Enterprise Risk Management Framework and Process

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/19

flashcard set

Earn XP

Description and Tags

These flashcards cover the key vocabulary and concepts from the Enterprise Risk Management (ERM) Framework and Process lecture notes, including ISO 31000 and COSO standards.

Last updated 5:25 PM on 8/12/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

20 Terms

1
New cards

Risk Management Framework

The foundation for applying the risk management process throughout the organization, with the fundamental purpose of integrating risk management throughout the organization.

2
New cards

ISO 31000

An international risk management standard that provides principles, a framework, and a process to manage operational, financial, strategic, and hazard risks.

3
New cards

Risk Appetite

The total exposed amounts that an organization wishes to undertake on the basis of risk-return trade-offs for one or more desired and expected outcomes.

4
New cards

Gap Analysis

A technique used to compare an organization’s existing risk management framework and process against an internationally recognized standard to identify components that are not matched.

5
New cards

Inherent Risk

Risk to an entity apart from any action to alter either the likelihood or impact of the risk.

6
New cards

Residual Risk

Risk remaining after actions to alter the risk’s likelihood or impact.

7
New cards

Plan-Do-Check-Act (P-D-C-A) Cycle

A model for continuous improvement where the "act" step restarts the cycle by evaluating implemented improvements and reinitiating the "plan" phase.

8
New cards

Risk Criteria

Measures used to evaluate the significance of an organization’s various risks in relation to the organization’s values, objectives, and legal and regulatory requirements.

9
New cards

Sarbanes-Oxley Act Section 404

A regulation requiring public companies to publish information in annual reports regarding the scope and adequacy of their internal control structure and procedures for financial reporting.

10
New cards

Key Performance Indicators (KPI)

A technique used to establish accountability for risk management within an organization.

11
New cards

Key Risk Indicators (KRI)

A technique used to evaluate performance and establish accountability for risk management.

12
New cards

Four Components of the ERM Framework Model

  1. Lead and establish accountability, 2. Align and integrate, 3. Allocate resources, 4. Communicate and report.
13
New cards

Five Steps of the ERM Process Model

  1. Scan environment, 2. Identify risks, 3. Analyze risks, 4. Treat risks, 5. Monitor and assure.
14
New cards

COSO Enterprise Risk Management definition of Risk

The possibility that an event will occur and adversely affect an organization’s objectives.

15
New cards

COSO (2004) Framework Objectives

Strategic (high-level goals aligned with mission), Operations (effective resource use), Reporting (reliable results), and Compliance (adherence to laws).

16
New cards

Eight Components of the COSO Framework

Internal environment, objective setting, event identification, risk assessment, risk response, control activities, information and communication, and monitoring.

17
New cards

Risk Treatment

The ongoing process of deciding on an option for modifying risk, assessing if residual risk is acceptable, and selecting new treatments if the current ones are ineffective.

18
New cards

Risk Assessment (ISO 31000)

A process including risk identification, risk analysis, and risk evaluation.

19
New cards

External Environment Factors

Economic, political, legal and regulatory, technology, natural, and competitive landscape factors.

20
New cards

Control Activities

Policies and procedures established to determine that risk responses are performed correctly and to help achieve objectives.