Diablo Valley College Write Risk Event and Risk Exposure Selection Paper
Description
There are 2 parts to this Presentation. Part II is an enterprise level project plan proposal, and is distinct from PART I.
-
Part I: For Specific Risk Events/ risk exposures across one or more risk types: Apply these concepts, terminology,
methodology to identify, risk assess real-life risk event & a material risk exposure of a public company to create a Board
report with risk response (action plan) and monitoring (KRI) frequency.
-
Part II: Perform a gap analysis and propose a project plan for Enterprise-wide Risk Framework Enhancements in response
to a regulatory finding (FRB, OCC, NYS DFS 500) to enhance risk governance framework and risk capabilities at the firm. Use
COSO Internal Control Framework, COSO ERM Framework and/or ISO Framework principles as a benchmark. - Approach: Utilize required reading and class material to demonstrate your understanding for Sessions 1 to 12. Use optional
reference material provided in Canvas and research online to risk assess the event.
- Risk Identification (root cause analysis including risk factors- triggers and conditions),
-
Risk Assessment and Measurement (Assess Inherent Risk (Impact x Likelihood with rationale, Assign Control rating (with
rationale and map the control weaknesses to COSO Internal Control and/or COSO ERM frameworks) to derive Residual Risk - Risk Mitigation and Corrective Action Plans (projects/plans to strengthen specific control weakness identified above
-
Risk Monitoring- Establish KRIs around risk factors identified in root cause analysis above
o COSO KRI paper entitled “Developing Key Risk Indicators to Strengthen Enterprise Risk management” provided in
Canvas files (see sections on Developing KRIS, Sources & information when developing KRIS and KRI communication &
reporting)
o And other required and optional material provided in syllabus and as class material to improve your work.
1 Step by Step Approach and Rubric for Grading:
Part I: For Specific Risk Events/ risk exposures across one or more risk types: Apply these concepts, terminology, methodology to
identify, risk assess real-life risk event & a material risk exposure of a public company to create a Board report with risk response
(action plan) and monitoring (KRI) frequency.
Material Risk
The material risk event or risk exposure can be non-financial (operational, model, vendor, cyber) or strategic or financial risk
(credit, market, liquidity/funding). Please note that Reputational Risk is always a secondary or tertiary knock-on effect, so
please do not select it.
Select
a. One real, material risk event of a public company from recent news (within the past 2 years) to conduct root cause analysis
is a designation that (typically in a particular regulatory context) indicates that a certain risk is of sufficient
significance for an organization that it must be managed following certain minimum criteria.
As part of Capital Adequacy
Assessment Process, regulated financial institutions must identify and manage all their material risks.
1. (Total 25 points): Risk Event and Risk Exposure Selection
A. (20 points) Risk Event Selection Process by performing a Bow-tie analysis diagram using Titanic Template- Needed
using Titanic bow-tie template provided.
b. One real, material risk exposure from Annual reports or another material risk event to perform Annual or bi-annual Risk
Assessment performed by the business line process owner or 4rd line auditor.
How to ensure risks is material? For this, determine Inherent Risk to the company: Adapt the Likelihood and Impact rating in
Session 2 slides to your company’s size, complexity, and business risk profile. To derive the materiality of the inherent risk,
please follow the instructions provided in the class, If you have Qs, please ask us after you have documented your Impact
rationale and likelihood rationale in discussion forum. This is the most important step as you don’t want to select a minor
incident to report to the Board.
a. Using the Impact x Likelihood scale + rationale for each, determine if the Inherent Risk rating is in Critical/ High range.
This is generally the range of material risk, and it is important enough to be mitigated and reported to the board, even
if it is well managed/ monitored and the controls are strong.
2 Identify the Risk Factors, Risk Conditions & Risk Consequences: For the selected material risk, conduct the root cause via
Bow-Tie analysis Diagram using Session 1- Titanic template and include Risk Factors (Blues: Trigger events – root causes;
Greens: Conditions – root causes); Risk Event: Red; Consequences: Yellows: Consequences and end event (loss))
B. (5 points) Risk Exposure Selection Process: Bow-tie Analysis NOT needed. But you need to identify risk factors around which
KRIs will need to be established.
2. (2.5 points each= Total 5 points): Summarize/ Describe risk event and risk exposure
A. Summarize the risk event in two sentences. (Describe who, what, when why and how- root cause).
B. Describe/ summarize the risk exposure in two sentences
Have a similar assignment? "Place an order for your assignment and have exceptional work written by our team of experts, guaranteeing you A results."