Unit 2 Flashcards

1
Q

Risk management standards

A

A published guide for managing risk comprises a risk process and risk framework

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

3 RM standards

A

IRM 2002
COSO ERM
ISO 31000

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Framework definition

A

Risk management context. Comprises the RASP -risk strategy, risk architecture and risk protocols and forms the risk context which helps drive the risk process.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

IRM 2002-Risk management process

A

Orgs strategic objectives
|
Risk assessment
______ Risk analysis
______ Risk identification
______ Risk description
______ Risk estimation
__\ Risk evaluation
|
Risk reporting -threats and opportunities
|
Decision
|
Risk treatment
|
Residual risk reporting
|
Monitoring

Formal Audit around all

Modification around all

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Risk management process - 3 steps

A

Identify risks (and opportunities)
Evaluate and prioritise the significant risks (and opportunities)
Manage the significant risks

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

COSO ERM cube

A

In order to implement a successful ERM initiative an organisation needs to implement all 8 components in relation to each of the 4 risks, in all parts of the organisation.

Front is process, top is org objectives, side is implementation of process-who in the entity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

COSO ERM cube- 8 components

A

Internal Environment
Objective setting
Event identification
Risk Assessment
Risk response
Control activities
Information and Communication
Monitoring

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

COSO ERM -4 risks

A

Strategic
Operations
Reporting
Compliance

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

COSO ERM -parts of the organisation

A

Subsidiary
Business unit
Division
Entity

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Risk framework = Risk context

A

Risk context is 3 layers of org which drive the risk process:
External environment
Internal environment
Risk Management context aka risk framework

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Risk context comprises RASP

A

Risk Architecture, strategy, protocols

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Risk architecture

A

Part of the framework which focuses on answering the question on responsibilities in the org in relation to risk management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Risk strategy

A

The agreed overriding purpose and aims of risk management in the organisation, which involves the publication of a risk policy document and the setting of risk appetite

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Risk protocols

A

The set of tools, procedures and instructions that an organisation has for managing risk

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

ISO 31000 -overall

A

The standard provides a statement of risk management principles, as well as a description of the risk management framework and process. List of principles of risk management provided centred around the central purpose of risk management-creation and protection of value

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

ISO 31000 -8 principles

A
  1. Risk management integral part of all org activities
  2. Structured and comprehensive approach required
  3. Framework and process should be customised and proportionate
  4. Appropriate and timely involvement of stakeholders
  5. Risk management anticipates, detects, acknowledges and responds to changes
  6. Risk management considers limitations of available information
  7. Human and cultural factors influence all aspects of risk management
  8. Risk management is continuously improved through learning and experience
17
Q

Steps in ISO 31000 -risk management process

A

Scope, context, criteria
|
Risk assessment-risk identification; risk analysis; risk evaluation
|
Risk treatment
|
Recording and reporting
|||
Around outside- Monitoring and Review

Communication and consultation

18
Q

ISO 31000 -framework (steps to implement)

A

Initial component is ‘leadership and commitment’ by the board, followed by:
-integrating risk management
-design of the rm framework
- evaluation of framework
- improvement of framework

19
Q

PIML

A

Plan; implement; measure; learn

20
Q

Basel 3 and Solvency 2 -Pillar 1

A

Quantitative requirements-
Adresses capital adequacy which is the relationship between eligible capital and RWAs. It sets out ways in which RWAs can be calculated and what constitutes eligible capital in relation to credit, market and operational risks.
Capital adequacy-how to calculate to a one year horizon

21
Q

Pillar 2

A

Governance
Qualitative requirements and supervisory review process. Requires banks to produce an Internal Capital Adequacy Assessment Process report which sets out their assessment of their overall capital adequacy in relation to risk profile and develop a strategy for maintaining/ achieving required capital levels. Reviewed and challenged by regulators.

22
Q

Pillar 3

A

Disclosure
Transparency

Disclosure requirements in relation to risk management, risk exposures and capital management. Publish annually.

23
Q

ISO 31000 -8 principles cont

A

First 5 relate to design and planning of the risk management initiative so could use PACED to summarise

24
Q

2017 Components of ERM COSO

A
  1. Governance and culture
  2. Strategy and objective setting
  3. Performance
  4. Review and revision
  5. Information, communication and reporting
25
Q

Solvency 2- 3 pillars

A

Pillar 1 - Quantitative requirements including level of capital that an insurer should hold -Solvency Capital Requirement (SCR) and absolute minimum floor level of capital below which Reg intervention

Pillar 2 - same as Basel but ORSA

Pillar 3 - solvency and financial condition report (public) and report to supervisors

26
Q

COSO ERM -nature of management systems-scope and design components of mgt system

A

Context - organisation, stakeholder expectations, scope of mgt system

Support- resources, competence, awareness, communication and documentation

Leadership- commitment, policy, org roles and responsibilities

27
Q

COSO ERM control and development components of management system

A

PIML. Plan, implement, measure, learn

28
Q

Property and casualty insurance risks

A

Standard- credit, market, op risk
Insurance- underwriting, reserving, claims mgt, claims reserving

29
Q

Life insurance risks

A

Longevity, mortality and morbidity, persistence, claims mgt, underwriting, product cycle, expenses

30
Q

3 approaches by the Standards

A

‘Risk management’ - ISO 31000 and IRM standard
‘Internal control’ - COSO internal cube and FRC guidance
‘ Risk aware’ culture - CoCo framework