What does a good risk register look like?
Collates risks & controls
Tailored to your organisation Updated regularly
Informs decision making
Enable team to prioritise & manage their risks
What is risk policy?
Risk policy is the ‘what’, framework and guidelines to manage risks
What are risk procedures?
Procedures is the ‘how’
What are the ISO 31000, 8 key RM steps?
Communication & Consultation; Scope, Context & Criteria; Risk Identification; Risk Analysis; Risk Evaluation; Risk Treatment; Monitoring & Review; Recording & Reporting
What are the COSO (2004), 8 Key RM steps?
Internal Environment; Objective Setting; Event Identification; Risk Assessment; Risk Response; Control Activities; Info, Comms, Monitoring
What are the 4 RM standards?
ISO 31000, COSO (2004), COSO (2017), The Orange Book
What are the 5 components of COSO (2017)?
Governance & Culture; Strategy & Objective Setting; Performance; Review & Revision; Info, Comms & Reporting
What is Principle A of the Orange Book?
RM as an essential part of governance & leadership
What is Principle B of the Orange Book?
RM an integral part of all organisational activities to support decision making
What is Principle C of the Orange Book?
RM shall be collaborative
and informed by the best available
information and expertise
What is Principle D of the Orange Book?
RM to have structured processes incl, risk identification & assessment, risk treatment, risk monitoring risk reporting
What is Principle E of the Orange Book?
RM shall be continually
improved through learning and experience
What are the 3 components of context?
Internal, External, Risk Management
What is the purpose of establishing context according to ISO 31000?
To enable effective risk assessment & treatment
What is the extended enterprise?
Organisation’s come together to achieve objectives they could not achieve on their own
What are the key elements of the extended enterprise?
Core activities, key inputs & outputs, external influences
What does PESTLE help to do?
Anlysis an organisation’s context
What is Mendelow’s matrix?
Helps with stakeholder mapping
What are some difficulties in setting objectives?
Picking ones that support the mission; conflicting stakeholder expectations; context constantly changing;
What is the attachment of risk?
The process of transferring or assigning a specific risk or liability from one party to another
What are the 3 stages of risk assessment?
Risk identification, risk analysis, risk evaluation
What is the purpose of risk identification?
To find, recognise and describe risks that might prevent/help org from achieving its objectives
What is a cause? risk? consequence?
Thing happening now or has happened. The uncertainty. Impact on objectives.
What are Hopkins 5 techniques for risk assessment?
Checklists & questionnaires; workshops & brainstorming; inspections & audits; flowcharts & dependency analysis; crowd sourcing technology