1/32
Flashcards covering the definitions, components, objective categories, and risk response strategies outlined in Marchetti Book Chapter 3: ERM Defined.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
COSO
The Committee Of Sponsoring Organizations of the Treadway Commission, which issued the Enterprise Risk Management – Integrated Framework in 2004.
Enterprise Risk Management (ERM)
A process, affected by an entity’s board of directors, management and other personnel, applied in strategy setting and across the enterprise, designed to identify potential events that may affect the entity, and manage risks to be within its risk appetite.
Reasonable Assurance
The realistic level of assurance an ERM solution provides regarding the attainment of entity objectives; absolute assurance is considered an unrealistic goal.
Portfolio View of Risk
The concept implied by the phrase "applied across the enterprise" within the ERM definition.
Internal Environment
The foundation of ERM that encompasses the tone of the organization, risk management philosophy, risk appetite, integrity, and ethical values.
Objective Setting
The process of ensuring management has a process in place to set objectives that support and align with the entity's mission and risk appetite.
Event Identification
The identification of internal and external events affecting objectives, specifically distinguishing between risks and opportunities.
Risk Assessment
The analysis of risks considering likelihood and impact, assessed on an inherent and a residual basis, to determine how they should be managed.
Risk Response (Component)
The selection of actions—avoiding, accepting, reducing, or sharing risk—to align risks with the entity’s risk tolerances and appetite.
Control Activities
Policies and procedures established and implemented to help ensure risk responses are carried out effectively.
Information and Communication
The identification and capture of relevant information in a form and time frame that enables people to carry out their responsibilities.
Monitoring
The process of monitoring the entirety of the ERM and making necessary modifications through ongoing activities or separate evaluations.
Strategic Objectives
High-level goals that are aligned with and support the organization's mission.
Operations Objectives
Objectives centered on the effective and efficient use of an entity's resources.
Reporting Objectives
Objectives concerning the reliability of an organization's reporting.
Compliance Objectives
Objectives concerning adherence to applicable laws and regulations.
Risk Appetite
The level of risk an organization is willing to accept in pursuit of the achievement of its objectives, which can be expressed qualitatively or quantitatively as a percentage of revenue.
Risk Tolerance
A measurable parameter that should parallel an entity's risk response.
Risk Avoidance
A response typically evoked by activities with a high likelihood of loss and significant financial impact, resulting in the complete avoidance of the activity.
Risk Acceptance
A response where management accepts risk, either because it is unavoidable or because the cost to bear it is lower than the cost to mitigate it.
Risk Mitigation
Also known as "reduction," this involves minimizing risk by seeking a response that reduces either the likelihood or the impact of an incident.
Risk Transfer
Also known as "sharing," this involves moving risk to an external party or different entity, commonly through insurance or derivative products like futures or options.
External Risks
Categories of risk involving customers, suppliers, competitors, brand reputation, or financial crises and disasters.
Financial Risks
Risks associated with credit/cash management, interest rate fluctuations, debt and equity structure, and financial reporting accuracy.
Operational Risks
Risks focusing on people (human resources), processes (product development), and physical assets (property, plant, equipment).
Strategic Risks
Risks focusing on areas such as governance, external relations, and business models or plans.
Regulatory Risks
Risks related to compliance with laws such as Sarbanes-Oxley (SOX), Occupational Safety and Health Administration (OSHA), or environmental policies.
Information Risks
Risks related to intellectual property and the reliability and security of information technology (hardware, software, and networks).
Risk Management Philosophy
The attitudes and principles of an entity regarding risk, reflected in management policies, values, culture, and operating style.
Integrity and Ethical Values
Standards of behavior expressed through documents like a code of conduct and through the actions of the board and management.
Organizational Structure
The framework that establishes key areas of responsibility and accountability to support ERM design, implementation, and monitoring.
Assignment of Authority and Responsibility
The element addressing accountability, ownership, and the level to which employees are authorized to address and solve issues.
Commitment to Competence
Management's determination of the knowledge and skills necessary to perform specific tasks and the reflection of those skills in performance.