Risk-management as a foundation of organisational success Flashcards

1
Q

Risk-management and anticipation (2)

A
  • Important to anticipate and predict risk events so that the probability of negative events can be reduced, and positive ones increased
  • Not all risks can be identified (anticipated), and even if they can, their probability and impact may be difficult to quantify with accuracy or affect
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Risk-management and resilience (2)

A
  • Black swan events are hard to predict and cannot be quantified => cannot be anticipated
  • Risk-man can help orgs respond effectively to, and recover quickly from, risk events that have not been anticipated = resilience
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

3 ways in which orgs may invest in resilience (names of types)

A
  • Effective crisis management
  • Business continuity management
  • Organisational learning
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Investing in resilience - what is effective crisis management?

A

Responding quickly to mitigate the immediate effects of unanticipated events as they unfold

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Investing in resilience - what is business continuity management?

A

Recovering quickly from the aftermath of an unanticipated event to ensure the org is able to maintain its operations and achieve its objectives

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Investing in resilience - what is organisational learning?

A

Reviewing past unanticipated events in order to improve future resilience

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Negatives of risk events due to a breakdown in internal control arrangements (3)

A
  • Very costly
  • Damage reputation
  • Divert attention from strategic and operational priorities
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Other than through regular risk-man activities, 3 specialist internal control management tools that can be used to strengthen internal control

A
  • Risk-based compliance reviews
  • Internal audits
  • External audits
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Strengthening internal controls - risk-based compliance reviews (2)

A
  • Most orgs assess whether employees are complying with applicable laws and regulations
  • More detailed and frequent reviews conducted in areas with higher risk of non-compliance or consequences of non-compliance are higher
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Strengthening internal controls - internal audits (2)

A
  • Conducted by most orgs to check effectiveness and efficiency or operational processes
  • Can identify failures in design or application of risk controls
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Strengthening internal controls - external audits (2)

A
  • External auditors review annually whether fin. reporting controls are adequate
  • Many go beyond fin. reporting to review broader governance and internal control environment, as this impacts financial statements as well (espec. going concern statement)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What do orgs generally focus on re. the link between risk and strategy?

A

Assessing and managing the risks that arise from a chosen strategy or different components of a strategy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

A strengthened risk-man framework would include: (4)

A
  • Initiation of a strategic review
  • Assessment of alternative strategies
  • Execution of a strategy
  • Monitoring and managing risks arising from a chosen strategy
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Advantages of linking risk to strategy: (2)

A
  • Allows for clearer assessment of aggregate risks related to a particular strategy
  • Enables board-level discussions on whether alternative strategies present a more attractive risk/return choice for an org
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

5 new processes and behaviours boards are incorporating into more significant role in linking risks to strategy:

A
  • Challenging management on key risk-appetite assumptions and definitions
  • Seeking more comprehensive assurances on how non-financial risks are monitored, inc. quantification
  • Encouraging management to discuss risks in relation to strategy
  • Hiring independent external advisors to evaluate risks of sizeable acquisitions
  • Connecting internal audit function to strategic planning and risk-man functions
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Difference between day-to-day risk taking and strategic risk taking

A

Day-to-day risk-taking = optimisation opportunities found within existing risk-man framework based on current strategy

Strategic risk-taking = making strategic business decisions that may leaf to an overall increase in total value, often requiring a recalibration of existing risk-man framework

17
Q

Real world example of successful positive risk taking

A

Facebook’s acquisition of instagram when it was not revenue making for USD1 billion.

Now its revenue is USD5 billion and it has a valuation of USD100 `billion

18
Q

4 barriers holding orgs back from strategic risk-taking:

A

Corporate culture - management does not support strategic risk-taking

Lack of risk prioritisation - higher priority placed on day-to-day risks at expense of missing the bigger pictures

Failure to perform adequate due diligence - management and board uncomfortable to take strategic risks due to improperly conducted risk/benefit analysis

Lack of designated risk manager to stay on top of emerging trends and navigate strategic risk-taking ideas

19
Q

Org’s with which two risk related characteristics are most likely to see their value significantly eroded or destroyed?

A
  • Promote excessively high-risk-taking behaviours
  • Have inadequate compliance monitoring or training procedures
20
Q

Which sector has to deal with most prescriptive regulatory risk framework?