Risk Management Flashcards
Is “a process to identify, assess, manage, and control potential events or situations to provide reasonable assurance regarding the achievement of the organization’s objectives”
Risk Management
The internal audit activity must do the following for the risk management processes:
Evaluate the effectiveness and contribute to the improvement
Risk management processes include:
1) Risk identification
2) Risk assessment and prioritization
3) Risk response
4) Risk monitoring
Must be performed for the entire entity. It should consider past events and future possibilities.
Risk Identification
The risk assessment process involves (a) estimating the significance of an event, (b) assessing the event’s likelihood, and (c) considering the means to manage the risk
Risk assessment and prioritization
Strategies for risk response include:
1) Risk avoidance
2) Risk retention
3) Risk sharing
4) Risk exploitation
(a) Tracks identified risks, (b) evaluates current risk response plans, (c) monitors residual risks, and (d) identifies new risks.
Risk monitoring
Risk management is a key responsibility of:
Senior management and the board
Senior management and the board determine the internal audit activity’s role in risk management based on factor such as:
(a) Organizational culture
(b) Abilities of the internal audit activity staff, and
(c) Local conditions and customs
Determining whether risk management processes are effective is a judgement resulting from:
The internal auditor’s assessment
To form an opinion on the adequacy of the risk management processes, the internal auditor should:
Obtain sufficient appropriate evidence regarding achievement of key objectives.
The COSO Framework defines ERM as:
A process, effected by an entity’s board of directors, management, and other personnel, applied in strategy setting and across the enterprise, designed to identify potential events that may affect the entity, and manage risk to be within its risk appetite, to provide reasonable assurance regarding the achievement of entity objectives.”
ERM allows management to optimize stakeholder value by:
Coping effectively with uncertainty and risk, helping management to
1) Reach objectives
2) Prevent loss of reputation and resources
3) Report effectively, and
4) Comply with laws and regulations.
When it comes to ERM the CEO:
Sets the tone at the top and has ultimate responsibility for ERM
Who has an oversight role of the ERM?
The board