second Line - oversight risk (risk management and compliance)
Third Line - Internal Audit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

7 elements of Risk Management Framework

A

Risk Policy
Risk Governance
Risk Appetite and tolerance
Risk identification process
Risk assessment process
Risk control process
Risk reporting
Key indicators
Risk typology and language
Risk culture

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a risk management framework

A

Risk Management framework is a system by which:
• risk management activity is linked to the organisation’s strategic objectives
• risks are identified, described and quantified
• risks are reported
• risks are controlled
• risks are monitored

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

3 risk management standards

A

IRM Risk Management Standard
COSO ERM framework
ISO31000 - introduced in 2009
Basel II

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

List McKinsey’s four levels of risk maturity

A

• initial transparency
• systematic risk reduction
• risk-return management
• risk as competitive advantage

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

List 2 risk quantification approaches

A
  1. Regulatory prescribed approaches (standard formulas)
  2. Stress test ( historical and multiyear)
  3. Internal models ora VaR approaches
  4. Risk registers
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the advantages of a risk management information system?

A
  • binds together work done by risk function and other teams
  • uniformity of data gathering, storage and analysis
  • reduced potential for errors and omissions
  • ability to link audit findings to controls
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

List 7 items set out by risk protocols and policies

A
  1. The techniques used in risk identification
  2. The format and content of the organisation’s risk register
  3. How risk ownership is assigned to staff
  4. Requirements on entering risk events into the issues and events log
  5. Reporting requirements - such as weekly or monthly reports and risk analysis, performance against KRI
  6. Approval processes for expenditure on risk improvement actions
  7. Control and sign-off processes
  8. Template documents for risk assessments and where required certification
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Risk Maturity Hopkins (4 N’s)

A

Naive
Novice
Normalised
Natural

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Explain the difference between centralised, decentralised and hybrid organisations

A

• Centralised businesses have a large head office with numerous functional divisions
• Decentralised business have a small head office with most functions being carried out at operational level
• Hybrid organisations may have certain functions at head office level (e.g., finance) whereas others are delegated to operating subsidiaries.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Risk strategy

A

Risk Management strategy includes:
- risk appetite and tolerance statement
- risk policy
- risk identification process
- risk quantification approaches
- risk control processes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly