Podcast
Questions and Answers
What is the purpose of NNPC Limited's risk appetite?
What is the purpose of NNPC Limited's risk appetite?
Which of these is not a key objective of risk management within NNPC Limited?
Which of these is not a key objective of risk management within NNPC Limited?
What is the role of ERM in NNPC Limited?
What is the role of ERM in NNPC Limited?
According to the text, which of the following is NOT a parameter considered when determining the risk appetite for NNPC Limited and its subsidiaries?
According to the text, which of the following is NOT a parameter considered when determining the risk appetite for NNPC Limited and its subsidiaries?
Signup and view all the answers
Who is responsible for developing and reviewing the risk appetite statements in consultation with the Senior Management Committee?
Who is responsible for developing and reviewing the risk appetite statements in consultation with the Senior Management Committee?
Signup and view all the answers
According to the text, when does NNPC Limited's risk appetite need to be re-evaluated?
According to the text, when does NNPC Limited's risk appetite need to be re-evaluated?
Signup and view all the answers
What are the broad corporate objectives on which NNPC Limited would base its risk appetite?
What are the broad corporate objectives on which NNPC Limited would base its risk appetite?
Signup and view all the answers
Which of the following is NOT considered when re-evaluating NNPC Limited's risk appetite?
Which of the following is NOT considered when re-evaluating NNPC Limited's risk appetite?
Signup and view all the answers
What does a strong risk culture within NNPC Limited lead to?
What does a strong risk culture within NNPC Limited lead to?
Signup and view all the answers
What is one of the key objectives of risk management within NNPC Limited?
What is one of the key objectives of risk management within NNPC Limited?
Signup and view all the answers
Which of the following is NOT a key pillar of risk management within NNPC Limited and its subsidiaries?
Which of the following is NOT a key pillar of risk management within NNPC Limited and its subsidiaries?
Signup and view all the answers
Based on the text, which of the following is NOT a component of NNPC Limited's risk governance structure?
Based on the text, which of the following is NOT a component of NNPC Limited's risk governance structure?
Signup and view all the answers
Which model does NNPC Limited's risk governance structure follow?
Which model does NNPC Limited's risk governance structure follow?
Signup and view all the answers
Who is authorized to grant exceptions to the application of NNPC Limited's risk management policy?
Who is authorized to grant exceptions to the application of NNPC Limited's risk management policy?
Signup and view all the answers
What are the four key pillars that NNPC Limited and its subsidiaries shall adhere to in terms of risk management?
What are the four key pillars that NNPC Limited and its subsidiaries shall adhere to in terms of risk management?
Signup and view all the answers
What is the role of the Governance, Risk and Compliance Function within NNPC Limited?
What is the role of the Governance, Risk and Compliance Function within NNPC Limited?
Signup and view all the answers
Who is authorized to grant exceptions to the application of NNPC Limited's risk management policy?
Who is authorized to grant exceptions to the application of NNPC Limited's risk management policy?
Signup and view all the answers
Which of the following is NOT a component of NNPC Limited's risk governance structure?
Which of the following is NOT a component of NNPC Limited's risk governance structure?
Signup and view all the answers
Who is responsible for overseeing the risk management activities at NNPC Limited and its subsidiaries?
Who is responsible for overseeing the risk management activities at NNPC Limited and its subsidiaries?
Signup and view all the answers
What is the role of the Heads of Risk Management at NNPC Limited and its subsidiaries?
What is the role of the Heads of Risk Management at NNPC Limited and its subsidiaries?
Signup and view all the answers
What is the purpose of NNPC Limited's risk reporting structure?
What is the purpose of NNPC Limited's risk reporting structure?
Signup and view all the answers
What is the role of Functional Heads in NNPC Limited's risk management activities?
What is the role of Functional Heads in NNPC Limited's risk management activities?
Signup and view all the answers
Based on the text, what is the responsibility of the ERM Function at NNPC Limited and its subsidiaries?
Based on the text, what is the responsibility of the ERM Function at NNPC Limited and its subsidiaries?
Signup and view all the answers
What is one of the key responsibilities of the Second Line of Defence in NNPC Limited's risk management?
What is one of the key responsibilities of the Second Line of Defence in NNPC Limited's risk management?
Signup and view all the answers
Who is responsible for implementing an effective risk management system and instilling the right culture throughout NNPC Limited and its subsidiaries for effective risk governance?
Who is responsible for implementing an effective risk management system and instilling the right culture throughout NNPC Limited and its subsidiaries for effective risk governance?
Signup and view all the answers
Based on the text, what is the role of the Board Audit Committee (BAC) in relation to risk management?
Based on the text, what is the role of the Board Audit Committee (BAC) in relation to risk management?
Signup and view all the answers
What is the responsibility of the Functional Heads in relation to risk management?
What is the responsibility of the Functional Heads in relation to risk management?
Signup and view all the answers
Based on the text, what is the responsibility of the Management Risk Committee in relation to risk management?
Based on the text, what is the responsibility of the Management Risk Committee in relation to risk management?
Signup and view all the answers
Which committee is responsible for reviewing the framework for managing risks and recommending it to the Board for approval?
Which committee is responsible for reviewing the framework for managing risks and recommending it to the Board for approval?
Signup and view all the answers
What is one of the responsibilities of the Management Risk Committee?
What is one of the responsibilities of the Management Risk Committee?
Signup and view all the answers
What is the role of the ERM Function at NNPC Limited and its subsidiaries?
What is the role of the ERM Function at NNPC Limited and its subsidiaries?
Signup and view all the answers
Which of the following is NOT a category used for categorizing risks in NNPC Limited's risk management process?
Which of the following is NOT a category used for categorizing risks in NNPC Limited's risk management process?
Signup and view all the answers
What is one of the activities involved in the ERM function at NNPC Limited and its subsidiaries?
What is one of the activities involved in the ERM function at NNPC Limited and its subsidiaries?
Signup and view all the answers
Which document is NOT reviewed during the ERM process at NNPC Limited?
Which document is NOT reviewed during the ERM process at NNPC Limited?
Signup and view all the answers
What is the purpose of populating the risk register and mapping risks to the relevant business process in the ERM process at NNPC Limited?
What is the purpose of populating the risk register and mapping risks to the relevant business process in the ERM process at NNPC Limited?
Signup and view all the answers
Which of the following is NOT a policy related to risk identification within NNPC Limited?
Which of the following is NOT a policy related to risk identification within NNPC Limited?
Signup and view all the answers
Who is responsible for gathering and reviewing information on project risks within NNPC Limited?
Who is responsible for gathering and reviewing information on project risks within NNPC Limited?
Signup and view all the answers
Which of the following is NOT a component of NNPC Limited's risk management process?
Which of the following is NOT a component of NNPC Limited's risk management process?
Signup and view all the answers
Who is responsible for overseeing the risk management activities at NNPC Limited's subsidiaries?
Who is responsible for overseeing the risk management activities at NNPC Limited's subsidiaries?
Signup and view all the answers
Which of the following is NOT a responsibility of the Functional Heads in relation to risk management?
Which of the following is NOT a responsibility of the Functional Heads in relation to risk management?
Signup and view all the answers
Which of the following is NOT a responsibility of the ERM Function at NNPC Limited and its subsidiaries?
Which of the following is NOT a responsibility of the ERM Function at NNPC Limited and its subsidiaries?
Signup and view all the answers
Which of the following is NOT a role of the Audit Function in NNPC Limited's risk management?
Which of the following is NOT a role of the Audit Function in NNPC Limited's risk management?
Signup and view all the answers
Which of the following is NOT a component of NNPC Limited's risk governance structure?
Which of the following is NOT a component of NNPC Limited's risk governance structure?
Signup and view all the answers
Which of the following is NOT a component of NNPC Limited's risk governance structure?
Which of the following is NOT a component of NNPC Limited's risk governance structure?
Signup and view all the answers
What is the responsibility of the Functional Heads in relation to risk management?
What is the responsibility of the Functional Heads in relation to risk management?
Signup and view all the answers
What is the role of the Governance, Risk and Compliance Function within NNPC Limited?
What is the role of the Governance, Risk and Compliance Function within NNPC Limited?
Signup and view all the answers
Which of the following is NOT a factor considered by NNPC Limited in assessing/ranking identified risks?
Which of the following is NOT a factor considered by NNPC Limited in assessing/ranking identified risks?
Signup and view all the answers
Which of the following is the highest likelihood factor for a risk to occur according to NNPC Limited's risk ranking criteria?
Which of the following is the highest likelihood factor for a risk to occur according to NNPC Limited's risk ranking criteria?
Signup and view all the answers
What is the likelihood factor for a risk to occur if it is expected to happen at least once in every 3 years according to NNPC Limited's risk ranking criteria?
What is the likelihood factor for a risk to occur if it is expected to happen at least once in every 3 years according to NNPC Limited's risk ranking criteria?
Signup and view all the answers
According to the text, which of the following is NOT a level of risk in NNPC Limited's risk map?
According to the text, which of the following is NOT a level of risk in NNPC Limited's risk map?
Signup and view all the answers
According to the text, which of the following is NOT a parameter considered when determining the financial impact of an event/risk in NNPC Limited?
According to the text, which of the following is NOT a parameter considered when determining the financial impact of an event/risk in NNPC Limited?
Signup and view all the answers
According to the text, which of the following is NOT a risk category in NNPC Limited's risk management process?
According to the text, which of the following is NOT a risk category in NNPC Limited's risk management process?
Signup and view all the answers
According to the text, which of the following is NOT a responsibility of middle level management in relation to risk management at NNPC Limited?
According to the text, which of the following is NOT a responsibility of middle level management in relation to risk management at NNPC Limited?
Signup and view all the answers
Which of the following methods is NOT mentioned as a way to assess risks within NNPC Limited's risk management process?
Which of the following methods is NOT mentioned as a way to assess risks within NNPC Limited's risk management process?
Signup and view all the answers
What is the purpose of a control assessment within NNPC Limited's risk management process?
What is the purpose of a control assessment within NNPC Limited's risk management process?
Signup and view all the answers
What is the description of a control rating of 'Fair' within NNPC Limited's risk management process?
What is the description of a control rating of 'Fair' within NNPC Limited's risk management process?
Signup and view all the answers
What is the responsibility of the ERM Function in collaboration with business and risk owners within NNPC Limited's risk management process?
What is the responsibility of the ERM Function in collaboration with business and risk owners within NNPC Limited's risk management process?
Signup and view all the answers
Which of the following is NOT a factor considered by NNPC Limited in assessing/ranking identified risks?
Which of the following is NOT a factor considered by NNPC Limited in assessing/ranking identified risks?
Signup and view all the answers
What is the highest likelihood factor for a risk to occur according to NNPC Limited's risk ranking criteria?
What is the highest likelihood factor for a risk to occur according to NNPC Limited's risk ranking criteria?
Signup and view all the answers
What is the potential non-financial consequence of an event/risk occurring if a risk were to crystallise?
What is the potential non-financial consequence of an event/risk occurring if a risk were to crystallise?
Signup and view all the answers
Which of the following is NOT a type of document reviewed during the ERM process at NNPC Limited?
Which of the following is NOT a type of document reviewed during the ERM process at NNPC Limited?
Signup and view all the answers
What is the frequency at which the risk assessment pack is inputted in the ERM process at NNPC Limited?
What is the frequency at which the risk assessment pack is inputted in the ERM process at NNPC Limited?
Signup and view all the answers
Who are the recipients of the risk heat map output in the ERM process at NNPC Limited?
Who are the recipients of the risk heat map output in the ERM process at NNPC Limited?
Signup and view all the answers
Which of the following is NOT a risk category used for categorizing risks in NNPC Limited's risk management process?
Which of the following is NOT a risk category used for categorizing risks in NNPC Limited's risk management process?
Signup and view all the answers
According to the text, which of the following is NOT a responsibility of the Management Risk Committee?
According to the text, which of the following is NOT a responsibility of the Management Risk Committee?
Signup and view all the answers
What is the highest likelihood factor for a risk to occur according to NNPC Limited's risk ranking criteria?
What is the highest likelihood factor for a risk to occur according to NNPC Limited's risk ranking criteria?
Signup and view all the answers
According to the text, what does a strong risk culture within NNPC Limited lead to?
According to the text, what does a strong risk culture within NNPC Limited lead to?
Signup and view all the answers
Which of the following methods is NOT mentioned as a way to assess risks within NNPC Limited's risk management process?
Which of the following methods is NOT mentioned as a way to assess risks within NNPC Limited's risk management process?
Signup and view all the answers
What is the frequency at which the risk assessment pack is inputted in the ERM process at NNPC Limited?
What is the frequency at which the risk assessment pack is inputted in the ERM process at NNPC Limited?
Signup and view all the answers
What is the highest likelihood factor for a risk to occur according to NNPC Limited's risk ranking criteria?
What is the highest likelihood factor for a risk to occur according to NNPC Limited's risk ranking criteria?
Signup and view all the answers
According to the text, what is the role of ERM in NNPC Limited?
According to the text, what is the role of ERM in NNPC Limited?
Signup and view all the answers
Which of the following is NOT a risk treatment approach adopted by NNPC Limited and its subsidiaries?
Which of the following is NOT a risk treatment approach adopted by NNPC Limited and its subsidiaries?
Signup and view all the answers
Under which risk treatment approach does NNPC Limited accept the risks inherent in the exposure?
Under which risk treatment approach does NNPC Limited accept the risks inherent in the exposure?
Signup and view all the answers
In which instances would NNPC Limited adopt the Tolerate risk treatment approach?
In which instances would NNPC Limited adopt the Tolerate risk treatment approach?
Signup and view all the answers
Which of the following is NOT a responsibility of the Risk Management Team at NNPC Limited?
Which of the following is NOT a responsibility of the Risk Management Team at NNPC Limited?
Signup and view all the answers
What is the purpose of the Risk Management Framework (RMF) at NNPC Limited?
What is the purpose of the Risk Management Framework (RMF) at NNPC Limited?
Signup and view all the answers
Which document is NOT an input to the ERM Function and Risk Process Owner at NNPC Limited?
Which document is NOT an input to the ERM Function and Risk Process Owner at NNPC Limited?
Signup and view all the answers
What is the highest impact level according to the risk map illustration in the text?
What is the highest impact level according to the risk map illustration in the text?
Signup and view all the answers
Which of the following is NOT a component of NNPC Limited's risk monitoring and reporting process?
Which of the following is NOT a component of NNPC Limited's risk monitoring and reporting process?
Signup and view all the answers
Which of the following is NOT a frequency at which risk monitoring and review should be performed at NNPC Limited and its subsidiaries?
Which of the following is NOT a frequency at which risk monitoring and review should be performed at NNPC Limited and its subsidiaries?
Signup and view all the answers
What is the purpose of key risk indicators (KRIs) in NNPC Limited's risk monitoring and reporting process?
What is the purpose of key risk indicators (KRIs) in NNPC Limited's risk monitoring and reporting process?
Signup and view all the answers
Which of the following is NOT a key component of NNPC Limited's risk register?
Which of the following is NOT a key component of NNPC Limited's risk register?
Signup and view all the answers
What is the purpose of the external risk review within NNPC Limited's risk management process?
What is the purpose of the external risk review within NNPC Limited's risk management process?
Signup and view all the answers
What information should be included in the risk event documentation within NNPC Limited's risk management process?
What information should be included in the risk event documentation within NNPC Limited's risk management process?
Signup and view all the answers
What is the responsibility of every support unit within NNPC Limited in relation to risk management?
What is the responsibility of every support unit within NNPC Limited in relation to risk management?
Signup and view all the answers
Which of the following is NOT included in NNPC Limited's risk management training and awareness plan?
Which of the following is NOT included in NNPC Limited's risk management training and awareness plan?
Signup and view all the answers
What is the responsibility of the Head of Risk Management at NNPC Limited?
What is the responsibility of the Head of Risk Management at NNPC Limited?
Signup and view all the answers
Which of the following is NOT covered in NNPC Limited's risk management training and awareness plan?
Which of the following is NOT covered in NNPC Limited's risk management training and awareness plan?
Signup and view all the answers
Which of the following options is NOT mentioned as a potential method for conducting risk management training at NNPC Limited and its subsidiaries?
Which of the following options is NOT mentioned as a potential method for conducting risk management training at NNPC Limited and its subsidiaries?
Signup and view all the answers
What is the purpose of the risk awareness program established by the Head of Risk Management at NNPC Limited?
What is the purpose of the risk awareness program established by the Head of Risk Management at NNPC Limited?
Signup and view all the answers
Which of the following is NOT a potential frequency for risk monitoring and review at NNPC Limited and its subsidiaries?
Which of the following is NOT a potential frequency for risk monitoring and review at NNPC Limited and its subsidiaries?
Signup and view all the answers
Which of the following is NOT mentioned as an option for risk management training and awareness at NNPC Limited?
Which of the following is NOT mentioned as an option for risk management training and awareness at NNPC Limited?
Signup and view all the answers
What is the purpose of the risk awareness program established by the Head of Risk Management at NNPC Limited?
What is the purpose of the risk awareness program established by the Head of Risk Management at NNPC Limited?
Signup and view all the answers
Which of the following is NOT a component of NNPC Limited's risk governance structure?
Which of the following is NOT a component of NNPC Limited's risk governance structure?
Signup and view all the answers
Which of the following is NOT a risk management objective mentioned in the text?
Which of the following is NOT a risk management objective mentioned in the text?
Signup and view all the answers
What is the maximum acceptable deviation from specified requirements in any given operation or project per year?
What is the maximum acceptable deviation from specified requirements in any given operation or project per year?
Signup and view all the answers
What is the maximum tolerance for financial crime and non-compliance to regulatory standards mentioned in the text?
What is the maximum tolerance for financial crime and non-compliance to regulatory standards mentioned in the text?
Signup and view all the answers
What is one of the key objectives of NNPC Limited's risk management process?
What is one of the key objectives of NNPC Limited's risk management process?
Signup and view all the answers
What is the maximum number of instances of negative media exposure that NNPC Limited will tolerate in a year?
What is the maximum number of instances of negative media exposure that NNPC Limited will tolerate in a year?
Signup and view all the answers
What is the maximum number of instances of asset destruction that NNPC Limited will tolerate in a year?
What is the maximum number of instances of asset destruction that NNPC Limited will tolerate in a year?
Signup and view all the answers
What is the maximum occupational accident frequency rate (AFR) that NNPC Limited will tolerate?
What is the maximum occupational accident frequency rate (AFR) that NNPC Limited will tolerate?
Signup and view all the answers
Which of the following risk reports is prepared and issued by the Risk Management (RM) team at NNPC Limited?
Which of the following risk reports is prepared and issued by the Risk Management (RM) team at NNPC Limited?
Signup and view all the answers
Who is the recipient of the Risk Assessment report prepared by the Risk Management (RM) team at NNPC Limited?
Who is the recipient of the Risk Assessment report prepared by the Risk Management (RM) team at NNPC Limited?
Signup and view all the answers
Which of the following risk reports is prepared and issued by the Risk Management (RM) team on a monthly basis at NNPC Limited?
Which of the following risk reports is prepared and issued by the Risk Management (RM) team on a monthly basis at NNPC Limited?
Signup and view all the answers
Which department within NNPC Limited is responsible for monitoring and reporting on the risk control self-assessment (RCSA) within their respective business units?
Which department within NNPC Limited is responsible for monitoring and reporting on the risk control self-assessment (RCSA) within their respective business units?
Signup and view all the answers
According to the text, what is the purpose of the Quality Assurance Improvement Program (QAIP) at NNPC Limited?
According to the text, what is the purpose of the Quality Assurance Improvement Program (QAIP) at NNPC Limited?
Signup and view all the answers
What is the meaning of the term 'GRC' in the context of NNPC Limited?
What is the meaning of the term 'GRC' in the context of NNPC Limited?
Signup and view all the answers
Which of the following is NOT mentioned as a key objective of the Quality Assurance and Monitoring Function at NNPC Limited?
Which of the following is NOT mentioned as a key objective of the Quality Assurance and Monitoring Function at NNPC Limited?
Signup and view all the answers
Which of the following models does the QA Function at NNPC Limited adopt for resourcing talents?
Which of the following models does the QA Function at NNPC Limited adopt for resourcing talents?
Signup and view all the answers
What is the purpose of the peer-to-peer review model in the QA Unit at NNPC Limited?
What is the purpose of the peer-to-peer review model in the QA Unit at NNPC Limited?
Signup and view all the answers
How often does the GRC Function at NNPC Limited need to conduct an external assessment?
How often does the GRC Function at NNPC Limited need to conduct an external assessment?
Signup and view all the answers
What is the role of the QA Unit in the capacity building of GRC staff at NNPC Limited?
What is the role of the QA Unit in the capacity building of GRC staff at NNPC Limited?
Signup and view all the answers
Which of the following is NOT one of the three major elements of the Quality Assurance and Improvement Program at NNPC Limited?
Which of the following is NOT one of the three major elements of the Quality Assurance and Improvement Program at NNPC Limited?
Signup and view all the answers
What is the purpose of the annual internal self-assessment conducted by the QA Unit at NNPC Limited?
What is the purpose of the annual internal self-assessment conducted by the QA Unit at NNPC Limited?
Signup and view all the answers
What does the QA Unit consider in developing the annual QA plan for ongoing internal assessments at NNPC Limited?
What does the QA Unit consider in developing the annual QA plan for ongoing internal assessments at NNPC Limited?
Signup and view all the answers
What is the basis for selecting GRC reviews for quality assurance in the QA plan at NNPC Limited?
What is the basis for selecting GRC reviews for quality assurance in the QA plan at NNPC Limited?
Signup and view all the answers
According to the text, what is the mission of the Quality Assurance (QA) unit within the GRC Function of NNPC Limited and its subsidiaries?
According to the text, what is the mission of the Quality Assurance (QA) unit within the GRC Function of NNPC Limited and its subsidiaries?
Signup and view all the answers
What is the structure of the Quality Assurance Policies and procedures?
What is the structure of the Quality Assurance Policies and procedures?
Signup and view all the answers
What is the vision of the Quality Assurance and Monitoring Function within NNPC Limited and its subsidiaries?
What is the vision of the Quality Assurance and Monitoring Function within NNPC Limited and its subsidiaries?
Signup and view all the answers
What is the scope of the QA Unit within NNPC Limited and its subsidiaries?
What is the scope of the QA Unit within NNPC Limited and its subsidiaries?
Signup and view all the answers
Which of the following is NOT a key performance indicator (KPI) for the People category in the Quality Assurance Unit's monitoring of the GRC Function at NNPC Limited?
Which of the following is NOT a key performance indicator (KPI) for the People category in the Quality Assurance Unit's monitoring of the GRC Function at NNPC Limited?
Signup and view all the answers
Which of the following is NOT a key performance indicator (KPI) for the Processes category in the Quality Assurance Unit's monitoring of the GRC Function at NNPC Limited?
Which of the following is NOT a key performance indicator (KPI) for the Processes category in the Quality Assurance Unit's monitoring of the GRC Function at NNPC Limited?
Signup and view all the answers
Which of the following is NOT a key performance indicator (KPI) for the Plan (Efficiency) category in the Quality Assurance Unit's monitoring of the GRC Function at NNPC Limited?
Which of the following is NOT a key performance indicator (KPI) for the Plan (Efficiency) category in the Quality Assurance Unit's monitoring of the GRC Function at NNPC Limited?
Signup and view all the answers
Which of the following is a key performance indicator (KPI) for the Stakeholder Management category in the Quality Assurance Unit's monitoring of the GRC Function at NNPC Limited?
Which of the following is a key performance indicator (KPI) for the Stakeholder Management category in the Quality Assurance Unit's monitoring of the GRC Function at NNPC Limited?
Signup and view all the answers
Which of the following is NOT a responsibility of the Quality Assurance Manager within NNPC Limited?
Which of the following is NOT a responsibility of the Quality Assurance Manager within NNPC Limited?
Signup and view all the answers
What is the objective of consolidating and standardizing the tasks and responsibilities within NNPC Limited's Quality Assurance function?
What is the objective of consolidating and standardizing the tasks and responsibilities within NNPC Limited's Quality Assurance function?
Signup and view all the answers
What is one of the overall responsibilities of the QA Unit within NNPC Limited?
What is one of the overall responsibilities of the QA Unit within NNPC Limited?
Signup and view all the answers
What is the responsibility of the Systems and Strategy sub-unit under QA within NNPC Limited?
What is the responsibility of the Systems and Strategy sub-unit under QA within NNPC Limited?
Signup and view all the answers
Which tool is the key tool designed to aid the quality assurance checks mentioned in the text?
Which tool is the key tool designed to aid the quality assurance checks mentioned in the text?
Signup and view all the answers
What is the purpose of the completed QA checklist mentioned in the text?
What is the purpose of the completed QA checklist mentioned in the text?
Signup and view all the answers
Who is expected to make inputs into the evaluation of all teams who conducted the various GRC engagements?
Who is expected to make inputs into the evaluation of all teams who conducted the various GRC engagements?
Signup and view all the answers
Which of the following tools is the key tool designed to aid quality assurance checks in NNPC Limited?
Which of the following tools is the key tool designed to aid quality assurance checks in NNPC Limited?
Signup and view all the answers
What should be documented in the Quality Assurance Checklist according to the text?
What should be documented in the Quality Assurance Checklist according to the text?
Signup and view all the answers
Who is expected to make inputs into the evaluation of all teams who conducted the various GRC engagements?
Who is expected to make inputs into the evaluation of all teams who conducted the various GRC engagements?
Signup and view all the answers
Which of the following is NOT a consideration during the planning stage of an investigation?
Which of the following is NOT a consideration during the planning stage of an investigation?
Signup and view all the answers
According to the text, what critical questions can a clear plan for an investigation help answer?
According to the text, what critical questions can a clear plan for an investigation help answer?
Signup and view all the answers
According to the text, why is it important for the investigation team to be flexible and prepared to address changes during the investigation?
According to the text, why is it important for the investigation team to be flexible and prepared to address changes during the investigation?
Signup and view all the answers
Which party is responsible for providing the Investigation Team with all available information regarding the case in question?
Which party is responsible for providing the Investigation Team with all available information regarding the case in question?
Signup and view all the answers
Which party is responsible for reviewing the work plan for adequacy and updating it, where applicable?
Which party is responsible for reviewing the work plan for adequacy and updating it, where applicable?
Signup and view all the answers
Which party is responsible for assigning roles and responsibilities to the Investigation team members based on knowledge and expertise?
Which party is responsible for assigning roles and responsibilities to the Investigation team members based on knowledge and expertise?
Signup and view all the answers
Which party is responsible for establishing the timeframe for completing the investigation?
Which party is responsible for establishing the timeframe for completing the investigation?
Signup and view all the answers
According to the text, what is the purpose of a work plan in an investigation?
According to the text, what is the purpose of a work plan in an investigation?
Signup and view all the answers
Who should be involved in the investigation team for a reported incident?
Who should be involved in the investigation team for a reported incident?
Signup and view all the answers
What is the recommended level of seniority for the personnel responsible for heading the investigation team?
What is the recommended level of seniority for the personnel responsible for heading the investigation team?
Signup and view all the answers
Which departments within the company may be required to provide resources for an investigation team?
Which departments within the company may be required to provide resources for an investigation team?
Signup and view all the answers
According to the text, what is the responsibility of the Chief Compliance Officer in the event of a conflict of interest involving a GRC Manager?
According to the text, what is the responsibility of the Chief Compliance Officer in the event of a conflict of interest involving a GRC Manager?
Signup and view all the answers
What is one of the reasons for appointing independent investigators in an investigation?
What is one of the reasons for appointing independent investigators in an investigation?
Signup and view all the answers
According to the text, what should be considered when selecting external investigators for an investigation?
According to the text, what should be considered when selecting external investigators for an investigation?
Signup and view all the answers
What is the responsibility of the Chief Compliance Officer or Head of Business Ethics in planning an investigation?
What is the responsibility of the Chief Compliance Officer or Head of Business Ethics in planning an investigation?
Signup and view all the answers
Which of the following is NOT a type of information that could be required for an investigation, according to the text?
Which of the following is NOT a type of information that could be required for an investigation, according to the text?
Signup and view all the answers
According to the text, investigators should be cautious when gathering information for investigations because:
According to the text, investigators should be cautious when gathering information for investigations because:
Signup and view all the answers
According to the text, investigations should be based on:
According to the text, investigations should be based on:
Signup and view all the answers
Which of the following measures should be implemented when interviewing alleged fraud perpetrators or witnesses who are employees according to the text?
Which of the following measures should be implemented when interviewing alleged fraud perpetrators or witnesses who are employees according to the text?
Signup and view all the answers
What types of parameters can be used to analyze information gathered during an investigation according to the text?
What types of parameters can be used to analyze information gathered during an investigation according to the text?
Signup and view all the answers
Which of the following is NOT a component of a risk governance structure according to the text?
Which of the following is NOT a component of a risk governance structure according to the text?
Signup and view all the answers
Which party is responsible for conducting interviews to gather information from individuals in a position to have relevant knowledge or facts on the investigation?
Which party is responsible for conducting interviews to gather information from individuals in a position to have relevant knowledge or facts on the investigation?
Signup and view all the answers
What should be captured per information received by the Investigation Team?
What should be captured per information received by the Investigation Team?
Signup and view all the answers
What should be done with original documents received by the Investigation Team?
What should be done with original documents received by the Investigation Team?
Signup and view all the answers
What should be done if there is non-availability of information or lack of cooperation from staff during the investigation?
What should be done if there is non-availability of information or lack of cooperation from staff during the investigation?
Signup and view all the answers
Which of the following is NOT a tip for conducting interviews according to the NNPC Limited Investigation Processes and Procedures?
Which of the following is NOT a tip for conducting interviews according to the NNPC Limited Investigation Processes and Procedures?
Signup and view all the answers
Which of the following is NOT a procedure for handling evidence according to the NNPC Limited Investigation Processes and Procedures?
Which of the following is NOT a procedure for handling evidence according to the NNPC Limited Investigation Processes and Procedures?
Signup and view all the answers
According to the NNPC Limited Investigation Processes and Procedures, when should forced entry into premises be made?
According to the NNPC Limited Investigation Processes and Procedures, when should forced entry into premises be made?
Signup and view all the answers
According to the NNPC Limited Investigation Processes and Procedures, what are the key aspects of surveillance procedures?
According to the NNPC Limited Investigation Processes and Procedures, what are the key aspects of surveillance procedures?
Signup and view all the answers
Which of the following practices should be adopted during investigations to safeguard the rights of employees at NNPC Limited?
Which of the following practices should be adopted during investigations to safeguard the rights of employees at NNPC Limited?
Signup and view all the answers
What should be done when interviewing alleged fraud perpetrators or witnesses who are employees at NNPC Limited?
What should be done when interviewing alleged fraud perpetrators or witnesses who are employees at NNPC Limited?
Signup and view all the answers
What types of analysis can be conducted on the gathered information during an investigation at NNPC Limited?
What types of analysis can be conducted on the gathered information during an investigation at NNPC Limited?
Signup and view all the answers
Which type of analysis involves reviewing financial information to identify anomalies and potential risk areas?
Which type of analysis involves reviewing financial information to identify anomalies and potential risk areas?
Signup and view all the answers
What is the purpose of non-financial analysis in an investigation?
What is the purpose of non-financial analysis in an investigation?
Signup and view all the answers
How can visual analysis aid investigators in identifying irregular trends and relationships?
How can visual analysis aid investigators in identifying irregular trends and relationships?
Signup and view all the answers
When should an escalation matrix be used in an investigation?
When should an escalation matrix be used in an investigation?
Signup and view all the answers
According to the text, who is responsible for providing an update on the outcome of the investigation to the party who reported the suspicious incident?
According to the text, who is responsible for providing an update on the outcome of the investigation to the party who reported the suspicious incident?
Signup and view all the answers
According to the text, who is responsible for preparing a weekly summary report of all investigations outstanding and completed in the previous week?
According to the text, who is responsible for preparing a weekly summary report of all investigations outstanding and completed in the previous week?
Signup and view all the answers
According to the text, what is the purpose of the Investigation file in NNPC Limited's Investigation Processes and Procedures?
According to the text, what is the purpose of the Investigation file in NNPC Limited's Investigation Processes and Procedures?
Signup and view all the answers
Which of the following questions should be answered in an investigation report according to the text?
Which of the following questions should be answered in an investigation report according to the text?
Signup and view all the answers
What should the Investigation Team do with information received during the course of an investigation, according to the text?
What should the Investigation Team do with information received during the course of an investigation, according to the text?
Signup and view all the answers
Who is responsible for taking disciplinary action based on the factual findings captured in the investigation report, according to the text?
Who is responsible for taking disciplinary action based on the factual findings captured in the investigation report, according to the text?
Signup and view all the answers
Which of the following is NOT a step in the reporting and recommendation process of an investigation, according to the text?
Which of the following is NOT a step in the reporting and recommendation process of an investigation, according to the text?
Signup and view all the answers
Who is responsible for reviewing the investigation report and updating recommendations on action(s) to take in response to the findings, according to the text?
Who is responsible for reviewing the investigation report and updating recommendations on action(s) to take in response to the findings, according to the text?
Signup and view all the answers
Which party is responsible for updating the investigation database with the summary of internal recipients for reviews and inputs, according to the text?
Which party is responsible for updating the investigation database with the summary of internal recipients for reviews and inputs, according to the text?
Signup and view all the answers
Which of the following is NOT a key performance indicator (KPI) for the closure of an investigation, according to the text?
Which of the following is NOT a key performance indicator (KPI) for the closure of an investigation, according to the text?
Signup and view all the answers
According to the text, who is authorized to grant exceptions to the application of the policy and seek ratification from the NNPC Limited Board?
According to the text, who is authorized to grant exceptions to the application of the policy and seek ratification from the NNPC Limited Board?
Signup and view all the answers
How often is the NNPC Limited Policy Management Processes and Procedures manual intended to be updated, unless there is a specific requirement for an immediate revision?
How often is the NNPC Limited Policy Management Processes and Procedures manual intended to be updated, unless there is a specific requirement for an immediate revision?
Signup and view all the answers
Who does the NNPC Limited Policy Management Processes and Procedures manual apply to?
Who does the NNPC Limited Policy Management Processes and Procedures manual apply to?
Signup and view all the answers
Which of the following is NOT a component of NNPC Limited's policy management processes and procedures?
Which of the following is NOT a component of NNPC Limited's policy management processes and procedures?
Signup and view all the answers
What does the SIPOC model stand for in NNPC Limited's policy management processes and procedures?
What does the SIPOC model stand for in NNPC Limited's policy management processes and procedures?
Signup and view all the answers
What is the purpose of the Relationship Map for the Efficiency Function in NNPC Limited's policy management processes and procedures?
What is the purpose of the Relationship Map for the Efficiency Function in NNPC Limited's policy management processes and procedures?
Signup and view all the answers
Which department is responsible for drafting the policy and presenting it to the Efficiency Unit and Board Committee?
Which department is responsible for drafting the policy and presenting it to the Efficiency Unit and Board Committee?
Signup and view all the answers
What is the timeframe for measuring the performance indicator 'Existence of the drivers of policy formulation'?
What is the timeframe for measuring the performance indicator 'Existence of the drivers of policy formulation'?
Signup and view all the answers
What is the basis of measurement for the performance indicator 'Use appropriate template'?
What is the basis of measurement for the performance indicator 'Use appropriate template'?
Signup and view all the answers
Which department is responsible for managing NNPC Limited's policies within the company?
Which department is responsible for managing NNPC Limited's policies within the company?
Signup and view all the answers
Who has the overall responsibility for Corporate Policies in NNPC Limited?
Who has the overall responsibility for Corporate Policies in NNPC Limited?
Signup and view all the answers
What is the objective of the policy formulation process in NNPC Limited?
What is the objective of the policy formulation process in NNPC Limited?
Signup and view all the answers
Which party is responsible for driving policy implementation within the relevant business processes, according to the text?
Which party is responsible for driving policy implementation within the relevant business processes, according to the text?
Signup and view all the answers
Who is responsible for reviewing the policy for adequacy and strategic alignment, according to the text?
Who is responsible for reviewing the policy for adequacy and strategic alignment, according to the text?
Signup and view all the answers
What is the minimum frequency at which the risk assessment pack is inputted in the ERM process at NNPC Limited, according to the text?
What is the minimum frequency at which the risk assessment pack is inputted in the ERM process at NNPC Limited, according to the text?
Signup and view all the answers
Who is responsible for preparing a presentation summarizing the policy and its benefits, according to the text?
Who is responsible for preparing a presentation summarizing the policy and its benefits, according to the text?
Signup and view all the answers
What is the responsibility of the Head of Efficiency unit in relation to policy changes in NNPC Limited?
What is the responsibility of the Head of Efficiency unit in relation to policy changes in NNPC Limited?
Signup and view all the answers
Which of the following triggers may lead to the update or renewal of NNPC Limited's policies?
Which of the following triggers may lead to the update or renewal of NNPC Limited's policies?
Signup and view all the answers
Who is responsible for approving policy changes that involve any change in or impact the implementation of Company strategy in NNPC Limited?
Who is responsible for approving policy changes that involve any change in or impact the implementation of Company strategy in NNPC Limited?
Signup and view all the answers
Which department is responsible for drafting and presenting policies to the Efficiency Unit and Board Committee?
Which department is responsible for drafting and presenting policies to the Efficiency Unit and Board Committee?
Signup and view all the answers
How often are periodic reviews of policies conducted at NNPC Limited?
How often are periodic reviews of policies conducted at NNPC Limited?
Signup and view all the answers
What is the role of the Efficiency Unit in the policy management process at NNPC Limited?
What is the role of the Efficiency Unit in the policy management process at NNPC Limited?
Signup and view all the answers
What is the responsibility of the Process Owner in the policy modification process at NNPC Limited?
What is the responsibility of the Process Owner in the policy modification process at NNPC Limited?
Signup and view all the answers
Which of the following is NOT a purpose of NNPC Limited's Business Continuity Policy?
Which of the following is NOT a purpose of NNPC Limited's Business Continuity Policy?
Signup and view all the answers
What is the purpose of NNPC Limited's Business Continuity Policy?
What is the purpose of NNPC Limited's Business Continuity Policy?
Signup and view all the answers
What is the general approach to Business Continuity Management (BCM) described in NNPC Limited's Business Continuity Policy?
What is the general approach to Business Continuity Management (BCM) described in NNPC Limited's Business Continuity Policy?
Signup and view all the answers
What is the purpose of NNPC Limited's Business Continuity (BC) Policy?
What is the purpose of NNPC Limited's Business Continuity (BC) Policy?
Signup and view all the answers
What does NNPC Limited's Business Continuity Policy aim to minimize?
What does NNPC Limited's Business Continuity Policy aim to minimize?
Signup and view all the answers
What does NNPC's general approach to Business Continuity Management (BCM) include?
What does NNPC's general approach to Business Continuity Management (BCM) include?
Signup and view all the answers
Which of the following triggers may lead to the renewal or update of NNPC Limited's policies?
Which of the following triggers may lead to the renewal or update of NNPC Limited's policies?
Signup and view all the answers
Who is responsible for reviewing and approving draft changes to the policy template at NNPC Limited?
Who is responsible for reviewing and approving draft changes to the policy template at NNPC Limited?
Signup and view all the answers
Which level of seniority is recommended for the personnel responsible for updating and renewing NNPC Limited's policies?
Which level of seniority is recommended for the personnel responsible for updating and renewing NNPC Limited's policies?
Signup and view all the answers
Which department is responsible for retiring corporate policies at NNPC Limited?
Which department is responsible for retiring corporate policies at NNPC Limited?
Signup and view all the answers
Who is responsible for evaluating proposed updates to policies at NNPC Limited?
Who is responsible for evaluating proposed updates to policies at NNPC Limited?
Signup and view all the answers
What is the role of the Board Audit Committee (BAC) in the policy retirement process at NNPC Limited?
What is the role of the Board Audit Committee (BAC) in the policy retirement process at NNPC Limited?
Signup and view all the answers
When should a policy at NNPC Limited be reviewed to ascertain if any modification is required?
When should a policy at NNPC Limited be reviewed to ascertain if any modification is required?
Signup and view all the answers
Which of the following is NOT a component of NNPC Limited's Business Continuity Policy?
Which of the following is NOT a component of NNPC Limited's Business Continuity Policy?
Signup and view all the answers
What is the purpose of NNPC Limited's Business Continuity Policy?
What is the purpose of NNPC Limited's Business Continuity Policy?
Signup and view all the answers
Which department is responsible for drafting NNPC Limited's Business Continuity Policy?
Which department is responsible for drafting NNPC Limited's Business Continuity Policy?
Signup and view all the answers
Which of the following is NOT covered by the scope of NNPC Limited's Business Continuity Policy?
Which of the following is NOT covered by the scope of NNPC Limited's Business Continuity Policy?
Signup and view all the answers
What is the purpose of Business Continuity Management at NNPC Limited?
What is the purpose of Business Continuity Management at NNPC Limited?
Signup and view all the answers
Which of the following events may have regional or nationwide impact, rendering multiple NNPC facilities inaccessible?
Which of the following events may have regional or nationwide impact, rendering multiple NNPC facilities inaccessible?
Signup and view all the answers
Which of the following is NOT a goal of NNPC Limited's Business Continuity Management (BCM) program?
Which of the following is NOT a goal of NNPC Limited's Business Continuity Management (BCM) program?
Signup and view all the answers
What is the purpose of providing awareness on business continuity to all employees and relevant external parties?
What is the purpose of providing awareness on business continuity to all employees and relevant external parties?
Signup and view all the answers
What is the responsibility of the Systems and Strategy sub-unit under Quality Assurance (QA) within NNPC Limited?
What is the responsibility of the Systems and Strategy sub-unit under Quality Assurance (QA) within NNPC Limited?
Signup and view all the answers
What is the responsibility of the Crisis Management Team (CMT) at NNPC Limited?
What is the responsibility of the Crisis Management Team (CMT) at NNPC Limited?
Signup and view all the answers
What is one of the key responsibilities of the Incident Management Team at NNPC Limited?
What is one of the key responsibilities of the Incident Management Team at NNPC Limited?
Signup and view all the answers
What is the purpose of defining and assessing key roles and responsibilities in establishing a business continuity programme?
What is the purpose of defining and assessing key roles and responsibilities in establishing a business continuity programme?
Signup and view all the answers
Which of the following is NOT a responsibility of the Business Continuity Manager at NNPC Limited?
Which of the following is NOT a responsibility of the Business Continuity Manager at NNPC Limited?
Signup and view all the answers
What is the role of the Business Continuity Champions (Emergency Response/Business Recovery Team) at NNPC Limited?
What is the role of the Business Continuity Champions (Emergency Response/Business Recovery Team) at NNPC Limited?
Signup and view all the answers
What is the responsibility of the Information Technology Team (Technical Recovery Team) at NNPC Limited?
What is the responsibility of the Information Technology Team (Technical Recovery Team) at NNPC Limited?
Signup and view all the answers
What is the responsibility of the Department Managers in relation to business continuity at NNPC Limited?
What is the responsibility of the Department Managers in relation to business continuity at NNPC Limited?
Signup and view all the answers
Which of the following is NOT a reason for updating the Business Continuity Plans?
Which of the following is NOT a reason for updating the Business Continuity Plans?
Signup and view all the answers
Who is responsible for reviewing and updating the Business Continuity Plans annually?
Who is responsible for reviewing and updating the Business Continuity Plans annually?
Signup and view all the answers
What should be done after identifying changes in business arrangements that have not yet been reflected in the Business Continuity Plan?
What should be done after identifying changes in business arrangements that have not yet been reflected in the Business Continuity Plan?
Signup and view all the answers
Which of the following is NOT a responsibility of NNPC in relation to its Business Continuity Plan?
Which of the following is NOT a responsibility of NNPC in relation to its Business Continuity Plan?
Signup and view all the answers
Who are considered key stakeholders in NNPC's Business Continuity Management (BCM) program?
Who are considered key stakeholders in NNPC's Business Continuity Management (BCM) program?
Signup and view all the answers
What is the purpose of the Business Impact Analysis (BIA) process?
What is the purpose of the Business Impact Analysis (BIA) process?
Signup and view all the answers
What is the frequency of reviewing and updating the Business Impact Analysis (BIA) and Risk Assessment (RA) processes?
What is the frequency of reviewing and updating the Business Impact Analysis (BIA) and Risk Assessment (RA) processes?
Signup and view all the answers
Which of the following is the primary objective of NNPC's Business Continuity Policy?
Which of the following is the primary objective of NNPC's Business Continuity Policy?
Signup and view all the answers
What is the purpose of the Competency and Training Requirements mentioned in the text?
What is the purpose of the Competency and Training Requirements mentioned in the text?
Signup and view all the answers
What is the purpose of the NNPC Business Continuity Policy?
What is the purpose of the NNPC Business Continuity Policy?
Signup and view all the answers
Which of the following is NOT a component of the business continuity planning process mentioned in the text?
Which of the following is NOT a component of the business continuity planning process mentioned in the text?
Signup and view all the answers
What is the purpose of testing the Business Continuity Plans (BCPs) according to the text?
What is the purpose of testing the Business Continuity Plans (BCPs) according to the text?
Signup and view all the answers
How often should the Business Continuity Plans (BCPs) be reviewed?
How often should the Business Continuity Plans (BCPs) be reviewed?
Signup and view all the answers
What is the responsibility of the owners of the appropriate business resources or processes involved in the business continuity planning process?
What is the responsibility of the owners of the appropriate business resources or processes involved in the business continuity planning process?
Signup and view all the answers
Which of the following is NOT a term/abbreviation mentioned in the glossary of terms in the text?
Which of the following is NOT a term/abbreviation mentioned in the glossary of terms in the text?
Signup and view all the answers
Which of the following is NOT a stakeholder mentioned in NNPC Limited's due diligence policy?
Which of the following is NOT a stakeholder mentioned in NNPC Limited's due diligence policy?
Signup and view all the answers
Which of the following is NOT a purpose of NNPC Limited's due diligence processes?
Which of the following is NOT a purpose of NNPC Limited's due diligence processes?
Signup and view all the answers
Who is responsible for overseeing the due diligence review process at NNPC Limited?
Who is responsible for overseeing the due diligence review process at NNPC Limited?
Signup and view all the answers
Who administers the due diligence process at NNPC Limited?
Who administers the due diligence process at NNPC Limited?
Signup and view all the answers
Who makes recommendations to approve or reject the business relationship at NNPC Limited?
Who makes recommendations to approve or reject the business relationship at NNPC Limited?
Signup and view all the answers
Who performs the initial risk categorization at NNPC Limited?
Who performs the initial risk categorization at NNPC Limited?
Signup and view all the answers
Which organization is responsible for the lift and sale of royalty oil and tax oil on behalf of the Nigerian Upstream Regulatory Commission and the Federal Inland Revenue Service?
Which organization is responsible for the lift and sale of royalty oil and tax oil on behalf of the Nigerian Upstream Regulatory Commission and the Federal Inland Revenue Service?
Signup and view all the answers
What is the purpose of the Frontier Exploration Fund?
What is the purpose of the Frontier Exploration Fund?
Signup and view all the answers
Who is responsible for carrying out test marketing to ascertain the value of crude oil?
Who is responsible for carrying out test marketing to ascertain the value of crude oil?
Signup and view all the answers
What is the role of NNPC Limited in promoting the domestic use of natural gas?
What is the role of NNPC Limited in promoting the domestic use of natural gas?
Signup and view all the answers
Which of the following is considered a Third Party in the context of NNPC Limited's Due Diligence Policy?
Which of the following is considered a Third Party in the context of NNPC Limited's Due Diligence Policy?
Signup and view all the answers
What is the objective of NNPC Limited's Due Diligence Policy?
What is the objective of NNPC Limited's Due Diligence Policy?
Signup and view all the answers
What is the definition of 'Beneficial Owner' according to NNPC Limited's Due Diligence Policy?
What is the definition of 'Beneficial Owner' according to NNPC Limited's Due Diligence Policy?
Signup and view all the answers
What does 'KYC' stand for in the context of NNPC Limited's Due Diligence Policy?
What does 'KYC' stand for in the context of NNPC Limited's Due Diligence Policy?
Signup and view all the answers
Which of the following factors is NOT considered when determining the risk rating of an employee's job role at NNPC Limited?
Which of the following factors is NOT considered when determining the risk rating of an employee's job role at NNPC Limited?
Signup and view all the answers
Which of the following is responsible for performing the initial risk categorization based on the General IDD and EDD at NNPC Limited?
Which of the following is responsible for performing the initial risk categorization based on the General IDD and EDD at NNPC Limited?
Signup and view all the answers
What are the possible risk categories at NNPC Limited?
What are the possible risk categories at NNPC Limited?
Signup and view all the answers
Which of the following is NOT a requirement for Level C due diligence according to the text?
Which of the following is NOT a requirement for Level C due diligence according to the text?
Signup and view all the answers
What is one of the factors considered when assessing the financial strength of a prospective partner according to the text?
What is one of the factors considered when assessing the financial strength of a prospective partner according to the text?
Signup and view all the answers
What type of information is NOT mentioned as potentially required for an investigation according to the text?
What type of information is NOT mentioned as potentially required for an investigation according to the text?
Signup and view all the answers
Which type of due diligence is conducted on third parties providing services classified as low risk at NNPC Limited?
Which type of due diligence is conducted on third parties providing services classified as low risk at NNPC Limited?
Signup and view all the answers
What is the risk classification that would require weighty reasons and an extensive EDD proportionate to the risk at NNPC Limited?
What is the risk classification that would require weighty reasons and an extensive EDD proportionate to the risk at NNPC Limited?
Signup and view all the answers
Which risk classification at NNPC Limited may not move forward with the proposed activity unless there exist substantial reasons for continuing with the project?
Which risk classification at NNPC Limited may not move forward with the proposed activity unless there exist substantial reasons for continuing with the project?
Signup and view all the answers
What does a high-risk counterparty at NNPC Limited being listed on a Sanctions List indicate?
What does a high-risk counterparty at NNPC Limited being listed on a Sanctions List indicate?
Signup and view all the answers
Which of the following is NOT a component of NNPC Limited's general integrity due diligence review?
Which of the following is NOT a component of NNPC Limited's general integrity due diligence review?
Signup and view all the answers
What is the purpose of the general integrity due diligence review conducted by NNPC Limited?
What is the purpose of the general integrity due diligence review conducted by NNPC Limited?
Signup and view all the answers
What is the purpose of reviewing sanctions lists as part of the general integrity due diligence review conducted by NNPC Limited?
What is the purpose of reviewing sanctions lists as part of the general integrity due diligence review conducted by NNPC Limited?
Signup and view all the answers
According to the text, what is the purpose of pre-employment screening for potential or new employees of NNPC Limited?
According to the text, what is the purpose of pre-employment screening for potential or new employees of NNPC Limited?
Signup and view all the answers
What is the basis of risk classification for existing or prospective customers of NNPC Limited?
What is the basis of risk classification for existing or prospective customers of NNPC Limited?
Signup and view all the answers
What type of due diligence must be conducted on customers identified as medium to high risk before any business transaction?
What type of due diligence must be conducted on customers identified as medium to high risk before any business transaction?
Signup and view all the answers
What should the relevant unit establish, record, maintain, and operate procedures and controls for in respect of new customers or occasional transactions?
What should the relevant unit establish, record, maintain, and operate procedures and controls for in respect of new customers or occasional transactions?
Signup and view all the answers
Which of the following statements is true about NNPC Limited's due diligence procedure for doing business with third-party service providers and suppliers?
Which of the following statements is true about NNPC Limited's due diligence procedure for doing business with third-party service providers and suppliers?
Signup and view all the answers
What is the purpose of NNPC Limited's due diligence procedure for doing business with third-party service providers and suppliers?
What is the purpose of NNPC Limited's due diligence procedure for doing business with third-party service providers and suppliers?
Signup and view all the answers
What is the minimum required due diligence procedure for doing business with certain third-party service providers and suppliers at NNPC Limited?
What is the minimum required due diligence procedure for doing business with certain third-party service providers and suppliers at NNPC Limited?
Signup and view all the answers
Which of the following is NOT a factor considered in the assessment of Politically Exposed Persons (PEPs) linked to the counterparty or the relevant NNPC Limited activity?
Which of the following is NOT a factor considered in the assessment of Politically Exposed Persons (PEPs) linked to the counterparty or the relevant NNPC Limited activity?
Signup and view all the answers
What is the purpose of conducting a contingency measures review at the outset of any business relationship?
What is the purpose of conducting a contingency measures review at the outset of any business relationship?
Signup and view all the answers
Which of the following is NOT a mitigating measure that could be applied in the event of an identified risk?
Which of the following is NOT a mitigating measure that could be applied in the event of an identified risk?
Signup and view all the answers
When is an Enhanced Due Diligence (EDD) review carried out by the GRC team or an external provider?
When is an Enhanced Due Diligence (EDD) review carried out by the GRC team or an external provider?
Signup and view all the answers
How often should recertifications be performed on vendors and third-party service providers in existing contracts at NNPC Limited?
How often should recertifications be performed on vendors and third-party service providers in existing contracts at NNPC Limited?
Signup and view all the answers
Which of the following is NOT a requirement for third parties that undertake regulated business on behalf of NNPC Limited?
Which of the following is NOT a requirement for third parties that undertake regulated business on behalf of NNPC Limited?
Signup and view all the answers
What types of processes may NNPC Limited use to perform ongoing monitoring of its counterparties?
What types of processes may NNPC Limited use to perform ongoing monitoring of its counterparties?
Signup and view all the answers
Which of the following is NOT a responsibility of the GRC Division/Chief Compliance Officer at NNPC Limited?
Which of the following is NOT a responsibility of the GRC Division/Chief Compliance Officer at NNPC Limited?
Signup and view all the answers
What is the minimum educational requirement for the GRC Manager or other relevant officers responsible for implementing the Due Diligence Policy at NNPC Limited?
What is the minimum educational requirement for the GRC Manager or other relevant officers responsible for implementing the Due Diligence Policy at NNPC Limited?
Signup and view all the answers
How long should the findings of the Risk monitoring be archived for future reference?
How long should the findings of the Risk monitoring be archived for future reference?
Signup and view all the answers
Who is responsible for reviewing the Due Diligence Policy at NNPC Limited every two (2) years and submitting recommendations to the Board of Directors for any necessary amendments or revisions?
Who is responsible for reviewing the Due Diligence Policy at NNPC Limited every two (2) years and submitting recommendations to the Board of Directors for any necessary amendments or revisions?
Signup and view all the answers
Study Notes
Risk Appetite and Objectives
- NNPC Limited's risk appetite is the amount of risk the organization is willing to accept to achieve its objectives.
- The key objective of risk management is to identify, assess, and mitigate risks that could impact the achievement of NNPC Limited's objectives.
- The broad corporate objectives on which NNPC Limited's risk appetite is based include strategic, financial, operational, and compliance objectives.
Risk Management Framework
- The Enterprise Risk Management (ERM) function is responsible for developing and implementing the risk management framework.
- The risk management framework is based on the three lines of defense model.
- The Governance, Risk and Compliance Function is responsible for overseeing the risk management activities at NNPC Limited and its subsidiaries.
Risk Governance Structure
- The risk governance structure consists of the Board of Directors, Management Risk Committee, Heads of Risk Management, and Functional Heads.
- The Board of Directors is responsible for reviewing and approving the risk management framework.
- The Management Risk Committee is responsible for reviewing the risk management framework and recommending it to the Board for approval.
Risk Management Process
- The risk management process involves identifying, assessing, and mitigating risks.
- The risk assessment process involves identifying and assessing risks, and prioritizing them based on their likelihood and impact.
- The risk treatment process involves selecting and implementing risk mitigation strategies.
Risk Monitoring and Reporting
- The risk monitoring and reporting process involves tracking and reporting on risk mitigation efforts.
- Key risk indicators (KRIs) are used to monitor and report on risks.
- The risk management framework is reviewed and updated annually.
Risk Management Training and Awareness
- The risk management training and awareness plan is designed to educate employees on risk management principles and practices.
- The plan includes training programs, workshops, and awareness campaigns.
- The risk awareness program is designed to promote a risk-aware culture within the organization.
Risk Management Roles and Responsibilities
- The Head of Risk Management is responsible for developing and implementing the risk management framework.
- The Heads of Risk Management at NNPC Limited and its subsidiaries are responsible for overseeing risk management activities.
- Functional Heads are responsible for implementing risk management practices within their respective departments.
- The ERM Function is responsible for developing and implementing the risk management framework.
- The Management Risk Committee is responsible for reviewing and approving the risk management framework.
Risk Management Policy
- The risk management policy outlines the organization's approach to risk management.
- The policy is reviewed and updated annually.
- The policy is approved by the Board of Directors.
Risk Management Exceptions
- The Board of Directors is authorized to grant exceptions to the application of the risk management policy.
- Exceptions are granted on a case-by-case basis.
Risk Management Categories
- Risks are categorized based on their likelihood and impact.
- The categories include high, medium, and low risks.
- Risks are prioritized based on their likelihood and impact.
Risk Management Parameters
- The risk management framework considers several parameters, including the organization's risk appetite, risk tolerance, and risk threshold.
- The parameters are used to determine the acceptable level of risk for the organization.
Risk Management Frequency
- Risk management activities are performed at various frequencies, including quarterly, bi-annually, and annually.
- The frequency of risk management activities depends on the organization's risk appetite and risk tolerance.
Risk Management Tools
- Several tools are used in the risk management process, including risk assessment templates, risk registers, and key risk indicators.
- The tools are used to identify, assess, and mitigate risks.
Risk Management Review
- The risk management framework is reviewed annually.
- The review is performed by the Management Risk Committee.
- The review is used to update the risk management framework and ensure it remains effective.
Studying That Suits You
Use AI to generate personalized quizzes and flashcards to suit your learning preferences.
Related Documents
Description
Test your knowledge on NNPC Limited's GRC processes and procedures! This quiz will cover the risk strategy and appetite, as well as the importance of establishing a proactive and effective risk model. Put your skills to the test and see how well you understand the coordination and management of risks within NNPC Limited.