Risk management standards
75
Risk management context
There are many risk management standards and risk management frameworks that
have been produced by various organizations. It is generally acknowledged that a
standard is a document that produces information on both the risk management
process and the risk management framework.
Within many risk management standards it is stated that risk management
activities should take place within the context of the business environment, the
organization and the risks faced by the organization. In order for the context to be
described and defined, a framework is required to implement and support the risk
management process. ISO 31000 places particular emphasis on context and states
that consideration should be given to the internal context, external context and risk
management context when undertaking risk management activities.
All of the established risk management standards refer to the risk management
framework, although this is represented in different ways. In order to provide a simple
explanation of the scope of the risk management framework, the acronym risk,
architecture, strategy and protocols (RASP) has been developed. Figure 6.2 illustrates
FIgURE
6.2
Components of the RM context
Risk strategy
• Risk strategy, appetite, attitudes
and philosophy are defined in the risk
management policy
Risk architecture
• Risk architecture defines roles,
responsibilities, communication
and risk-reporting structure
Risk management
process
Risk protocols
• Risk protocols are defined in the risk guidelines for the organization and include the
rules and procedures, as well as the risk management methodologies, tools and
techniques that should be used
Do'stlaringiz bilan baham: |