Unit 1 Flashcards
Define risk profile
overall risk exposure currently faced by the organisation
Define ERM
- no 1 definition
- RM conducted throughout the organisation
- In a structured & consistent way
- considers all risks faced & their interactions
- integrates risk measures into business reporting
- allowing to influence strategic decisions
- CRF lead by CRO
Define risk appetite
Desired level of risk the organisation wishes to take on, on an on-going basis.
What is the risk profiling process
- Identify risks
- assess likelihood and impact
- Decide how to deal with risks
Describe the 5 ERM concepts
- Holistic approach
Consider enterprise as a whole - Upside and downside risks
Not just consider downside, seize opportunities - Quantify risks
Use to determine whether a risk is acceptable or not - Unquantifiable risks
Class into subjective categories
Nature of risk makes it difficult to assess - Respond to risks
When ID & measured, need to determine a response
What are the Benefits of ERM?
- better Risk reporting increase business efficiency - Improve business performance -- loss reduction -- uncertainty management -- performance optimisation
Board’s responsibility in ERM?
- define risk profile
- skill themselves to be able to successfully implement ERM strategies
- guiding decision as to the most appropriate approach to ERM for the organisation
- set direction, structure and culture
- approve suitable internal controls
- actively monitor risk reporting
What’s the line managers responsibility in ERM?
- implement board decisions
- set up processes for ERM
- integrate risk reporting into business reporting
- understand risks they are taking
- and extent of risk taking power
- supported with thorough documentation
Describe stakeholder management
Communicate effectively with stakeholders
Internal Comms to board and relevant committees
– they are fully aware of risks
– consistent “risk language” to ensure no risk is left out or doubled up
External Comms with regulator/ supervisory body
what are the 5 steps in RM Process?
ID risks faced
Risk analysis to quantify risks
Evaluating info-risks compared to limits
How to manage risks and implement actions
Monitoring processes - risks and management actions continually reviewed
What organisational structures help to set a good risk culture?
Set from the top
Codes of honesty and fair dealing
Clear organisational responsibility for the ID And management of risks
Every employee sees it as their job to ID new risks/ increases in risks
What are the main ideas to setting a good risk culture?
Consultative leadership Participation in decision-making Openness Accountability rather than blame Organisational learning Knowledge sharing Good internal communications
List the 5 aims of internal controls
Accurate and adequate record keeping
Prevent fraud and safeguard the company assets
Guarantee accuracy of financial statements
Respond to risks
Ensure compliance with law and legislation
Key to excellence in corporate governance
Communication with stakeholders Independence of board Board performance Board compensation arrangements *fairness *social responsibility
6 points that should be covered when a risk committee is set up
1 purpose 2 responsibility 3 membership 4 performance assessment 5 frequency of meetings 6 resources available