Risk Profiling Flashcards

1
Q

What are the 3 chapters of Risk Profiling?

A
  1. Complete MRE determination
  2. Complete L3 risk assessment
  3. Complete L1 risk assessment
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How are applicable MREs determined?

A

Workshop held:
* Identify processes owned by the DoCO
* For each (43) L3 risk, ask: Can a Risk Event eventuate from any owned processes.
* If yes, the L3 Risk and supporting MRE will be included in the Risk Profile.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Are risk records required for applicable risks/MREs?

A

Yes, GRACE will mandate the creation of a risk record.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Are rationales required for non-applicable risks/MREs?

A

Yes, rationale will be required.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are 3 reasons we want to categorise risks and events properly?

A
  • Correctly reflect the risks the BU or enabling unit is facing.
  • Impacts ability to identify gaps in process/controls and uplift as required.
  • Affects quality of reporting to Senior Management, Board Committees and regulators, and impacts their confidence in our ability to manage risks.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does MRE refer to?

A

The type of risks that may occur.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Who will own Risk Profiles?

A

Risk Owner, being:
* Divisional executive for divisional profiles.
* CO Owner for CO profiles.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Which persona is to support the Risk Owner with specialist risk advice and complete tasks?

A

Risk Manager (DCO, GRC Facilitator, or equivalent).

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What does 2nd Line Risk do?

A

Facilitates workshop and provides independent review.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the 6 steps of Chapter 2 - L3 risk assessment?

A
  1. Create L3 risk record(s)
  2. Prepare L3 risk description
  3. Complete CCA
  4. Complete RRA
  5. Complete TRA
  6. Determine L3 Risk response
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Who performs Chapter 2 - L3 risk assessment?

A

Risk Manager (DCO or equivalent)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

In L3 Risk assessment, what L3 risks are assessed?

A

The L3 risks identified in Chapter 1 – MRE determination

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

When writing risk descriptions, what taxonomies need to be used?

A

Cause and Impact Taxonomies

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

When writing risk descriptions, what should be included to align with bow-tie approach?

A
  • Cause – what causes risk event to occur
  • Event – what could go wrong
  • Impact – implication of risk event on NAB
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Who performs Chapter 3 – Complete L1 Risk Assessment

A

Risk Manager (DCO or equivalent)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the 3 tasks in completing L1 Risk Assessment?

A
  1. Create L1 risk record
  2. Validate CCA, RRA, and TRA for L1 risk
  3. Validate risk response for L1 risk
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is used to perform L1 Risk assessment?

A

Output from Chapters 1 & 2, which includes linking of all supporting L3 risk records

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

What calculations does GRACE automatically provide for L1 Risks, and what are they based on?

A
  • CCA – based on lowest (worst) of all linked L3 CCAs
  • RRA – based on highest (worst) of all L3 financial and non-financial impacts, and likelihood.
  • TRA – based on highest (worst) of all L3 impacts/likelihood and latest target date
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

Must GRACE automatic calculations for CCA, RRA, TRA be accepted?

A

No, must validate rating and provide rational for any adjustments

20
Q

How is risk response completed?

A

Manually, using ALARP approach, informed by L3 risk responses.

21
Q

What are the 3 ALARP categories?

A
  1. Requires action
  2. Tolerable
  3. Acceptable
22
Q

What does RRA stand for?

A

Residual Risk Assessment

23
Q

What is are the steps of the L3 RRA?

A
  1. Assess residual FI (input dollar amount)
  2. Assess residual NFI (input impact classification)
  3. Input justification for residual NF&FI
  4. Assess and input residual likelihood
  5. Calculate risk rating
    * L3 RRA completed
24
Q

FIs are assessed based on data both inside and outside of GRACE. What data side GRACE informs FI assessment?

A
  • Internal losses (# and $ over last 3 years)
  • External losses (Australian banking/financial industry only)
  • Top 5 external losses across all industries globally
  • CCA Outcome
25
Q

What data inside GRACE informs NFI assessment?

A
  • Top 5 external losses across all industries globally
  • Events linked to the risk record
26
Q

NF&FIs are assessed based on data both inside and outside of GRACE. What data outside GRACE informs NF&FI assessment?

A
  • GAITS
  • MOI
  • Complaint Data
27
Q

How is residual likelihood assessed?

A

Use likelihood table within RMPFGN

28
Q

How is residual risk rating performed?

A

GRACE automatically calculates residual risk rating by taking the highest residual risk impact and likelihood rating and plotting them on a heatmap to derive the overall rating

29
Q

What does TRA stand for?

A

Targeted Risk Assessment

30
Q

What are the steps in TRA and RR?

A
  1. Determine target impact
  2. Determine target likelihood
  3. Capture justification for target rating
  4. Calculate target risk rating
  5. Capture risk response in GRACE, if required.
  6. Raise finding/treatment plan, if required.
    * TRA and RR completed
31
Q

What is the target impact?

A

The objective for a residual risk impact (NF&FI) in the next 12 months

32
Q

How is target impact calculated?

A

Use the higher of your targeted financial and non-financial impact classification.

33
Q

What is target likelihood?

A

The objective for a residual risk likelihood in the next 12 months

34
Q

How is target risk rating determined?

A

GRACE automatically calculates the target risk rating by taking the target risk impact and likelihood rating and plotting them on the heatmap to derive the overall rating

35
Q

What does RR stand for?

A

Risk Response

36
Q

What are the 3 possible risk responses in GRACE?

A
  1. Acceptable
  2. Tolerable
  3. Requires action
37
Q

When is a risk ‘Requires Action’?

A

When Target Risk Rating is lower than Residual Risk Rating – the risk must be reduced in the next 12 months

38
Q

When is a risk ‘Tolerable’?

A

When Target Risk Rating is or same as the Residual Risk Rating (i.e., indicating further action can be taken to reduce the risk) and the actions to reduce the risk is likely to take longer than 12 months to deliver.
CCA must be effective.

39
Q

When is a risk ‘Acceptable’?

A

When Target Risk Rating is the same as the Residual Risk Rating, and the risk does not need to be reduced any further over the next 12 months.
CCA must be effective.

40
Q

In regards to Risk Responses, when must you raise a Finding / Treatment Plan?

A

When Risk Response is “Requires Action”

41
Q
A
42
Q

What is risk profiling, in simple terms?

A
  • The process of identifying and reviewing all non-financial risks that exist within our business.
  • Understanding what we’re doing to mitigate these risks, and
  • Determining if we’re doing enough or if we need to make changes to improve our risk management
43
Q

What does CCA Coverage answer?

A

If we have enough controls to address all relevant causes and impacts or risk events

44
Q

What does CCA Effectiveness answer?

A

If our controls reduce the likelihood and/or impacts of risk events

45
Q

What does CCA Efficiency answer?

A

If our controls are adding value or costing resources