Digital Risk

0.0(0)
Studied by 0 people
call kaiCall Kai
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/15

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 8:58 PM on 9/27/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

16 Terms

1
New cards

ERP (Enterprise Resource Planning)

Central software that manages core business processes (finance, HR, supply chain, reporting)


2
New cards

IT General Controls (ITGC)

Cover system security, access, and change management across the environment

3
New cards

Applicaiton Controls (ITAC)

ITACs are automated controls operating directly inside the ERP application

4
New cards

Segregation of Duties

Ensuring conflicting roles are separated within the ERP system to prevent fraud (e.g. creating a vendor and approving payment to that vendor) 


5
New cards

Data Integration & Interfaces

How data flows between systems; multiple ERPs require complex API/batch integrations, creating points of failure and data inconsistency


6
New cards

Current State vs. Target State (Merger)

Understanding what systems exist today (Company A's software vs. Company B's software) and deciding what system everyone will use post-merger

7
New cards

Data Cleansing & Reconciliation (Merger)

Cleaning up messy data before moving it, then verifying that every dollar and customer record transferred accurately without missing or duplicate entries

8
New cards

Control Alignment (Merger)

Combining two different sets of company rules (e.g., Company A required 1 manager approval for $5,000, while Company B required 2 approvals) into one unified rulebook

9
New cards

Parallel Run (Merger)

Running the old systems and new system side-by-side for a short time to prove that financial numbers match before shutting the old systems off

10
New cards

Change / Implementation

There’s a risk that changes could be implemented without sufficient testing, approval, or planning before going live.“Because changes can directly affect liv.”e systems and business processes, poorly executed changes could lead to disruption or incorrect functiolaities. “I’d want proper change approval, testing, UAT where appropriate, and a rollback or contingency plan in place before implementation.”

11
New cards

People / Process:

There’s a risk that unclear responsibilities, or insufficient training could cause employees to perform tasks incorrectly or bypass intended controls. “Because technology still depends on people and processes to operate in an intended way this could lead to errors,ot  delays “I’d want clear ownership, standardized procedures, appropriate training, and monitoring to make sure the process is being followed as intended.

12
New cards

Third Party

There’s a risk that the company becomes dependent on a third-party provider that could experience an outage, security incident, or control failure. If the provider fails, the company could lose access to a critical service, expose sensitive information, or disrupt important business operations. I’d want proper vendor due diligence, clear service expectations, ongoing monitoring, and a contingency or recovery plan in case the provider becomes unavailable.”

13
New cards

Integration

I’d also look at integration as well. There’s a risk that connected systems could fail to interact, accurately, or on time. “That could cause inconsistency between systems, halt certain business process, or lead to incorrect outcomes or decisions. “To deal with any potential integration issuesI’d want end-to-end integration testing, reconciliation where appropriate, and monitoring to make sure information is being transferred correctly between systems.”


14
New cards

Access

Because there are different groups and types of users accessing the system there’s a risk that users could receive more access than they need for their role. That could allow someone to view sensitive information, make unauthorized changes, or perform actions outside their responsibilities. “I’d want role-based access controls and the principle of least privilege, with regular access reviews to make sure permissions still match each user’s responsibilities.”  

15
New cards

Data Confidentiality

There’s also a risk that sensitive information could be accessed, exposed, or disclosed to unauthorized users.” “Because the system contains employee and financial information, that could lead to privacy issues, misuse of information, or fraud .I’d want appropriate access controls and encryption in place, so only authorized users can access the information and it remains protected while being stored or transmitted

16
New cards

Data Integrity:

There’s a risk that data could be transferred incorrectly, incompletely, duplicated, or mapped incorrectly.”“Because the business relies on that information to make decisions and run key processes, inaccurate or incomplete data could lead to errors, delays, or incorrect outcomes.