Nov 2020 Flashcards
1
Q
What are the 4 Ts of risk?
A
Transfer; treat; tolerate; terminate
2
Q
What are the four risk control techniques?
A
Preventive; corrective; directive; detective
3
Q
Name 26 risk treatment controls
A
- alarms (F/Det)
- Audits and review (F/Det)
- Business recovery plans (F/Dir)
- Comms (F&I/All)
- Emergency shut down (F/Corr)
- Inspections (F/Det)
- Maintenance (F/Prev)
- Policies and procedures (F/Dir)
- Property protection devices (F/Prev)
- Safety equipment (F/Prev)
- Safety training (F/Dir)
- Testing (F/Det)
- Tone from top (I/Prev & Dir)
- Action plans (F/Dir)
- Automation (F/Prev)
- Computer firewalls (F/Prev)
- Data backup (F/Corr)
- Due diligence (F/Det)
- Financial provisions (F/Corr)
- Insurance contracts (F/Corr)
- Redundancy (F/Corr)
- Segregation of duties (F/Prev)
- Skills and professional training (F/Prev)
- Soft skills training (I/All)
- Team building (I/All)
- Systems based validation (F/Det)
4
Q
What are the risk perceptions (6)?
A
- Choice
- Control
- Familiarity
- Distance
- Media
- Randomness
5
Q
What are the three ERM characteristics?
A
- holistic focus
- emphasis on value added risk management
- blend of formal and informal risk management tools and actions
6
Q
Name 8 ERM benefits
A
- improved reporting to support strategic decision-making
- avoidance of silos
- improved operational efficiency and cost effectiveness
- improved profit and equity value
- improved ability to achieve other business objectives
- consistent decision-making
- effective resource allocation for risk management at local level
- spread risk ownership - managed by local experts locally
7
Q
What makes up the triple bottom line?
A
People; Planet; Profit
8
Q
What is a risk event?
A
A random, discrete occurrence which may affect, positively or negatively, an organisation.
9
Q
Name 6 non-analytical techniques
A
- expert judgement
- focus groups/surveys
- checklists
- physical inspections
- loss events and near miss reporting (learning)
- bow-tie/PESTLE/SWOT/etc
10
Q
Name 4 analytical techniques
A
- SWIFT (Structured What If Technique)
- Delphi technique (anon.)
- Root cause analysis
- System and process mapping
11
Q
Name the (5) components of compliance management
A
- establish compliance standards
- develop processes and controls
- link with internal control
- risk-based compliance
- roles and responsibilities
12
Q
Name compliance tools (9)
A
- policies and procedures
- codes of conduct
- reviews and audits (assessments)
- impact analysis (form of RM)
- gap analysis and action planning
- compliance reporting
- HR-related controls
- whistleblowing
- establish appropriate culture