
Explanation:
The statement that the risk appetite and tolerance statement for operational risk should be approved and periodically reviewed by senior management is incorrect. In accordance with operational risk management principles, it is the responsibility of the board of directors (not senior management) to approve and periodically review the risk appetite and tolerance statements to ensure they remain consistent with the organization's overall strategy and risk capacity. Senior management is responsible for implementing the framework and adhering to the risk limits set by the board.
Ultimate access to all questions.
Q.5062 Mr. Ibrahim Rashid is a lecturer at Oxford University. In one of his lectures on risk appetite and tolerance, Rashid states several points regarding risk appetite and risk tolerance. Which of the following statements made by Rashid is incorrect?
A
As a good practice of risk appetite, a risk owner should be assigned to each risk type; control owners to design, implement, and evaluate controls
B
Risk appetite should be consistent with the firm's objectives and the firm's risk management strategy
C
To demonstrate their risk appetite and tolerance for disruptions, firms must set maximum impact tolerances for critical business services
D
Risk appetite and tolerance statement for operational risk to be approved and periodically reviewed by senior management
No comments yet.