Risk Profiling eLearn Flashcards
Why are our operational risk profiles anchored to our processes at NAB?
To ensure clear identification of where risk eventuates and where it needs to be managed (or improved).
In simple terms, what does Risk Profiling do? (3 points)
- Identifies the operational risks in our business that impact NAB’s ability to achieve its strategic objectives and ensures these are assessed and managed.
- Helps us understand how we are managing these risks.
- Determines if we’re doing enough or if we need to make changes to improve our risk management.
Why does Risk Profiling requires us to consider the causes for each risk event, and the impacts that result?
Understanding theses causes and impacts enables us to implement controls to prevent or reduce the impacts
Why does NAB use the “bowtie” method for risk profiling?
Because each documented risk event includes multiple causes and impacts
How does Risk Profiling analysis begin?
By identifying the risks that may eventuate directly from processes owned by the division or critical operation, or that impact the division or critical operation from processes owned elsewhere at NAB
Once we’ve identified the applicable Risks that impact the division or critical operation, what do we identify for each risk event?
- The potential causes
- The potential financial or non-financial impacts
Once we understand risk events, and their causes and impacts, what is the next step?
To understand how we are managing these risk events
What do we do to understand how we are managing risk events?
Two assessments:
1. CCA to identify what we have to manage causes and impacts
2. RRA to assess remaining potential impact from risk event once the effectiveness of controls is considered
What do the CCA elements tell us?
Coverage: have we implemented the right controls?
Effectiveness: do the controls reduce likelihood/impacts?
Efficiency: do the controls find issues quickly before they impact our customers?
What is the Target Risk Rating?
The target risk across the next 12 months, determined by the risk owner
How is the Risk response determined?
Comparing the residual risk to the target risk
Who is involved in the Risk Profiling process? (Persona names only)
- Risk Owner
- Risk Manager /DCO
- Chief Risk Officer (CRO) Teams
- Material Risk Exposure (MRT) Teams
What are the Risk Owner responsibilities in Risk Profiling?
Accountable for developing and maintaining a risk profile and will validate and approve (approvers)
What are the Risk Manager/DCO responsibilities in Risk Profiling?
Management of risk profiles and will most likely perform most risk profiling activities.
What are the Chief Risk Officer (CRO) Team responsibilities in Risk Profiling?
Provide independent review and challenge of risk profiling activities and outputs where required.