Module 2 - Unit 5 Risk Assurance And Reporting Flashcards
Define control environment
The whole range and interaction of controls that address risks and support the achievement of objectives including resources, systems, processes, culture, structure and tasks.
Explain the term “reputational risk” and why it is different to other risk?
Most organisations regard damage to reputation as a consequence of the occurrence of risk events, rather than a risk in itself
Examples of internal risk reporting
Internal Risk reporting means the risk reports that the risk function provides for analysis to understand the risk position related to appetite. These will include positions reports showing exposures and positions against appetite.
- risk exposure
- kri’s
- staff turnover
- legal cases bought against the company
- injury to employees
- loss of existing business
- feedback and complaints
- audit findings
Examples of external risk reporting
External reporting is important since it improves market transparency.
Reports could include:
- SFCR and RSR under Pillar 3 of Solvency II (for the European operations)
- Financial reporting requirements in the relevant jurisdictions such as USA where would be US GAAP, US SEC and Sarbanes Oxley).
What does SFCR stands for?
Solvency and Financial Condition Report (SFCR) - it is publicly available and must provide profit and loss and balance sheet detail.
What does RTS stand for?
Report to Supervisors (RTS)
Three aspects that FRC states that a system of internal control should do:
- Facilitate business effective & efficient operation
- Help reduce the likelihood and impact of poor judgement in decision making
- Ensure the quality of internal & external reporting
- Ensure compliance with applicable laws, regulations and internal policies
What is the purpose of internal control?
- Protect assests
- Record keeping
- Operational efficiency
- Reliability of reporting
- Compliance
- Safeguard shareholders
- Adhere to policies and procedures
Components of reputational risk? (CASE)
Capabilities (purpose and resources)
Activities (processes, finances)
Standard (support)
Ethics (integrity & values)
Rating agency confidence
4 main areas of responsibility for an audit committee
External Audit
Internal Audit
Financial reporting
Regulatory reporting
5 internal risk reporting indicators
Risk exposure
KRI’s
Staff turnover
Injury to employees
Loss of existing business
3 external risk reports
SFCR, ICAAP, ORSA