Risk and Control Self-Assessments Flashcards

1
Q

what is a RCSA?

A

IT IS A SYSTEMATIC PROCESS FOR IDENTIFYING AND ASSESSING RISKS AND CONTROLS WITHIN AN ORGANIZATION.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is the purpose of the RCSA?

A

Helps in evaluating the effectiveness of risk management practices and control mechanisms

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

what is the importance of the RCSA?

A
  • Enhances risk awareness and ownership among employees.
  • Identifies potential risk exposures and control weaknesses.
  • Provides a structured approach for continuous risk management.
  • Supports regulatory compliance and risk governance.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

what are the components of the RCSA?

A
  • Risk Identification
  • Risk Assessment
  • Control Identification
  • Control Assessment
  • Action Plans
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

what are the exercises as part of the RCSA?

A
  • Key risks exposures review
  • An assessment of controls (preventative/detective)
  • Estimates of the expected losses
  • Estimates of stress shortfalls or stressed losses
  • list of further mitigating action plans
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

what are the benefits of the RCSA?

A
  • Enhanced risk awareness
  • Improved Risk management
  • regulatory compliance
  • informed decision-making
  • continuous improvement
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

what are the different levels of the impact scale?

A
  • extreme
  • major
  • moderate
  • low
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

what is the role of the heat map?

A

it combines the likelihood and impact of risks identified and action plans off the back of this can be made

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

what are the different techniques for risk identification?

A
  • brainstorming
  • process mapping
  • interviews and surveys
  • review of past incidents
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

what are the different methods of risk assessment?

A
  • qualitative (subjective judgement)
  • quantitative (numerical data and statistical models)
  • risk matrix
  • scenario analysis
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

what are the different methods of control assessment?

A
  • testing
  • self-assessment (by employees)
  • audits and reviews
  • benchmarking (to industry best practices)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q
A
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

what are the contents of an action plan?

A
  • development of the action plan
  • assignment of responsibilities
  • follow-up and monitoring
  • review and updating of the action plan
How well did you know this?
1
Not at all
2
3
4
5
Perfectly