Chpt 5 Flashcards

1
Q

What is RCSA?

A

Risk and Control Self-Assessment - a process for identifying, assessing and managing risks and controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the benefits of RCSA?

A

Cultural change, strategy alignment, consensus, accountability, anticipating threats, efficiency.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the role of RCSA?

A

Proactively identify and manage operational risks before they impact objectives.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Name 3 RCSA approaches.

A

Workshops, Questionnaires, Hybrid.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are 2 advantages of RCSA workshops?

A

Interaction, guidance, buy-in.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are 2 disadvantages of questionnaires?

A

Misinterpretation, bias.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Define likelihood.

A

Possibility of a risk event occurring.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Define impact.

A

Consequences if an operational risk occurs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is assessed for likelihood and impact?

A

Inherent risk and residual risk.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Name 4 types of controls.

A

Preventative, detective, corrective, directive.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What determines if a control is effective?

A

Design and operation.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Who is the risk owner?

A

Accountable for managing risk identification, assessments etc.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Who is the control owner?

A

Designs, operates and monitors controls.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Name 4 risk response actions.

A

Accept, reduce, transfer, avoid.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What are 2 uses of risk reporting?

A

Guide decisions, raise awareness.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What does a heat map show?

A

Visual summary of risk exposures.

17
Q

Name 3 triggers for ad hoc RCSA.

A

Change in appetite, restructure, new regulation.

18
Q

What validates likelihood and impact assessments?

A

Risk indicators and loss events.

19
Q

What are 3 reporting contents?

A

Assessments, actions, changes.

20
Q

What maintains RCSA as BAU activity?

A

Governance committee oversight.

21
Q

What skills make an effective RCSA facilitator?

A

Risk knowledge, challenge consensus, unbiased.

22
Q

What evidences control effectiveness?

A

Testing and attestation.

23
Q

What causes re-assessment of risks?

A

Changes in likelihood, impacts or controls.

24
Q

What improves reporting?

A

Interpretation not just data.

25
Q

What is a risk register?

A

Database recording RCSA outputs.

26
Q

What confirms RCSA adds value?

A

Implemented efficiency improvements.