Principles Flashcards
How does an organisation align risk management with its objectives?
It determines it’s risk management appetite after assessing its capacity for risk.
Define Risk Management Capacity
The maximum amount of risk an organisation can bear
Define Risk Management Appetite
The amount of risk an organisation is willing to accept.
What is the primary outcome of aligning with objectives?
Suitable risks are identified and that appropriate priority for action is given to individual risks and the overall risk associated with the activity.
To align with objectives an organisation must.
- Clearly state and agree strategy and policy
- Have clear objectives for the organisation
- Understand appetite and capacity for risk
- Have clear risk balance levels
In Fits the context. What are external contexts?
- Sector
- Markets
- Locations
- Regulatory regimes
Expand PESTLE for external context
Political Economic Sociology Technological Legal Environmental
Fits the context, expand the internal context
Culture
Structures
Stakeholder relationships
Processes deployed
Expand POTI for internal contexts
Processes and business models
Organisations Roles, responsibilities and cultures
Technology and tools
Information
Primary outcome of fits the context
Money is not wasted, either on an over engineered approach that wastes money because it cannot effectively deal with the risks posed by the external an internal environment within the risk capacity and appetite.
What’s are the ‘trigger categories’ within Engage stakeholders?
Users/beneficiaries (Customers/staff)
Those in governance (Board/regulators)
Influencers (Press/media)
Providers (Suppliers of goods)
Primary outcome of Engaging stakeholders?
The risk identification step of the process is thorough and the differences are understood and resolved as far as possible so that time and money are not wasted on misunderstandings which could be avoided.
Primary outcome of Provides Clear Guidance
The organisation can compare results with plans and make judgements about whether resources are being deployments optimally
Define Risk Tolerance?
The threshold levels of risk exposure which when exceeded will trigger an escalation
Primary outcome of Informs Decision Making
Important decisions are taken with explicit consideration of the impacts of risks and the status of risk management