ORA Prelim (M3) Flashcards
Defines how information on risk is communicated throughout the org
is the RM and arrangements of an Org; Lines of communication for reporting on RM issues
Includes:
commitee structure, roles and responsi, reporting reqs
Risk Architecture
Defines the overall objectives that the org is trying to achieve with respect to risk management
Includes Philosophy, arrangements, appetite and attitude to risk, benchmark tests, assessement techniques, risk priorities
risk strategy
are the systemes, standards, and procedures that are put in place in order to fulfill the defined risk strategy
Includes:
Training and communication, R. Clasification, assessment procedures, control rules and procedure, responding to incidents
risk protocols
Per ______, RM framework should include the objectives, mandate and comitment to accountabilities, resources, processess, and activities, and that the framework should be embeded within the org’s overall stratefgic and operational policies and practices
BS 31100
Needs to be set out in RM policy statement of the org
its important components is that there is rm input into STOC compliance processes of the org.
RM strategy
Are procedures and protocols for undertaking the assesment of risks to strategy, proejcts, and operations in an org
Provide guidance on the freq and nature of risk reports and who is responsible for compiling
RM Protocols
5 Components of RM Protocols include:
I. R Assessment Procedures
II. R Control objectives
III. R Resourcing Arrangement
IV. Reaction Planning Requirements
V. R Assurance systems
read only
I. R Assessment Procedures
— Gov Procedures, Respons to R., Proced for strat and budgets
II. R Control objectives
— Brand mgmt, healt & safety; environment; Contract rm
III. R Resourcing Arrangement
— Opport mgmt, resource allocation, insurance and captive insurane
IV. Reaction Planning Requirements
— Loss and claims mgmt, disaster and recovery
V. R Assurance systems
— Risk reg, RM committee, self cert
k
— list of RM records that should be kept on file
RM Documentations
These should be kept for decision making, advice for managers, provide auditors controls have been implemented
Read only
Importance of Records management
— Reduce time
— Sharing of info
— reduce duplic of info
— Supports RM and Business continuity planning
k
4 types of RM Docs
I. R governance
II. R Response
III. Event Reports
IV R Performance
Docs that include RM policies, procedures, protocols, and guidelines
RM Manual
What should RM Manual include?
Give 14
– RM and Internal Objectives
(4) R Strategy, Archi, and Assessment, protocols
– Desc of control environment
– Level and nature of risk that is acceptable
– arrangements for communicating risk info
— R mitigation reqs and control mechs
— Criteria for monitoring and benchmarking risks
— Allocation of appropriate resources
— R priorities and performance targets
— RM calendar
Guidelines in Creating the Common Risk Language (FICS)
Focused
Impact
Concise
Standard Format
RM Responsibilities for ____:
- Determine strat approach to risk
- ESTABLISH the structure for risk management
- Understand the most significant risks
- Consider the risk implications of poor decisions
- Manage the organization in a crisis
CEO
RM Responsibilities for ____:
- Build risk-aware culture within the location
- Agree risk management performance targets for the location
- Evaluate reports from employees on risk management matters
- Ensure implementation of risk improvement recommendations
- Identify and report changed circumstances/risks
Location Manager
RM Responsibilities for ____:
- Understand, accept and implement RM processes
- Report inefficient, unnecessary or unworkable controls
- Report loss events and near-miss incidents
■ Cooperate with management on incident investigations - Ensure that visitors and contractors comply with procedures
Indiv Employees
RM Responsibilities for ____:
- Develop the risk management policy and keep it up-to-date
■ Facilitate a risk-aware culture within the organization - Establish internal risk policies and structures
- Coordinate the risk management activities
- Compile risk information and prepare reports for the board
Risk manager
RM Responsibilities for ____:
- Assist the company in establishing specialist risk policies
- Develop specialist contingency and recovery plans
Keep up-to-date with developments in the specialist area - Support investigations of incidents and near misses
- Prepare detailed reports on specialist risks
Specialist RM Functions
RM Responsibilities for ____:
- Develop a risk-based internal audit program
- Audit the risk processes across the organization
- Provide assurance on the management of risk
- Support and help develop the risk management processes
Report on the efficiency and effectiveness of internal controls
Audit Manager
RM Responsibilities for ____:
plays a key part in bringing together disparate risk management processes to ensure that limited company resources are applied effectively. The COSO ERM Framework defines their rols as working with other managers to establish effective risk management, monitoring progress, and assisting other managers in reporting relevant risk information up, down and across the organization.
CRO
Risk aware culture is achived by LILAC.
WHAT IS LILAC
Leadership
Involvement
Learning
Accountability
Communication
Means by which an org receives reasonable assurance that the sig risks are controlled
Audit committe seek assurance that all sig risks are being managemed and that controls have been implemented
Risk Assurance
Benefits:
■ Builds confidence with stakeholders;
* Provides reassurance to sponsors and financiers;
■ Demonstrates good practice to regulators;
* Prevents financial and other surprises;
■ Reduces the chances of damage to reputation;
* Encourages the risk culture within the organization;
* Allows more secure delegation of authority.
5 Sources of Risk Assurance
- ____ by use of a recognized framework such as CoCo or COSO in order to gain a quantitative evaluation of the control environment.
- ____ - produced by internal audit and external auditors on a range of issues including risk assessment, implementation, compliance and training.
- _____ on such issues as risk performance indicators, CRSA, response to audit recommendations and reports on incidents that have occurred.
- _____ - on risk-related issues, losses, significant weaknesses in control measures and details of any material losses suffered by the unit
- _____ on topics such as the risk management policy, health and safety policy, business continuity plans and disaster recovery plans.
- Culture measurement
- audit reports
- unit reports
- performance of the unit
- unit documentation
A _________________ is a wholly owned subsidiary insurer formed to provide risk mitigation services for its parent company or related entities
captive insurance company