Chapter 3 - Risk Definition and Taxonomy Flashcards

1
Q

Is technology a risk or resource

A

a resource

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

is manual processing considered a risk

A

it’s a cause/risk driver- increases
probability of risk e.g. input errors and omissions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

what are the Risks due to
manual processing

A

errors in the valuation of funds, errors in accounting records, omitting to send reports to clients

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

are Inadequate supervision or insufficient training considered risks

A

they are control failures

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

solution to control failiures

A

fix the control. Or add a secondary control

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

what can Inadequate supervision lead to

A

internal fraud, sub-standard productivity resulting in customer dissatisfaction or loss.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

how should Risks be defined as

A

negative events, uncertainties, incidents or accidents. They should be specific and concrete

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

simple question to define risks

A

“What could go wrong?”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Basel category level 1

A

Event-type
category

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Basel category level 2

A

categories (sub categories of level 1)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Basel category level 3

A

Activity examples

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Level 2 categories of Internal fraud (level 1)

A
  • Unauthorised activity
  • Theft and Fraud
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Level 2 categories of external fraud (level 1)

A
  • Systems security
  • Theft and Fraud
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Risk of too much detail in risk identification

A

detrimental to quality of information and is difficult to review- drains effort without benefits

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How many levels of regulatory categories does basel commitee recognise

A

2 levels of category, level 3 is just for detail/examples

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

what is required when for firms to categorise risks

A

firms are required to map risk categories to the Basel categories

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

what do firms not have to do when classifying risks

A

n doesn’t have to define a firm’s risk taxonomy these days

15
Q

When was the basel classification drafted

A

almsot 20 years ago

16
Q

what has led to tncrease in cybercrime

A

mass digitization

17
Q

what has multiplied the risks of outsourcing project/change management, and information management

A

Business transformation and wider international operations

18
Q

what have business practices been renamed as

19
Q

what did 08 highlight the need for higher focus on

A

“conduct,” anti-money laundering (AML),
international sanctions and preventing tax-evasion

20
Q

how many risk classification’s do Basel have

21
Q

dictionary definition of taxonomy

A

a “scheme of classification.”

22
what does taxonomy mean in terms of risk management
categorizing risks and recording causes, impacts and controls as a MECE system
23
whats a mece system
Mutually Exclusive and Collectively Exhaustive
24
Basel definition of operational risk
“The risk from failed internal processes, people, systems or external events”
25
What was initially counted as a loss from operational risk in the 1990s - what did this grow to include
At first only financial, now reputational is included
26
What are the current four commonly used categories for the impacts of operational risks
financial, reputation , regulatory non-compliance and customer detriment
27
Which firms find continuity of services important
online financial services or trading platforms
28
a common category of impact for firms where continuity of service is important
service disruption
29
PPSE/ causes of risk in a mece taxonomy
people, processes, systems or external events
30
The four main categories of controls in a mece taxonomy
Preventive, Detective, Corrective, Directive
31
Preventive control
reduce likelihood of risks by mitigating their causes
32
Detective control
during the event/soon after, early detection to reduce impact
33
Corrective control
reduces impacts caused by incidents. Damage is repaired /loss compensated by using backup and redundancies
34
Directive control
comprises guidelines and procedures that structure the mode of operations to reduce risks.
35
When does detective control have a preventative element
if detection also identifies the cause of an incident
36
4 parts of a mece taxonomy
Causes Risks Impacts Controls
37
4 impacts of risks in a mece taxonomy
Financial loss Reputation damage Regulatory breach Customer detriment
38
Operations risk L1 code
5
39
Information security risk L1 code
6