ORA Prelim (M3) Flashcards

1
Q

Defines how information on risk is communicated throughout the org

is the RM and arrangements of an Org; Lines of communication for reporting on RM issues

Includes:
commitee structure, roles and responsi, reporting reqs

A

Risk Architecture

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Defines the overall objectives that the org is trying to achieve with respect to risk management

Includes Philosophy, arrangements, appetite and attitude to risk, benchmark tests, assessement techniques, risk priorities

A

risk strategy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

are the systemes, standards, and procedures that are put in place in order to fulfill the defined risk strategy

Includes:
Training and communication, R. Clasification, assessment procedures, control rules and procedure, responding to incidents

A

risk protocols

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Per ______, RM framework should include the objectives, mandate and comitment to accountabilities, resources, processess, and activities, and that the framework should be embeded within the org’s overall stratefgic and operational policies and practices

A

BS 31100

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Needs to be set out in RM policy statement of the org

its important components is that there is rm input into STOC compliance processes of the org.

A

RM strategy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Are procedures and protocols for undertaking the assesment of risks to strategy, proejcts, and operations in an org

Provide guidance on the freq and nature of risk reports and who is responsible for compiling

A

RM Protocols

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

5 Components of RM Protocols include:

A

I. R Assessment Procedures

II. R Control objectives

III. R Resourcing Arrangement

IV. Reaction Planning Requirements

V. R Assurance systems

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

read only

I. R Assessment Procedures
— Gov Procedures, Respons to R., Proced for strat and budgets

II. R Control objectives
— Brand mgmt, healt & safety; environment; Contract rm

III. R Resourcing Arrangement
— Opport mgmt, resource allocation, insurance and captive insurane

IV. Reaction Planning Requirements
— Loss and claims mgmt, disaster and recovery

V. R Assurance systems
— Risk reg, RM committee, self cert

A

k

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

— list of RM records that should be kept on file

A

RM Documentations

These should be kept for decision making, advice for managers, provide auditors controls have been implemented

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Read only

Importance of Records management

— Reduce time
— Sharing of info
— reduce duplic of info
— Supports RM and Business continuity planning

A

k

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

4 types of RM Docs

A

I. R governance
II. R Response
III. Event Reports
IV R Performance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Docs that include RM policies, procedures, protocols, and guidelines

A

RM Manual

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What should RM Manual include?

Give 14

A

– RM and Internal Objectives
(4) R Strategy, Archi, and Assessment, protocols
– Desc of control environment
– Level and nature of risk that is acceptable
– arrangements for communicating risk info
— R mitigation reqs and control mechs
— Criteria for monitoring and benchmarking risks
— Allocation of appropriate resources
— R priorities and performance targets
— RM calendar

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Guidelines in Creating the Common Risk Language (FICS)

A

Focused
Impact
Concise
Standard Format

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

RM Responsibilities for ____:

  • Determine strat approach to risk
  • ESTABLISH the structure for risk management
  • Understand the most significant risks
  • Consider the risk implications of poor decisions
  • Manage the organization in a crisis
A

CEO

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

RM Responsibilities for ____:

  • Build risk-aware culture within the location
  • Agree risk management performance targets for the location
  • Evaluate reports from employees on risk management matters
  • Ensure implementation of risk improvement recommendations
  • Identify and report changed circumstances/risks
A

Location Manager

17
Q

RM Responsibilities for ____:

  • Understand, accept and implement RM processes
  • Report inefficient, unnecessary or unworkable controls
  • Report loss events and near-miss incidents
    ■ Cooperate with management on incident investigations
  • Ensure that visitors and contractors comply with procedures
A

Indiv Employees

18
Q

RM Responsibilities for ____:

  • Develop the risk management policy and keep it up-to-date
    ■ Facilitate a risk-aware culture within the organization
  • Establish internal risk policies and structures
  • Coordinate the risk management activities
  • Compile risk information and prepare reports for the board
A

Risk manager

19
Q

RM Responsibilities for ____:

  • Assist the company in establishing specialist risk policies
  • Develop specialist contingency and recovery plans
    Keep up-to-date with developments in the specialist area
  • Support investigations of incidents and near misses
  • Prepare detailed reports on specialist risks
A

Specialist RM Functions

20
Q

RM Responsibilities for ____:

  • Develop a risk-based internal audit program
  • Audit the risk processes across the organization
  • Provide assurance on the management of risk
  • Support and help develop the risk management processes
    Report on the efficiency and effectiveness of internal controls
A

Audit Manager

21
Q

RM Responsibilities for ____:

plays a key part in bringing together disparate risk management processes to ensure that limited company resources are applied effectively. The COSO ERM Framework defines their rols as working with other managers to establish effective risk management, monitoring progress, and assisting other managers in reporting relevant risk information up, down and across the organization.

22
Q

Risk aware culture is achived by LILAC.

WHAT IS LILAC

A

Leadership
Involvement
Learning
Accountability
Communication

23
Q

Means by which an org receives reasonable assurance that the sig risks are controlled

Audit committe seek assurance that all sig risks are being managemed and that controls have been implemented

A

Risk Assurance

Benefits:
■ Builds confidence with stakeholders;
* Provides reassurance to sponsors and financiers;
■ Demonstrates good practice to regulators;
* Prevents financial and other surprises;
■ Reduces the chances of damage to reputation;
* Encourages the risk culture within the organization;
* Allows more secure delegation of authority.

24
Q

5 Sources of Risk Assurance

  • ____ by use of a recognized framework such as CoCo or COSO in order to gain a quantitative evaluation of the control environment.
  • ____ - produced by internal audit and external auditors on a range of issues including risk assessment, implementation, compliance and training.
  • _____ on such issues as risk performance indicators, CRSA, response to audit recommendations and reports on incidents that have occurred.
  • _____ - on risk-related issues, losses, significant weaknesses in control measures and details of any material losses suffered by the unit
  • _____ on topics such as the risk management policy, health and safety policy, business continuity plans and disaster recovery plans.
A
  • Culture measurement
  • audit reports
  • unit reports
  • performance of the unit
  • unit documentation
25
Q

A _________________ is a wholly owned subsidiary insurer formed to provide risk mitigation services for its parent company or related entities

A

captive insurance company