2 - Risk appetite and culture
Deal and Kennedy: risk, feedback and reward
3 - Risk assessment
* Framework
- Identification
- Analysis
- Mapping
- Consolidation
3 - Risk assessment
Risk and event identification
- External events
- Internal events
- Leading event indicators
- Trends and root cacuses
- Escalation triggers
- Event interdependencies
3 - Risk assessment
Analysis
means obtaining an idea of the severity of the consequences of the risk materialising and how
frequently (or likely) it is that the risk will materialise.
* Risk quantification - risk that require more analysis can be quantified, where possible results or losses
and probabilities are calculated and distributions or confidence limits added on. From this exercise is
derived the following key data:
- Average or expected result or loss
- Frequency of losses
- Chances of losses
- Largest predictable loss
3 - Risk assessment
Risk mapping
3 - Risk assessment
Consolidation
Now risk needs to be aggregated to corp leveel and grouped into categories.
A good way to approach exam questions on risk is to analyse:
- what do we know or what can we infer from the scenario about the risks and their causes (consider
events that result in risk and conditions that result in risk)
- what is the likelihood of the risk materialising and how severe will the consequences be
* A risk register lists and prioritises the main risks an org faces and can be used for decisions. Monetary
value sh/be added, interdependencies, who is responsible, actions taken, levels before and after control
has been taken for a CBA.
4 - Risk response
Methods of dealing with risk include abandonment, control, acceptance and transfer