Enterprise Risk Management Flashcards

Apply ERM frameworks and link risk to strategy. (26 cards)

1
Q

What is Enterprise Risk Management?

(ERM)

A

A structured and disciplined approach that aligns strategy, processes, technology, and knowledge to manage uncertainties and maximize shareholder value.

ERM provides a holistic, integrated, forward-looking, and process-oriented approach to managing all key business risks and opportunities, not just financial ones.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How does ERM differ from traditional risk management?

A

ERM provides a top-down view of key risks facing the organization and coordinates risk management across the entire organization.

Traditional risk management often operates in silos, focusing on individual departments without considering the organization-wide impact.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the objective of Enterprise Risk Management?

A

To coordinate risk identification, assessment, and management throughout the organization to maximize coverage and reduce overlooked risks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is a portfolio view of risk in ERM?

A

An approach that evaluates how risks interact across the company, optimizing the entire portfolio by balancing risk and return.

This avoids fragmented and potentially conflicting risk strategies and allows for more effective resource allocation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What role does corporate governance play in ERM?

A

It provides oversight of risk management, ensuring management has robust processes to identify, assess, manage, and monitor significant risks.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

True or False:

ERM should be integrated with corporate governance.

A

True

Integrating ERM with corporate governance improves communication regarding strategic risks, aligns managerial focus, and enhances transparency.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is the COSO 2017 definition of ERM?

A

The culture, capabilities, and practices that organizations integrate with strategy-setting to manage risk in creating, preserving, and realizing value.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Why is integrating risk management with strategy selection important?

A

It helps in understanding the implications of a strategy and ensures alignment with the organization’s mission, vision, and values.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What are the benefits of integrating risk management with strategic planning?

A

Enhances strategic resilience and long-term performance by embedding risk considerations in decision-making at all levels.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

List the components of the COSO 2017 ERM Framework.

A
  • Governance and Culture
  • Strategy and Objective-Setting
  • Performance
  • Review and Revision

These components guide organizations in embedding risk considerations into governance, strategic decision-making, and operations.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is the purpose of the portfolio view of risk in ERM?

A

To consider risk in aggregate across the organization rather than in isolation.

The portfolio view informs decision-makers and enables a timely, coordinated response to risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Why is the Review and Revision component important in risk management?

A

Because business environments change, requiring regular evaluation and revision of ERM components.

This ensures risk responses remain appropriate and lessons learned inform continuous improvement.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is essential for effective risk management communication?

A
  • Capturing relevant risk information
  • Processing and communicating information throughout the organization
  • Transparency across all levels

External sources such as market data and regulatory updates are also essential inputs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is the objective of the COSO ERM framework?

A

To enhance an organization’s ability to understand and manage risk in alignment with its goals, thereby creating and preserving value.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Fill in the blank:

ERM integrates risk awareness into every part of an organization’s ______, operations, and performance monitoring.

A

strategy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the five components of the COSO ERM framework?

A
  • Governance and Culture
  • Strategy and Objective-Setting
  • Performance
  • Review and Revision
  • Information, Communication, and Reporting
17
Q

What principle involves the board of directors providing oversight of the strategy?

A

Exercises board risk oversight.

18
Q

What is the focus of the principle ‘Evaluates alternative strategies’?

A

Evaluating alternative strategies and their potential impact on the risk profile.

19
Q

What does the principle ‘Identifies risk’ entail?

A

Identifying risks and risk events that can impact the performance of strategy and business objectives.

20
Q

What does the principle ‘Prioritizes risks’ focus on?

A

Prioritizing risks as a basis for selecting responses to risks.

21
Q

What is the significance of the principle ‘Develops portfolio view’?

A

Developing and evaluating a portfolio view of risk.

22
Q

What does the principle ‘Assesses substantial change’ involve?

A

Identifying and assessing changes that may substantially affect strategy and business objectives.

23
Q

What is the goal of ‘Pursues improvement in enterprise risk management’?

A

Pursuing improvement of enterprise risk management.

24
Q

What does the principle ‘Leverages information systems’ emphasize?

A

Leveraging the entity’s information and technology systems to support enterprise risk management.

25
What is the role of '**Communicates risk information**' in ERM?
Using communication channels to support enterprise risk management.
26
What is the purpose of the principle '**Reports on risk, culture, and performance**'?
Reporting on risk, culture, and performance at multiple levels and across the entity.