← All PGI Flashcard Decks

Risk Management Principles Flashcards

6 cards from real PGI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Risk Management Principles flashcards as text
  1. What is the 'risk management process' and what are its key steps?

    Answer: Risk identification, risk assessment, risk treatment, and monitoring and review — a continuous cycle

    The risk management process is a continuous cycle: identify risks, assess their likelihood and impact, determine appropriate treatment (avoid, reduce, transfer, or accept), implement treatment, and monitor and review effectiveness on an ongoing basis.

  2. What are the four main risk treatment strategies?

    Answer: Avoidance, reduction, transfer (including insurance), and retention (acceptance)

    The four main risk treatment strategies are: Avoidance (eliminating the risk), Reduction/Mitigation (reducing likelihood or impact), Transfer (e.g., via insurance or contracts), and Retention/Acceptance (keeping the risk, often with a contingency fund).

  3. What is 'enterprise risk management' (ERM) and how does it differ from traditional risk management?

    Answer: ERM takes a holistic, organization-wide view of all risk categories in an integrated framework, rather than managing risks in silos

    ERM integrates all categories of risk across the entire organization into a single coherent framework, considering interdependencies between risks. Traditional risk management often addresses individual risk types in separate departments without considering the bigger picture.

  4. What is 'risk appetite' and how does it guide an organization's risk management?

    Answer: The amount and type of risk an organization is willing to accept in pursuit of its strategic objectives

    Risk appetite defines how much risk an organization is willing to take in pursuing its goals. It guides decision-making, resource allocation, and risk treatment choices — risks within appetite may be accepted; those outside it must be treated.

  5. What is the purpose of a 'risk register' in organizational risk management?

    Answer: A documented record of identified risks, their assessment, ownership, and treatment plans, serving as the central tool for risk management

    A risk register is a central document recording all identified risks, their likelihood and impact ratings, risk owners, current controls, and treatment plans. It provides visibility across the organization and enables monitoring of risk management activities.

  6. What is the difference between 'inherent risk' and 'residual risk' in risk assessment?

    Answer: Inherent risk is the risk before any controls are applied; residual risk is the risk remaining after controls are in place

    Inherent risk is the raw, unmitigated risk level before any controls or treatments are applied. Residual risk is what remains after controls are in place and functioning effectively. Good risk management reduces inherent risk to an acceptable residual level.