1/19
These flashcards cover the key vocabulary and concepts from the Enterprise Risk Management (ERM) Framework and Process lecture notes, including ISO 31000 and COSO standards.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
Risk Management Framework
The foundation for applying the risk management process throughout the organization, with the fundamental purpose of integrating risk management throughout the organization.
ISO 31000
An international risk management standard that provides principles, a framework, and a process to manage operational, financial, strategic, and hazard risks.
Risk Appetite
The total exposed amounts that an organization wishes to undertake on the basis of risk-return trade-offs for one or more desired and expected outcomes.
Gap Analysis
A technique used to compare an organization’s existing risk management framework and process against an internationally recognized standard to identify components that are not matched.
Inherent Risk
Risk to an entity apart from any action to alter either the likelihood or impact of the risk.
Residual Risk
Risk remaining after actions to alter the risk’s likelihood or impact.
Plan-Do-Check-Act (P-D-C-A) Cycle
A model for continuous improvement where the "act" step restarts the cycle by evaluating implemented improvements and reinitiating the "plan" phase.
Risk Criteria
Measures used to evaluate the significance of an organization’s various risks in relation to the organization’s values, objectives, and legal and regulatory requirements.
Sarbanes-Oxley Act Section 404
A regulation requiring public companies to publish information in annual reports regarding the scope and adequacy of their internal control structure and procedures for financial reporting.
Key Performance Indicators (KPI)
A technique used to establish accountability for risk management within an organization.
Key Risk Indicators (KRI)
A technique used to evaluate performance and establish accountability for risk management.
Four Components of the ERM Framework Model
Five Steps of the ERM Process Model
COSO Enterprise Risk Management definition of Risk
The possibility that an event will occur and adversely affect an organization’s objectives.
COSO (2004) Framework Objectives
Strategic (high-level goals aligned with mission), Operations (effective resource use), Reporting (reliable results), and Compliance (adherence to laws).
Eight Components of the COSO Framework
Internal environment, objective setting, event identification, risk assessment, risk response, control activities, information and communication, and monitoring.
Risk Treatment
The ongoing process of deciding on an option for modifying risk, assessing if residual risk is acceptable, and selecting new treatments if the current ones are ineffective.
Risk Assessment (ISO 31000)
A process including risk identification, risk analysis, and risk evaluation.
External Environment Factors
Economic, political, legal and regulatory, technology, natural, and competitive landscape factors.
Control Activities
Policies and procedures established to determine that risk responses are performed correctly and to help achieve objectives.