Enterprise Risk Management - Integrated Framework Review

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/32

flashcard set

Earn XP

Description and Tags

Flashcards covering the definitions, components, objective categories, and risk response strategies outlined in Marchetti Book Chapter 3: ERM Defined.

Last updated 5:13 PM on 8/12/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

33 Terms

1
New cards

COSO

The Committee Of Sponsoring Organizations of the Treadway Commission, which issued the Enterprise Risk Management – Integrated Framework in 2004.

2
New cards

Enterprise Risk Management (ERM)

A process, affected by an entity’s board of directors, management and other personnel, applied in strategy setting and across the enterprise, designed to identify potential events that may affect the entity, and manage risks to be within its risk appetite.

3
New cards

Reasonable Assurance

The realistic level of assurance an ERM solution provides regarding the attainment of entity objectives; absolute assurance is considered an unrealistic goal.

4
New cards

Portfolio View of Risk

The concept implied by the phrase "applied across the enterprise" within the ERM definition.

5
New cards

Internal Environment

The foundation of ERM that encompasses the tone of the organization, risk management philosophy, risk appetite, integrity, and ethical values.

6
New cards

Objective Setting

The process of ensuring management has a process in place to set objectives that support and align with the entity's mission and risk appetite.

7
New cards

Event Identification

The identification of internal and external events affecting objectives, specifically distinguishing between risks and opportunities.

8
New cards

Risk Assessment

The analysis of risks considering likelihood and impact, assessed on an inherent and a residual basis, to determine how they should be managed.

9
New cards

Risk Response (Component)

The selection of actions—avoiding, accepting, reducing, or sharing risk—to align risks with the entity’s risk tolerances and appetite.

10
New cards

Control Activities

Policies and procedures established and implemented to help ensure risk responses are carried out effectively.

11
New cards

Information and Communication

The identification and capture of relevant information in a form and time frame that enables people to carry out their responsibilities.

12
New cards

Monitoring

The process of monitoring the entirety of the ERM and making necessary modifications through ongoing activities or separate evaluations.

13
New cards

Strategic Objectives

High-level goals that are aligned with and support the organization's mission.

14
New cards

Operations Objectives

Objectives centered on the effective and efficient use of an entity's resources.

15
New cards

Reporting Objectives

Objectives concerning the reliability of an organization's reporting.

16
New cards

Compliance Objectives

Objectives concerning adherence to applicable laws and regulations.

17
New cards

Risk Appetite

The level of risk an organization is willing to accept in pursuit of the achievement of its objectives, which can be expressed qualitatively or quantitatively as a percentage of revenue\text{percentage of revenue}.

18
New cards

Risk Tolerance

A measurable parameter that should parallel an entity's risk response.

19
New cards

Risk Avoidance

A response typically evoked by activities with a high likelihood of loss and significant financial impact, resulting in the complete avoidance of the activity.

20
New cards

Risk Acceptance

A response where management accepts risk, either because it is unavoidable or because the cost to bear it is lower than the cost to mitigate it.

21
New cards

Risk Mitigation

Also known as "reduction," this involves minimizing risk by seeking a response that reduces either the likelihood or the impact of an incident.

22
New cards

Risk Transfer

Also known as "sharing," this involves moving risk to an external party or different entity, commonly through insurance or derivative products like futures or options.

23
New cards

External Risks

Categories of risk involving customers, suppliers, competitors, brand reputation, or financial crises and disasters.

24
New cards

Financial Risks

Risks associated with credit/cash management, interest rate fluctuations, debt and equity structure, and financial reporting accuracy.

25
New cards

Operational Risks

Risks focusing on people (human resources), processes (product development), and physical assets (property, plant, equipment).

26
New cards

Strategic Risks

Risks focusing on areas such as governance, external relations, and business models or plans.

27
New cards

Regulatory Risks

Risks related to compliance with laws such as Sarbanes-Oxley (SOX), Occupational Safety and Health Administration (OSHA), or environmental policies.

28
New cards

Information Risks

Risks related to intellectual property and the reliability and security of information technology (hardware, software, and networks).

29
New cards

Risk Management Philosophy

The attitudes and principles of an entity regarding risk, reflected in management policies, values, culture, and operating style.

30
New cards

Integrity and Ethical Values

Standards of behavior expressed through documents like a code of conduct and through the actions of the board and management.

31
New cards

Organizational Structure

The framework that establishes key areas of responsibility and accountability to support ERM design, implementation, and monitoring.

32
New cards

Assignment of Authority and Responsibility

The element addressing accountability, ownership, and the level to which employees are authorized to address and solve issues.

33
New cards

Commitment to Competence

Management's determination of the knowledge and skills necessary to perform specific tasks and the reflection of those skills in performance.