SlideShare uma empresa Scribd logo
1 de 21
Public Workshop
Enterprise Risk       Deddy Jacobus, www.rwi.co.id
 Management
Deddy Jacobus

           • Senior Risk Management Partner, JPM & Partners,
             Jakarta

           • Secretary General, the Association of Risk Management
             Practitioners (ARMP), Jakarta, www.id.armp-asia.com

           • Member of the Steering Committee, Professional Risk
             Managers International Association (PRMIA), Chicago,
             US, www.prmia.org

           • Certified Member of the Institute of Internal Auditors
             (IIA), Florida, US., www.theiia.org

           • Certified Member of Lembaga Komisaris dan Direktur
             Indonesia (LKDI)

           • Certified in Risk and Control Self-Assessment (CCSA),
             IIA

           • MBA, Risk Management, Universitas Gadjah Mada.
Sharing Objectives

• Sharing Objective #1: To establish the importance
  of Enterprise Risk Management (ERM) to achieve
  corporate objectives

• Sharing Objective #2: An overview of ISO
  31000:2009 Risk Management Principles and
  Guideline
Sharing Objective #1

To establish the importance of Enterprise Risk
Management (ERM) to achieve corporate
objectives
• What is risk?

Some is the first...
• What basic
 difference
 between risk
 and
 uncertainty?

• Why is it
  important to
  manage
  risks?

• And...why
  the
  enterprise
  risk
is...

   •"...the effect

•of uncertainty on
    objectives."
Triggers of uncertainty

                          The wave of
                           changes




    Driven by
                             Uncertainty
    Driven by
    external and
    external and
    internal factors
    internal factors
                                 Poor ability to
                                  response
Some effects of uncertainties




Disasters do not just happen. They are
       critical chain of events...
A need of paradigm shift




              +
                                 Well-informed
  Reliable                       and responsive
                  Proven model
information                        Decision
                                    Making
  Risk management transforms a
    guesswork decision making
into a well-informed and responsive
Risk management paradigm shift




      Partial approach     ERM approach
ERM drives a paradigm shift in...


      Paradigma                  Paradigma
        Lama                        Baru
  Pengawasan/Pengendali       Pemberdayaan/Owners
           an                         hip

          Silo                      Integrated


         'Sinten'                    'Sistem'


      Jangka Pendek              Jangka Panjang


     Krisis/Minimize            Risiko/Optimize
Sharing Objective #2

An overview of ISO 31000:2009 Risk Management
Principles and Guideline
Risk management process in general

  Start         Risk Assessment Plan



                Risk Context Definition



      Accepta
      Accepta
        ble?      Risk Assessment
        ble?



                                          Risk Management Plan
                   Risk Response              and Execution



                    Risk Register            Risk Monitoring




                         End
International standards for ERM




   COSO 2004



                        ISO 31000:2009
ERM COSO Model

• Enterprise Risk Management (ERM) yang efektif membutuhkan adanya komponen-
  komponen berikut ini:
                                                       1. Niat & Kesungguhan

                                                      2. Tujuan yang tepat dan
                                                               selaras

                                                       3. Paham perubahan
                                                      eksternal & internal yang
                                    Komponen-             mungkin terjadi
                                     komponen
                                                      4. Paham dampak perubahan
                                                      4. Paham dampak perubahan
                                       untuk
                                                                 (risiko)
                                                                 (risiko)
                                    memastikan
                                    bahwa suatu     5. Tanggap strategik yang
                                    perusahaan         efektif thd perubahan
                                      memiliki:
                                                      6. Pengendalian secara
                                                             Internal

                                                    7. Optimalisasi knowledge
                                                             untuk...

                                                    8. Perbaikan Berkelanjutan
ISO 31000:2009-principles, framework,
process
Risk Register

 Business Unit/Project Name:                                                         Date:
 Process/Phase:                                                                      RCSA Participants:
 Time Period of Risk Assessment:
 Objective of Risk Assessment:
                                                                                                        Estimated
                                                           Risk Risk                                                     Risk
                             Inherent                                  Expected      Risk                Residual
Risk              Inherent              Current              after                                                      Owner,
     Objectives              Risk Level            L   I               Risk Level Response/Tr L   I   Risk Level after
 Id                 Risk                Controls           Control                                                     PIC, and
                             (L, M, H)                                 (L, M, H)   eatments             Treatment
                                                           (L, M, H)                                                   Sponsor
                                                                                                         (L, M, H)




                             Our worksheets must demonstrate the interrelated
                             Our worksheets must demonstrate the interrelated
                                     of objectives, risks, and controls
                                     of objectives, risks, and controls
Risk assessment

• How do we review our
  existing controls?

• Given our existing
  controls, how likely the
  event will occur?

• How the impacts will
  be measured?

• How the risk level will
  be determined?

• What measures to
  decide whether it is
  acceptable or
  unacceptable?

• What risks need to be
  responded?
Risk: exposure, appetite, tolerance and
controls




                                                Acceptable with   Unacceptable/
     Too low risk level   Acceptable ranges       conditions         avoid



                                              range of risk levels
An example of risk map and risk appetite



          R1
          R1        R6
                    R6

                            R5
                            R5




                     R4
               R2           R3
Thank you...
Deddy Jacobus
www.rwi.co.id
deddy@rwi.co.id
081510311103

Mais conteúdo relacionado

Mais procurados

Strategic risk management
Strategic risk managementStrategic risk management
Strategic risk management
rejoysirvel
 
Fundamentals of-risk-management
Fundamentals of-risk-managementFundamentals of-risk-management
Fundamentals of-risk-management
Majd Ghanem,MBA
 
Coso Erm(2)
Coso Erm(2)Coso Erm(2)
Coso Erm(2)
deeptica
 
Corporate Risk Management
Corporate Risk ManagementCorporate Risk Management
Corporate Risk Management
Shravan Bhumkar
 

Mais procurados (16)

Risk Management Frameworks
Risk Management FrameworksRisk Management Frameworks
Risk Management Frameworks
 
51_operational_risk
51_operational_risk51_operational_risk
51_operational_risk
 
How to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management FrameworkHow to Build an Enterprise Risk Management Framework
How to Build an Enterprise Risk Management Framework
 
Strategic risk management
Strategic risk managementStrategic risk management
Strategic risk management
 
Risk management chpt 2
Risk management chpt 2Risk management chpt 2
Risk management chpt 2
 
The importance of risk management in business
The importance of risk management in businessThe importance of risk management in business
The importance of risk management in business
 
Enterprise Risk Management
Enterprise Risk ManagementEnterprise Risk Management
Enterprise Risk Management
 
Fundamentals of-risk-management
Fundamentals of-risk-managementFundamentals of-risk-management
Fundamentals of-risk-management
 
Enterprise Risk Management
Enterprise Risk ManagementEnterprise Risk Management
Enterprise Risk Management
 
Coso Erm(2)
Coso Erm(2)Coso Erm(2)
Coso Erm(2)
 
Managing specialized risk_14
Managing specialized risk_14Managing specialized risk_14
Managing specialized risk_14
 
Chapter1 introduction to risk management
Chapter1  introduction to risk managementChapter1  introduction to risk management
Chapter1 introduction to risk management
 
Risk 6
Risk 6Risk 6
Risk 6
 
Corporate Risk Management
Corporate Risk ManagementCorporate Risk Management
Corporate Risk Management
 
Risk Management in Business
Risk Management in BusinessRisk Management in Business
Risk Management in Business
 
Risk management standard_030820
Risk management standard_030820Risk management standard_030820
Risk management standard_030820
 

Destaque

Is awareness government
Is awareness governmentIs awareness government
Is awareness government
Hamisi Kibonde
 

Destaque (9)

Is awareness government
Is awareness governmentIs awareness government
Is awareness government
 
Security Training: Necessary Evil, Waste of Time, or Genius Move?
Security Training: Necessary Evil, Waste of Time, or Genius Move?Security Training: Necessary Evil, Waste of Time, or Genius Move?
Security Training: Necessary Evil, Waste of Time, or Genius Move?
 
The security officer role in virtual environments - (ISC)2 LATAM CONGRESS 2016
The security officer role in virtual environments - (ISC)2 LATAM CONGRESS 2016The security officer role in virtual environments - (ISC)2 LATAM CONGRESS 2016
The security officer role in virtual environments - (ISC)2 LATAM CONGRESS 2016
 
Roles of Information Security Officers in State Government
Roles of Information Security Officers in State GovernmentRoles of Information Security Officers in State Government
Roles of Information Security Officers in State Government
 
IT Governance
IT GovernanceIT Governance
IT Governance
 
(ENT305) Develop an Enterprise-wide Cloud Adoption Strategy | AWS re:Invent 2014
(ENT305) Develop an Enterprise-wide Cloud Adoption Strategy | AWS re:Invent 2014(ENT305) Develop an Enterprise-wide Cloud Adoption Strategy | AWS re:Invent 2014
(ENT305) Develop an Enterprise-wide Cloud Adoption Strategy | AWS re:Invent 2014
 
ISO 31000 Risk Management
ISO 31000 Risk ManagementISO 31000 Risk Management
ISO 31000 Risk Management
 
Enterprise Security Architecture for Cyber Security
Enterprise Security Architecture for Cyber SecurityEnterprise Security Architecture for Cyber Security
Enterprise Security Architecture for Cyber Security
 
Enterprise Security Architecture
Enterprise Security ArchitectureEnterprise Security Architecture
Enterprise Security Architecture
 

Semelhante a Enterprise Risk Management - Deddy Jacobus

Enterprise Risk Management - Deddy Jacobus
Enterprise Risk Management - Deddy JacobusEnterprise Risk Management - Deddy Jacobus
Enterprise Risk Management - Deddy Jacobus
Deddy Jacobus
 
Enterprise Risk Management - Deddy Jacobus
Enterprise Risk Management - Deddy JacobusEnterprise Risk Management - Deddy Jacobus
Enterprise Risk Management - Deddy Jacobus
Deddy Jacobus
 
AACE Presentation Final 2007
AACE Presentation Final 2007AACE Presentation Final 2007
AACE Presentation Final 2007
janknopfler
 
Microsoft Power Point Simon Final
Microsoft Power Point   Simon FinalMicrosoft Power Point   Simon Final
Microsoft Power Point Simon Final
guesta09d518
 
Risk management standard_030820
Risk management standard_030820Risk management standard_030820
Risk management standard_030820
Tim Smith
 
Riskpro Iso 31000 Services
Riskpro Iso 31000 ServicesRiskpro Iso 31000 Services
Riskpro Iso 31000 Services
Rahul Bhan (CA, CIA, MBA)
 
Riskpro Iso 31000 Services
Riskpro Iso 31000 ServicesRiskpro Iso 31000 Services
Riskpro Iso 31000 Services
Rahul Bhan (CA, CIA, MBA)
 

Semelhante a Enterprise Risk Management - Deddy Jacobus (20)

Enterprise Risk Management - Deddy Jacobus
Enterprise Risk Management - Deddy JacobusEnterprise Risk Management - Deddy Jacobus
Enterprise Risk Management - Deddy Jacobus
 
Erm public workshop
Erm public workshopErm public workshop
Erm public workshop
 
Enterprise Risk Management - Deddy Jacobus
Enterprise Risk Management - Deddy JacobusEnterprise Risk Management - Deddy Jacobus
Enterprise Risk Management - Deddy Jacobus
 
Presentation qrm shc
Presentation qrm shcPresentation qrm shc
Presentation qrm shc
 
AACE Presentation Final 2007
AACE Presentation Final 2007AACE Presentation Final 2007
AACE Presentation Final 2007
 
Iso 31000 presentation
Iso 31000 presentationIso 31000 presentation
Iso 31000 presentation
 
Microsoft power point risk governance-schreckenberg_swissre_idrc_2012
Microsoft power point   risk governance-schreckenberg_swissre_idrc_2012Microsoft power point   risk governance-schreckenberg_swissre_idrc_2012
Microsoft power point risk governance-schreckenberg_swissre_idrc_2012
 
Microsoft Power Point Simon Final
Microsoft Power Point   Simon FinalMicrosoft Power Point   Simon Final
Microsoft Power Point Simon Final
 
FERMA Survey Part 1 - The Maturity of Risk Management in Europe
FERMA Survey Part 1 - The Maturity of Risk Management in EuropeFERMA Survey Part 1 - The Maturity of Risk Management in Europe
FERMA Survey Part 1 - The Maturity of Risk Management in Europe
 
Risk leadership perspectives Risk Manager of the Year
Risk leadership perspectives Risk Manager of the YearRisk leadership perspectives Risk Manager of the Year
Risk leadership perspectives Risk Manager of the Year
 
Risk management standard_030820
Risk management standard_030820Risk management standard_030820
Risk management standard_030820
 
Risk management standard_030820
Risk management standard_030820Risk management standard_030820
Risk management standard_030820
 
Risk management standard_030820
Risk management standard_030820Risk management standard_030820
Risk management standard_030820
 
Risk management standard
Risk management standardRisk management standard
Risk management standard
 
Riskpro Iso 31000 Services
Riskpro Iso 31000 ServicesRiskpro Iso 31000 Services
Riskpro Iso 31000 Services
 
Riskpro Iso 31000 Services
Riskpro Iso 31000 ServicesRiskpro Iso 31000 Services
Riskpro Iso 31000 Services
 
Riskpro Iso 31000 Services
Riskpro Iso 31000 ServicesRiskpro Iso 31000 Services
Riskpro Iso 31000 Services
 
Riskpro Iso 31000 Services
Riskpro Iso 31000 ServicesRiskpro Iso 31000 Services
Riskpro Iso 31000 Services
 
Riskpro Iso 31000 Services
Riskpro Iso 31000 ServicesRiskpro Iso 31000 Services
Riskpro Iso 31000 Services
 
Information Security Risk Management
Information Security Risk Management Information Security Risk Management
Information Security Risk Management
 

Último

Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al MizharAl Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
allensay1
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
daisycvs
 

Último (20)

Paradip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Paradip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDINGParadip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Paradip CALL GIRL❤7091819311❤CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
 
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...
Escorts in Nungambakkam Phone 8250092165 Enjoy 24/7 Escort Service Enjoy Your...
 
Ooty Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Avail...
Ooty Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Avail...Ooty Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Avail...
Ooty Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Avail...
 
New 2024 Cannabis Edibles Investor Pitch Deck Template
New 2024 Cannabis Edibles Investor Pitch Deck TemplateNew 2024 Cannabis Edibles Investor Pitch Deck Template
New 2024 Cannabis Edibles Investor Pitch Deck Template
 
Falcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investorsFalcon Invoice Discounting: The best investment platform in india for investors
Falcon Invoice Discounting: The best investment platform in india for investors
 
Lucknow Housewife Escorts by Sexy Bhabhi Service 8250092165
Lucknow Housewife Escorts  by Sexy Bhabhi Service 8250092165Lucknow Housewife Escorts  by Sexy Bhabhi Service 8250092165
Lucknow Housewife Escorts by Sexy Bhabhi Service 8250092165
 
Phases of Negotiation .pptx
 Phases of Negotiation .pptx Phases of Negotiation .pptx
Phases of Negotiation .pptx
 
Falcon Invoice Discounting: Unlock Your Business Potential
Falcon Invoice Discounting: Unlock Your Business PotentialFalcon Invoice Discounting: Unlock Your Business Potential
Falcon Invoice Discounting: Unlock Your Business Potential
 
Lundin Gold - Q1 2024 Conference Call Presentation (Revised)
Lundin Gold - Q1 2024 Conference Call Presentation (Revised)Lundin Gold - Q1 2024 Conference Call Presentation (Revised)
Lundin Gold - Q1 2024 Conference Call Presentation (Revised)
 
Nashik Call Girl Just Call 7091819311 Top Class Call Girl Service Available
Nashik Call Girl Just Call 7091819311 Top Class Call Girl Service AvailableNashik Call Girl Just Call 7091819311 Top Class Call Girl Service Available
Nashik Call Girl Just Call 7091819311 Top Class Call Girl Service Available
 
Arti Languages Pre Seed Teaser Deck 2024.pdf
Arti Languages Pre Seed Teaser Deck 2024.pdfArti Languages Pre Seed Teaser Deck 2024.pdf
Arti Languages Pre Seed Teaser Deck 2024.pdf
 
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
Unveiling Falcon Invoice Discounting: Leading the Way as India's Premier Bill...
 
How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League City
 
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al MizharAl Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
Al Mizhar Dubai Escorts +971561403006 Escorts Service In Al Mizhar
 
Cannabis Legalization World Map: 2024 Updated
Cannabis Legalization World Map: 2024 UpdatedCannabis Legalization World Map: 2024 Updated
Cannabis Legalization World Map: 2024 Updated
 
Horngren’s Cost Accounting A Managerial Emphasis, Canadian 9th edition soluti...
Horngren’s Cost Accounting A Managerial Emphasis, Canadian 9th edition soluti...Horngren’s Cost Accounting A Managerial Emphasis, Canadian 9th edition soluti...
Horngren’s Cost Accounting A Managerial Emphasis, Canadian 9th edition soluti...
 
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
Quick Doctor In Kuwait +2773`7758`557 Kuwait Doha Qatar Dubai Abu Dhabi Sharj...
 
Berhampur 70918*19311 CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Berhampur 70918*19311 CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDINGBerhampur 70918*19311 CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
Berhampur 70918*19311 CALL GIRLS IN ESCORT SERVICE WE ARE PROVIDING
 
joint cost.pptx COST ACCOUNTING Sixteenth Edition ...
joint cost.pptx  COST ACCOUNTING  Sixteenth Edition                          ...joint cost.pptx  COST ACCOUNTING  Sixteenth Edition                          ...
joint cost.pptx COST ACCOUNTING Sixteenth Edition ...
 
Chennai Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Av...
Chennai Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Av...Chennai Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Av...
Chennai Call Gril 80022//12248 Only For Sex And High Profile Best Gril Sex Av...
 

Enterprise Risk Management - Deddy Jacobus

  • 1. Public Workshop Enterprise Risk Deddy Jacobus, www.rwi.co.id Management
  • 2. Deddy Jacobus • Senior Risk Management Partner, JPM & Partners, Jakarta • Secretary General, the Association of Risk Management Practitioners (ARMP), Jakarta, www.id.armp-asia.com • Member of the Steering Committee, Professional Risk Managers International Association (PRMIA), Chicago, US, www.prmia.org • Certified Member of the Institute of Internal Auditors (IIA), Florida, US., www.theiia.org • Certified Member of Lembaga Komisaris dan Direktur Indonesia (LKDI) • Certified in Risk and Control Self-Assessment (CCSA), IIA • MBA, Risk Management, Universitas Gadjah Mada.
  • 3. Sharing Objectives • Sharing Objective #1: To establish the importance of Enterprise Risk Management (ERM) to achieve corporate objectives • Sharing Objective #2: An overview of ISO 31000:2009 Risk Management Principles and Guideline
  • 4. Sharing Objective #1 To establish the importance of Enterprise Risk Management (ERM) to achieve corporate objectives
  • 5. • What is risk? Some is the first... • What basic difference between risk and uncertainty? • Why is it important to manage risks? • And...why the enterprise risk
  • 6. is... •"...the effect •of uncertainty on objectives."
  • 7. Triggers of uncertainty The wave of changes Driven by Uncertainty Driven by external and external and internal factors internal factors Poor ability to response
  • 8. Some effects of uncertainties Disasters do not just happen. They are critical chain of events...
  • 9. A need of paradigm shift + Well-informed Reliable and responsive Proven model information Decision Making Risk management transforms a guesswork decision making into a well-informed and responsive
  • 10. Risk management paradigm shift Partial approach ERM approach
  • 11. ERM drives a paradigm shift in... Paradigma Paradigma Lama Baru Pengawasan/Pengendali Pemberdayaan/Owners an hip Silo Integrated 'Sinten' 'Sistem' Jangka Pendek Jangka Panjang Krisis/Minimize Risiko/Optimize
  • 12. Sharing Objective #2 An overview of ISO 31000:2009 Risk Management Principles and Guideline
  • 13. Risk management process in general Start Risk Assessment Plan Risk Context Definition Accepta Accepta ble? Risk Assessment ble? Risk Management Plan Risk Response and Execution Risk Register Risk Monitoring End
  • 14. International standards for ERM COSO 2004 ISO 31000:2009
  • 15. ERM COSO Model • Enterprise Risk Management (ERM) yang efektif membutuhkan adanya komponen- komponen berikut ini: 1. Niat & Kesungguhan 2. Tujuan yang tepat dan selaras 3. Paham perubahan eksternal & internal yang Komponen- mungkin terjadi komponen 4. Paham dampak perubahan 4. Paham dampak perubahan untuk (risiko) (risiko) memastikan bahwa suatu 5. Tanggap strategik yang perusahaan efektif thd perubahan memiliki: 6. Pengendalian secara Internal 7. Optimalisasi knowledge untuk... 8. Perbaikan Berkelanjutan
  • 17. Risk Register Business Unit/Project Name: Date: Process/Phase: RCSA Participants: Time Period of Risk Assessment: Objective of Risk Assessment: Estimated Risk Risk Risk Inherent Expected Risk Residual Risk Inherent Current after Owner, Objectives Risk Level L I Risk Level Response/Tr L I Risk Level after Id Risk Controls Control PIC, and (L, M, H) (L, M, H) eatments Treatment (L, M, H) Sponsor (L, M, H) Our worksheets must demonstrate the interrelated Our worksheets must demonstrate the interrelated of objectives, risks, and controls of objectives, risks, and controls
  • 18. Risk assessment • How do we review our existing controls? • Given our existing controls, how likely the event will occur? • How the impacts will be measured? • How the risk level will be determined? • What measures to decide whether it is acceptable or unacceptable? • What risks need to be responded?
  • 19. Risk: exposure, appetite, tolerance and controls Acceptable with Unacceptable/ Too low risk level Acceptable ranges conditions avoid range of risk levels
  • 20. An example of risk map and risk appetite R1 R1 R6 R6 R5 R5 R4 R2 R3