Unit 2 Flashcards
Risk management standards
A published guide for managing risk comprises a risk process and risk framework
3 RM standards
IRM 2002
COSO ERM
ISO 31000
Framework definition
Risk management context. Comprises the RASP -risk strategy, risk architecture and risk protocols and forms the risk context which helps drive the risk process.
IRM 2002-Risk management process
Orgs strategic objectives
|
Risk assessment
______ Risk analysis
______ Risk identification
______ Risk description
______ Risk estimation
__\ Risk evaluation
|
Risk reporting -threats and opportunities
|
Decision
|
Risk treatment
|
Residual risk reporting
|
Monitoring
Formal Audit around all
Modification around all
Risk management process - 3 steps
Identify risks (and opportunities)
Evaluate and prioritise the significant risks (and opportunities)
Manage the significant risks
COSO ERM cube
In order to implement a successful ERM initiative an organisation needs to implement all 8 components in relation to each of the 4 risks, in all parts of the organisation.
Front is process, top is org objectives, side is implementation of process-who in the entity
COSO ERM cube- 8 components
Internal Environment
Objective setting
Event identification
Risk Assessment
Risk response
Control activities
Information and Communication
Monitoring
COSO ERM -4 risks
Strategic
Operations
Reporting
Compliance
COSO ERM -parts of the organisation
Subsidiary
Business unit
Division
Entity
Risk framework = Risk context
Risk context is 3 layers of org which drive the risk process:
External environment
Internal environment
Risk Management context aka risk framework
Risk context comprises RASP
Risk Architecture, strategy, protocols
Risk architecture
Part of the framework which focuses on answering the question on responsibilities in the org in relation to risk management
Risk strategy
The agreed overriding purpose and aims of risk management in the organisation, which involves the publication of a risk policy document and the setting of risk appetite
Risk protocols
The set of tools, procedures and instructions that an organisation has for managing risk
ISO 31000 -overall
The standard provides a statement of risk management principles, as well as a description of the risk management framework and process. List of principles of risk management provided centred around the central purpose of risk management-creation and protection of value