Risk-management frameworks and standards Flashcards

1
Q

Why is there a need for a formal, explicit risk-man system, and not to simply rely on intuitive, instinctive, implicit risk-man? (3)

A
  • Relying on intuition will lead to inconsistencies and incorrect decisions
  • Formal system ensures risk-man decisions support achievement of strategic objectives
  • Formal system ensures risk preferences of shareholders are taken into account
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What does a framework include? (4)

A
  • Policies
  • Procedures
  • Processes
  • Tools
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the ultimate aim of a risk-man framework?

A

Add value to an organisation, helping it to operate in a successful and sustainable way over the long term

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

At a minimum, a typical risk-man framework will include mechanisms for: (4)

A

Risk identification - identification of risks that could impact org in positive or negative way

Risk assessment - assessing significance of identified risks, in order to prioritise attention and resources

Risk monitoring - monitoring to help detect any changes in the org’s exposure to identified risks

Risk control - controlling the org’s exposure to the identified risks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Risk identification, assessment, monitoring and control are often known collectively as:

A

the risk-management process

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

ISO 31000:2018 - 3 core elements around which risk-man process will be designed

A
  • Risk-man architecture (committees, reporting structures, etc.)
  • Risk-man strategy (policies, appetite, etc.)
  • Risk-man protocols (processes and procedures)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

10 key components of typical risk-man system

A
  • risk-man policy or series of policies
  • risk-man procedures
  • risk-man information systems
  • risk reports
  • risk-appetite statement
  • assessments of risk culture
  • training and awareness activities
  • risk-governance and compliance arrangements
  • specialist staff and functions
  • risk committees (or audit and risk committees)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

An org’s risk-man policy/policies outline/s: (4)

A
  • its aims and objectives & how these support wider strategic objectives
  • processes, procedures and activities that comprise framework
  • governance arrangements, such as a risk committee
  • allocation of roles and responsibilities
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

A risk management procedure will…

A

relate to the assessment and control of related risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

3 examples of risk-man procedures

A
  • Manual handling procedures for heavy objects
  • Operating machinery
  • Procedures for making financial transactions
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

2 benefits of using a risk-man information system (RMIS) to support risk assessment, monitoring and control activities

A
  • Eases coordination of risk-man activities
  • Reduce time and effort required to produce risk-man reports on exposures and effectiveness of controls
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is a purpose of a risk report?

A

To help management understand the organisation’s risk exposures and to make effective risk-man decisions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What may dictate that risk reporting needs to be more frequent?

A

If risk exposures are changing quickly

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What will a risk-appetite statement outline?

A

The types and levels of risk that an organisation is willing to take in the pursuit of its objectives, as well as the risks it is not willing to take (or will only tolerate in specific circumstances)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Will risk-appetite statements be made public?

A

It can be, but doesn’t need to be, so sometimes (if there is a benefit)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Risk-man training and awareness will:

A
  • help employees understand how to identify, assess, monitor and control risks
  • explain the importance of risk-man for org and stakeholders
  • explain benefits and costs associated with taking specific risks
  • reinforce the contents of policies and procedures, use the RMIS, etc.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What are the aims of risk-governance and compliance arrangements?

A
  • to ensure compliance with policies, processes and procedures that comprise a risk-man framework
  • to identify and address any weakness in design and application of framework
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

Which risk-man specialist staff may be recruited? (5)

A
  • H&S professionals
  • Information security professionals
  • Business continuity managers
  • General risk managers
  • Compliance managers
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

What is the purpose of a risk committee?

A

Oversee and coordinate the design and operation of risk-man framework

20
Q

Risk committees activities will include: (4)

A
  • Ensuring that risks are managed in a consistent and objective-supporting way
  • Monitoring more significant risks
  • Balances risk preferences of stakeholders
  • Ensuring adequate resources are devoted to risk-man
21
Q

Generally, which orgs will have dedicated risk-man committees? Why will others not?

A

Only large orgs - small to medium-sized orgs will often incorporate risk-man oversight into their audit committee

22
Q

What is the objective of the ISA 31000:2018?

A

To provide a set of internationally recognised principles and guidance on the practice of risk-man in organisations, to help improve design and implementation of frameworks with orgs

23
Q

3 main topic areas of ISO 31000:2018

A
  • Principles for risk-man
  • Core elements of an effective risk-man framework
  • The risk-man process
24
Q

ISO 31000:2018 - core principle for risk-man & 6 supporting principles

A
  • Risk-man activity should help protect and create value in orgs
    Frameworks should be:
  • structured
  • inclusive
  • customised
  • dynamic
  • responsive
  • integrated
25
ISO 31000:2018 on leadership (2)
Argues that - A tangible commitment of effective risk-man is needed from org's leaders - Support for risk-man should be evidenced by what these leaders say and do
26
ISO 31000:2018 - 3 core elements of risk-man process & 3 supporting activities
Elements: - Establishing the context - Risk assessment - Risk treatment Activities - Communication and consultation - Recording and reporting - Monitoring and review
27
ISO 31000:2018 - risk-man process - establishing the context (2)
- Includes understanding internal and external drivers affecting exposure to risk - Understanding types of risk that may affect org, and assessment and control tools available
28
ISO 31000:2018 - risk-man process - risk assessment (2)
- Identify, analyse and evaluate exposure to all sources of risk - May involve use of statistical models or qualitative judgement
29
ISO 31000:2018 - risk-man process - risk treatment (3)
- Another term for risk control - Ensure level of exposure is controlled (not too high or to low) - Influenced by risk appetite
30
ISO 31000:2018 - risk-man process - communication and consultation (3)
- Communicating risk-man info in timely, accurate and factual way - Communicating to promote awareness and understanding of risk and how to deal with it - Consulting with key stakeholders to ensure they understand risks and are satisfied with approach
31
ISO 31000:2018 - risk-man process - recording and reporting (2)
- Properly documenting identified risks, and processes and procedures - Reporting to decision-makers and stakeholders on risk exposures and measures taken to control exposures
32
ISO 31000:2018 - risk-man process - monitoring and review (3)
- Review on regular basis in order to learn, improve and adapt - Declining risk-man performance indicates that efficiency and effectiveness of framework has declined, so changes may be required - Risk-man framework may need to be changed if strategy and activities change
33
What is the British Standard BS 31100
UK's national guidance on developing, implementing and maintaining proportionate and effective risk-man - designed to be suitable for any org operating in UK
34
Guidance in BS 31100 includes: (4)
- How to manage risk proactively rather than reactively - The operation of effective risk-man oversight - Providing assurance to board and senior management on effectiveness of risk-man activities - Reporting to stakeholders
35
The Institute of Risk-management standard (3)
- Very similar to ISO 31000 - Free to download in 14 languages and shorter than ISO 31000 - Has not been updated as recently is ISO 31000
36
UK Governments 'The Orange Book' (2)
- Aimed at gov orgs and departments (but useful to other types of org) - Adopts principle based approach to risk-man
37
When did the COSO ERM Framework undergo a major revision?
2017
38
At which organisations is the COSO ERM Framework aimed?
Organisations of all sizes and sectors?
39
For what reason is COSO ERM Framework different in approach to most conventional risk-man frameworks?
To emphasise the performance-enhancing focus for risk-man that COSO believes is important
40
COSO ERM Framework's principles are organised into these 5 inter-related components:
1. Governance and culture 2. Strategy and objective setting 3. Performance 4. Review and revision 5. Information, communication and reporting
41
COSO ERM Framework's 5 inter-related components - Governance and culture (2)
- About ensuring that employees and other relevant stakeholders behave in manner consistent with org's values and codes of conduct, and support org's objectives - Includes overseeing management decisions to ensure opportunities are exploited and threats are mitigated
42
COSO ERM Framework's 5 inter-related components - Strategy and objective setting (2)
- Risk-man and strategy are complementary in that they each play their part in enhancing org performance - Org must determine appetite for different types of risk, and then plan strategy that is less likely to result in any associated risk exposures that exceed this level of risk appetite
43
COSO ERM Framework's 5 inter-related components - Performance (2)
- Concerned with identifying and assessing risks that may affect achievement of an org's objectives - Threatening risks are compared against appetite, and controlling actions taken if required
44
COSO ERM Framework's 5 inter-related components - Review and revision - 3 objectives
- Org should identify and assess substantial changes that may affect strategy or achievement of objectives - Org should evaluate performance in light of chosen strategy and risk response - Based on outcomes of above, org should evaluate continued appropriateness of risk-man arrangements and revise accordingly
45
COSO ERM Framework's 5 inter-related components - Information, communication and reporting
- Information should continuously be shared up, down and across the org to ensure that all decision-makers have necessary information - Some frameworks rely on periodic sharing, but COSO considers this ineffective as an org's environment changes constantly
46
What is the COBIT 2019 framework (inc. what it stands for) (2)
- Control Objectives for Information and Related Technologies is a good-practice risk-man framework for IT governance - Business oriented, linking IT goals to business goals, providing example metrics and benchmark maturity models
47
5 elements of the COBIT framework
- Code governance principles - Generic process descriptions for governance of IT risks - Control objectives - Management guidelines - Process maturity models