Risk Management Flashcards
Situation in which a person or organization may benefit from undue influence due to involvement in outside activities, relationships, or investments that conflict with or have an impact on the employment relationship or its outcomes.
Conflict of interest
Amount of uncertainty an organization is willing to pursue or to accept to attain its risk management goals.
Risk appetite
Tool used to gather individual assessments of various characteristics of risk (e.g., frequency of occurrence; degree of impact, loss, or gain for the organization; degree of efficacy of current controls).
Risk scorecard
Amount of uncertainty that remains after all risk management efforts have been exhausted.
Residual risk
Expected monetary loss every time a risk occurs; calculated by multiplying asset value by exposure factor.
Single loss expectancy (SLE)
Amount of uncertainty an organization is willing to pursue or to accept to attain its risk management goals.
Risk tolerance
Reporting of an organization’s violations of policies and processes by employees.
Whistleblowing
Organization’s desired gain or acceptable loss in value.
Risk position
Action taken to manage a risk.
Risk control
System for identifying, evaluating, and controlling actual and potential risks to an organization.
Risk management
Expected monetary loss for an asset due to a risk over a one-year period; calculated by multiplying single loss expectancy by annualized rate of occurrence.
Annualized loss expectancy (ALE)
Principle that organizations should take all steps that are reasonably possible to ensure the health, safety, and well-being of employees and protect them from foreseeable injury.
Duty of care
Uncertainty that has an effect on an objective, where outcomes may include opportunities, losses, and threats.
Risk
Situation in which an agent (e.g., an employee) makes decisions for a principal (e.g., an employer) potentially on the basis of personal incentives that may not be aligned with the principal’s incentives.
Principal-agent problem
Protocol that an organization implements when an identified risk event occurs.
Contingency plan