PGI Risk Management Principles 1 — Questions and Answers
Question 1: What is the 'risk management process' and what are its key steps?
- Buying insurance to cover all identified risks
- Risk identification, risk assessment, risk treatment, and monitoring and review — a continuous cycle (Correct answer)
- Writing risk reports for shareholders only
- Outsourcing all risks to insurance companies
Correct answer: Risk identification, risk assessment, risk treatment, and monitoring and review — a continuous cycle
The risk management process is a continuous cycle: identify risks, assess their likelihood and impact, determine appropriate treatment (avoid, reduce, transfer, or accept), implement treatment, and monitor and review effectiveness on an ongoing basis.
Question 2: What are the four main risk treatment strategies?
- Buy, sell, trade, and hold
- Avoidance, reduction, transfer (including insurance), and retention (acceptance) (Correct answer)
- Mitigate, arbitrate, litigate, and negotiate
- Identify, measure, monitor, and report
Correct answer: Avoidance, reduction, transfer (including insurance), and retention (acceptance)
The four main risk treatment strategies are: Avoidance (eliminating the risk), Reduction/Mitigation (reducing likelihood or impact), Transfer (e.g., via insurance or contracts), and Retention/Acceptance (keeping the risk, often with a contingency fund).
Question 3: What is 'enterprise risk management' (ERM) and how does it differ from traditional risk management?
- ERM is identical to traditional risk management
- ERM takes a holistic, organization-wide view of all risk categories in an integrated framework, rather than managing risks in silos (Correct answer)
- ERM focuses only on financial risks
- ERM is only applicable to financial institutions
Correct answer: ERM takes a holistic, organization-wide view of all risk categories in an integrated framework, rather than managing risks in silos
ERM integrates all categories of risk across the entire organization into a single coherent framework, considering interdependencies between risks. Traditional risk management often addresses individual risk types in separate departments without considering the bigger picture.
Question 4: What is 'risk appetite' and how does it guide an organization's risk management?
- The organization's desire to eliminate all risks
- The amount and type of risk an organization is willing to accept in pursuit of its strategic objectives (Correct answer)
- The maximum insurance premium an organization will pay
- The organization's historical claims experience
Correct answer: The amount and type of risk an organization is willing to accept in pursuit of its strategic objectives
Risk appetite defines how much risk an organization is willing to take in pursuing its goals. It guides decision-making, resource allocation, and risk treatment choices — risks within appetite may be accepted; those outside it must be treated.
Question 5: What is the purpose of a 'risk register' in organizational risk management?
- A register of all insurance policies held
- A documented record of identified risks, their assessment, ownership, and treatment plans, serving as the central tool for risk management (Correct answer)
- A register of all employees with risk-related responsibilities
- A list of insurance claims made in the past year
Correct answer: A documented record of identified risks, their assessment, ownership, and treatment plans, serving as the central tool for risk management
A risk register is a central document recording all identified risks, their likelihood and impact ratings, risk owners, current controls, and treatment plans. It provides visibility across the organization and enables monitoring of risk management activities.
Question 6: What is the difference between 'inherent risk' and 'residual risk' in risk assessment?
- They are the same concept with different names
- Inherent risk is the risk before any controls are applied; residual risk is the risk remaining after controls are in place (Correct answer)
- Inherent risk applies to operational risks; residual risk to financial risks
- Residual risk is always greater than inherent risk
Correct answer: Inherent risk is the risk before any controls are applied; residual risk is the risk remaining after controls are in place
Inherent risk is the raw, unmitigated risk level before any controls or treatments are applied. Residual risk is what remains after controls are in place and functioning effectively. Good risk management reduces inherent risk to an acceptable residual level.
What is the 'risk management process' and what are its key steps?