352 Index
capacity see risk capacity
capital adequacy 205
captive insurance companies 284–86, 285
Chicago Fire 278, 279
chief risk offi cer (CRO) 41, 42, 93–94, 227
classifi cation systems see risk classifi cation
systems
clinical risk management 42, 78
Combined Code on Corporate Governance 175
Committee of Sponsoring Organizations see
COSO framework
Companies Act 2006 90
compliance, assurance, decisions and effi ciency/
effectiveness/effi cacy (CADE3) 4–5, 46–47,
50, 88, 154, 155, 227, 302, 308, 328, 333
contingency planning 40, 129, 170
in projects 33, 200, 202, 251
see also uncertainty
control environment 293–96
evaluating the
features of
see also Canadian Criteria of Control (CoCo)
framework
control risks 2, 13–14, 29, 30, 33, 137–39
control management 51, 104
in project risk management 199
and risk appetite 236–37
and risk assurance 311
see also hazard risks, opportunity risks
core processes 22, 23, 39, 42–43, 90, 161
and the business model 193–94
and enterprise risk management 225–26
ownership of 87–88
and risk classifi cations systems 131–32, 139
and stakeholders 188, 188–89
see also upside of risk
corporate governance 175–84
for a bank 179
board performance, evaluation of 182–84,
183–84
committees 176
and corporate social responsibility
(CSR) 321–22
enforcement of 175
for a government agency 180, 180–82
London Stock Exchange framework 177–78,
178
Nolan principles 181
principles of 176, 177, 178
purpose of 175
corporate social responsibility (CSR) 271,
321–26
and corporate governance 321–22
defi nition of 322
ethical trading 324–25
issues covered by 322
reporting 326
and reputational risk 323, 325
and risk management 322, 323
social, ethical and environmental (SEE)
concerns 321
and stakeholders 323–24, 326
corrective controls 254, 258
COSO framework 55, 58, 133, 139, 212, 272,
296, 314
COSO ERM standard 3, 53, 54–55, 56, 58,
58–59, 59, 62, 94, 108, 111, 133–34, 231,
293, 296, 298, 314
COSO Internal Control framework 54, 55,
56, 108, 133–34, 231, 296, 314
credit risk 17, 206, 207, see also insurance
CSR see corporate social responsibility (CSR)
culture see risk culture
current risk 16, 121, 141–42, 142, 239
Delta and Northwest Airlines merger 19
detective controls 256, 259–60
directive controls 256, 258–59
directors, role of 90–91, 97–98
directors’ & offi cers’ (D&O) insurance 281
disaster recovery plan (DRP) 150, 256, see also
business recovery planning (BRP)
disruption, categories of 30, 31
enterprise risk management (ERM) 42–43,
225–32, 335
benefi ts of 228
and business continuity planning 229