Skip to main content

Form Number (3)

Effective from 30/4/2020

 

Risk Assessment as of [DATE]
Identified Risks and SchemesLikelihoodSignificanceRisk RatingControls Effectiveness AssessmentResidual RisksRisk Response (List an action plan on how each residual risk will be mitigated)
Insurance risk      
Credit risk      
Market risk      
Operational risk      
Regulatory risk      
Contagion and related party risk      
Financial crime risk      
Cyber risk      
Strategic risk      
Regulatory Risk      

 

Likelihood
RatingBased on Annual FrequencyBased on Annual Probability of Occurrence
DescriptorDefinitionDescriptorDefinition
5Very frequentMore than twenty times per yearAlmost certain>90% chance of occurrence
4FrequentSix to twenty times per yearLikely65% to 90% chance of occurrence
3Reasonably frequentTwo to five times per yearReasonably possible35% to 65% chance of occurrence
2OccasionalOnce per yearUnlikely10% to 35% chance of occurrence
1RareLess than once per yearRemote< 10% chance of occurrence

 

Significance
RatingDescriptor
5Catastrophic
4Major
3Moderate
2Minor
1Incidental

 

Control Effectiveness
Control Risk RatingDescription
5Very effective (reduces 81-100% of the risk)
4Effective (reduces 61-80% of the risk)
3Moderately effective (reduces 41-60% of the risk)
2Marginally effective (reduces 21-40% of the risk)
1Not effective (reduces 0-20% of the risk)

 

OVERALL ASSURANCE
FULL " Very effective"Full assurance that the system of internal control is designed to meet the organisation's objectives and controls are consistently applied in all the areas reviewed
SIGNIFICANT " Effective"Significant assurance that there is a generally sound system of control designed to meet the organisation's objectives. However, some weakness in the design or inconsistent application of controls put the achievement of particular objectives at risk.
LIMITED " Moderately effective"Limited assurance as generally moderate sound system in the design or inconsistent application of controls put the achievement of the organisation's objectives at risk in the areas reviewed.
Very LIMITED " Marginally effective"Limited assurance as weaknesses in the design or inconsistent application of controls put the achievement of the organisation's objectives at risk in the areas reviewed.
NO ASSURANCENo assurance as weaknesses in control or consistent non-compliance with key controls could result (have resulted) in failure to achieve the organisation's objectives in the areas reviewed.

 

Residual Risks for individual findings

HighActive management attention required as a high priority. Controls are not adequate to address the associated risk.
MediumActive management attention required as a moderate priority. Controls are not adequate to address the associated risk.
LowActive management attention not required on priority. Controls are more or less adequate to address the associated risk.