Role of directors in implementing strategy in a risk approach
Role of risk committee in implementing strategy in a risk approach
Role of risk manager (chief risk officer) in implementing strategy in a risk approach
UK corporate governance code compromises:
Sarbanes-Oxley Act requires comp’s to:
Limitations on risk disclosures:
What is risk appetite?
* Range org chooses to actively pursue
What is risk universe?
All possible performance outcomes that org will experience from its current strategy
What is risk tolerance?
* Measure of what org does not wish to go beyond
What is risk capacity?
Collection of tangible and intangible assets at an org’s disposal that allows it to take risks and absorb losses
Attitudes toward risk:
How can we identifying conditions that leads to risk?
TARA Model:
Low frequency, High severity = Transfer
Low frequency, Low severity = Accept
High frequency, Low severity = Control/ reduce
High frequency, High severity = Avoid/ abandon
Risk Transfer:
Risk sharing = partly held by org, partly transferred to someone else (insurance policy)
Risk avoidance:
Risk reduction:
Other risk reduction strategies:
COSO Enterprise Risk Management Framework
What is the aim of ISO 31000 Risk Management?
ISO 31000 - Risk Management Policies:
Design: (PACED)
* Proportionate to the level of risk faced
* Aligned with all other activities
* Comprehensive
* Embedded within the org
* Dynamic and responsive to emerging trends
Operation:
* Limitations in available info actively considered
* Influence of human and cultural factors
* Continual improvement through learning and experience
ISO 31000 - Risk Management Framework:
ISO 31000 - Risk Management Process:
Three lines of defence:
What is the risk register and what is its function?