Podcast
Questions and Answers
What is the purpose of NNPC Limited's risk appetite?
What is the purpose of NNPC Limited's risk appetite?
- To guide the determination of risk appetite
- To establish a proactive ERM model
- To reduce operational surprises and losses
- To determine how much risk is acceptable (correct)
Which of these is not a key objective of risk management within NNPC Limited?
Which of these is not a key objective of risk management within NNPC Limited?
- To integrate risk management into the decision-making process
- To develop a risk culture
- To eliminate risk in NNPC activities (correct)
- To improve stakeholders' confidence and trust
What is the role of ERM in NNPC Limited?
What is the role of ERM in NNPC Limited?
- To reduce operational surprises and losses
- To develop and implement effective strategies
- To be an integral part of strategic and operational planning (correct)
- To integrate risk management into the decision-making process
According to the text, which of the following is NOT a parameter considered when determining the risk appetite for NNPC Limited and its subsidiaries?
According to the text, which of the following is NOT a parameter considered when determining the risk appetite for NNPC Limited and its subsidiaries?
Who is responsible for developing and reviewing the risk appetite statements in consultation with the Senior Management Committee?
Who is responsible for developing and reviewing the risk appetite statements in consultation with the Senior Management Committee?
According to the text, when does NNPC Limited's risk appetite need to be re-evaluated?
According to the text, when does NNPC Limited's risk appetite need to be re-evaluated?
What are the broad corporate objectives on which NNPC Limited would base its risk appetite?
What are the broad corporate objectives on which NNPC Limited would base its risk appetite?
Which of the following is NOT considered when re-evaluating NNPC Limited's risk appetite?
Which of the following is NOT considered when re-evaluating NNPC Limited's risk appetite?
What does a strong risk culture within NNPC Limited lead to?
What does a strong risk culture within NNPC Limited lead to?
What is one of the key objectives of risk management within NNPC Limited?
What is one of the key objectives of risk management within NNPC Limited?
Which of the following is NOT a key pillar of risk management within NNPC Limited and its subsidiaries?
Which of the following is NOT a key pillar of risk management within NNPC Limited and its subsidiaries?
Based on the text, which of the following is NOT a component of NNPC Limited's risk governance structure?
Based on the text, which of the following is NOT a component of NNPC Limited's risk governance structure?
Which model does NNPC Limited's risk governance structure follow?
Which model does NNPC Limited's risk governance structure follow?
Who is authorized to grant exceptions to the application of NNPC Limited's risk management policy?
Who is authorized to grant exceptions to the application of NNPC Limited's risk management policy?
What are the four key pillars that NNPC Limited and its subsidiaries shall adhere to in terms of risk management?
What are the four key pillars that NNPC Limited and its subsidiaries shall adhere to in terms of risk management?
What is the role of the Governance, Risk and Compliance Function within NNPC Limited?
What is the role of the Governance, Risk and Compliance Function within NNPC Limited?
Who is authorized to grant exceptions to the application of NNPC Limited's risk management policy?
Who is authorized to grant exceptions to the application of NNPC Limited's risk management policy?
Which of the following is NOT a component of NNPC Limited's risk governance structure?
Which of the following is NOT a component of NNPC Limited's risk governance structure?
Who is responsible for overseeing the risk management activities at NNPC Limited and its subsidiaries?
Who is responsible for overseeing the risk management activities at NNPC Limited and its subsidiaries?
What is the role of the Heads of Risk Management at NNPC Limited and its subsidiaries?
What is the role of the Heads of Risk Management at NNPC Limited and its subsidiaries?
What is the purpose of NNPC Limited's risk reporting structure?
What is the purpose of NNPC Limited's risk reporting structure?
What is the role of Functional Heads in NNPC Limited's risk management activities?
What is the role of Functional Heads in NNPC Limited's risk management activities?
Based on the text, what is the responsibility of the ERM Function at NNPC Limited and its subsidiaries?
Based on the text, what is the responsibility of the ERM Function at NNPC Limited and its subsidiaries?
What is one of the key responsibilities of the Second Line of Defence in NNPC Limited's risk management?
What is one of the key responsibilities of the Second Line of Defence in NNPC Limited's risk management?
Who is responsible for implementing an effective risk management system and instilling the right culture throughout NNPC Limited and its subsidiaries for effective risk governance?
Who is responsible for implementing an effective risk management system and instilling the right culture throughout NNPC Limited and its subsidiaries for effective risk governance?
Based on the text, what is the role of the Board Audit Committee (BAC) in relation to risk management?
Based on the text, what is the role of the Board Audit Committee (BAC) in relation to risk management?
What is the responsibility of the Functional Heads in relation to risk management?
What is the responsibility of the Functional Heads in relation to risk management?
Based on the text, what is the responsibility of the Management Risk Committee in relation to risk management?
Based on the text, what is the responsibility of the Management Risk Committee in relation to risk management?
Which committee is responsible for reviewing the framework for managing risks and recommending it to the Board for approval?
Which committee is responsible for reviewing the framework for managing risks and recommending it to the Board for approval?
What is one of the responsibilities of the Management Risk Committee?
What is one of the responsibilities of the Management Risk Committee?
What is the role of the ERM Function at NNPC Limited and its subsidiaries?
What is the role of the ERM Function at NNPC Limited and its subsidiaries?
Which of the following is NOT a category used for categorizing risks in NNPC Limited's risk management process?
Which of the following is NOT a category used for categorizing risks in NNPC Limited's risk management process?
What is one of the activities involved in the ERM function at NNPC Limited and its subsidiaries?
What is one of the activities involved in the ERM function at NNPC Limited and its subsidiaries?
Which document is NOT reviewed during the ERM process at NNPC Limited?
Which document is NOT reviewed during the ERM process at NNPC Limited?
What is the purpose of populating the risk register and mapping risks to the relevant business process in the ERM process at NNPC Limited?
What is the purpose of populating the risk register and mapping risks to the relevant business process in the ERM process at NNPC Limited?
Which of the following is NOT a policy related to risk identification within NNPC Limited?
Which of the following is NOT a policy related to risk identification within NNPC Limited?
Who is responsible for gathering and reviewing information on project risks within NNPC Limited?
Who is responsible for gathering and reviewing information on project risks within NNPC Limited?
Which of the following is NOT a component of NNPC Limited's risk management process?
Which of the following is NOT a component of NNPC Limited's risk management process?
Who is responsible for overseeing the risk management activities at NNPC Limited's subsidiaries?
Who is responsible for overseeing the risk management activities at NNPC Limited's subsidiaries?
Which of the following is NOT a responsibility of the Functional Heads in relation to risk management?
Which of the following is NOT a responsibility of the Functional Heads in relation to risk management?
Which of the following is NOT a responsibility of the ERM Function at NNPC Limited and its subsidiaries?
Which of the following is NOT a responsibility of the ERM Function at NNPC Limited and its subsidiaries?
Which of the following is NOT a role of the Audit Function in NNPC Limited's risk management?
Which of the following is NOT a role of the Audit Function in NNPC Limited's risk management?
Which of the following is NOT a component of NNPC Limited's risk governance structure?
Which of the following is NOT a component of NNPC Limited's risk governance structure?
Which of the following is NOT a component of NNPC Limited's risk governance structure?
Which of the following is NOT a component of NNPC Limited's risk governance structure?
What is the responsibility of the Functional Heads in relation to risk management?
What is the responsibility of the Functional Heads in relation to risk management?
What is the role of the Governance, Risk and Compliance Function within NNPC Limited?
What is the role of the Governance, Risk and Compliance Function within NNPC Limited?
Which of the following is NOT a factor considered by NNPC Limited in assessing/ranking identified risks?
Which of the following is NOT a factor considered by NNPC Limited in assessing/ranking identified risks?
Which of the following is the highest likelihood factor for a risk to occur according to NNPC Limited's risk ranking criteria?
Which of the following is the highest likelihood factor for a risk to occur according to NNPC Limited's risk ranking criteria?
What is the likelihood factor for a risk to occur if it is expected to happen at least once in every 3 years according to NNPC Limited's risk ranking criteria?
What is the likelihood factor for a risk to occur if it is expected to happen at least once in every 3 years according to NNPC Limited's risk ranking criteria?
According to the text, which of the following is NOT a level of risk in NNPC Limited's risk map?
According to the text, which of the following is NOT a level of risk in NNPC Limited's risk map?
According to the text, which of the following is NOT a parameter considered when determining the financial impact of an event/risk in NNPC Limited?
According to the text, which of the following is NOT a parameter considered when determining the financial impact of an event/risk in NNPC Limited?
According to the text, which of the following is NOT a risk category in NNPC Limited's risk management process?
According to the text, which of the following is NOT a risk category in NNPC Limited's risk management process?
According to the text, which of the following is NOT a responsibility of middle level management in relation to risk management at NNPC Limited?
According to the text, which of the following is NOT a responsibility of middle level management in relation to risk management at NNPC Limited?
Which of the following methods is NOT mentioned as a way to assess risks within NNPC Limited's risk management process?
Which of the following methods is NOT mentioned as a way to assess risks within NNPC Limited's risk management process?
What is the purpose of a control assessment within NNPC Limited's risk management process?
What is the purpose of a control assessment within NNPC Limited's risk management process?
What is the description of a control rating of 'Fair' within NNPC Limited's risk management process?
What is the description of a control rating of 'Fair' within NNPC Limited's risk management process?
What is the responsibility of the ERM Function in collaboration with business and risk owners within NNPC Limited's risk management process?
What is the responsibility of the ERM Function in collaboration with business and risk owners within NNPC Limited's risk management process?
Which of the following is NOT a factor considered by NNPC Limited in assessing/ranking identified risks?
Which of the following is NOT a factor considered by NNPC Limited in assessing/ranking identified risks?
What is the highest likelihood factor for a risk to occur according to NNPC Limited's risk ranking criteria?
What is the highest likelihood factor for a risk to occur according to NNPC Limited's risk ranking criteria?
What is the potential non-financial consequence of an event/risk occurring if a risk were to crystallise?
What is the potential non-financial consequence of an event/risk occurring if a risk were to crystallise?
Which of the following is NOT a type of document reviewed during the ERM process at NNPC Limited?
Which of the following is NOT a type of document reviewed during the ERM process at NNPC Limited?
What is the frequency at which the risk assessment pack is inputted in the ERM process at NNPC Limited?
What is the frequency at which the risk assessment pack is inputted in the ERM process at NNPC Limited?
Who are the recipients of the risk heat map output in the ERM process at NNPC Limited?
Who are the recipients of the risk heat map output in the ERM process at NNPC Limited?
Which of the following is NOT a risk category used for categorizing risks in NNPC Limited's risk management process?
Which of the following is NOT a risk category used for categorizing risks in NNPC Limited's risk management process?
According to the text, which of the following is NOT a responsibility of the Management Risk Committee?
According to the text, which of the following is NOT a responsibility of the Management Risk Committee?
What is the highest likelihood factor for a risk to occur according to NNPC Limited's risk ranking criteria?
What is the highest likelihood factor for a risk to occur according to NNPC Limited's risk ranking criteria?
According to the text, what does a strong risk culture within NNPC Limited lead to?
According to the text, what does a strong risk culture within NNPC Limited lead to?
Which of the following methods is NOT mentioned as a way to assess risks within NNPC Limited's risk management process?
Which of the following methods is NOT mentioned as a way to assess risks within NNPC Limited's risk management process?
What is the frequency at which the risk assessment pack is inputted in the ERM process at NNPC Limited?
What is the frequency at which the risk assessment pack is inputted in the ERM process at NNPC Limited?
What is the highest likelihood factor for a risk to occur according to NNPC Limited's risk ranking criteria?
What is the highest likelihood factor for a risk to occur according to NNPC Limited's risk ranking criteria?
According to the text, what is the role of ERM in NNPC Limited?
According to the text, what is the role of ERM in NNPC Limited?
Which of the following is NOT a risk treatment approach adopted by NNPC Limited and its subsidiaries?
Which of the following is NOT a risk treatment approach adopted by NNPC Limited and its subsidiaries?
Under which risk treatment approach does NNPC Limited accept the risks inherent in the exposure?
Under which risk treatment approach does NNPC Limited accept the risks inherent in the exposure?
In which instances would NNPC Limited adopt the Tolerate risk treatment approach?
In which instances would NNPC Limited adopt the Tolerate risk treatment approach?
Which of the following is NOT a responsibility of the Risk Management Team at NNPC Limited?
Which of the following is NOT a responsibility of the Risk Management Team at NNPC Limited?
What is the purpose of the Risk Management Framework (RMF) at NNPC Limited?
What is the purpose of the Risk Management Framework (RMF) at NNPC Limited?
Which document is NOT an input to the ERM Function and Risk Process Owner at NNPC Limited?
Which document is NOT an input to the ERM Function and Risk Process Owner at NNPC Limited?
What is the highest impact level according to the risk map illustration in the text?
What is the highest impact level according to the risk map illustration in the text?
Which of the following is NOT a component of NNPC Limited's risk monitoring and reporting process?
Which of the following is NOT a component of NNPC Limited's risk monitoring and reporting process?
Which of the following is NOT a frequency at which risk monitoring and review should be performed at NNPC Limited and its subsidiaries?
Which of the following is NOT a frequency at which risk monitoring and review should be performed at NNPC Limited and its subsidiaries?
What is the purpose of key risk indicators (KRIs) in NNPC Limited's risk monitoring and reporting process?
What is the purpose of key risk indicators (KRIs) in NNPC Limited's risk monitoring and reporting process?
Which of the following is NOT a key component of NNPC Limited's risk register?
Which of the following is NOT a key component of NNPC Limited's risk register?
What is the purpose of the external risk review within NNPC Limited's risk management process?
What is the purpose of the external risk review within NNPC Limited's risk management process?
What information should be included in the risk event documentation within NNPC Limited's risk management process?
What information should be included in the risk event documentation within NNPC Limited's risk management process?
What is the responsibility of every support unit within NNPC Limited in relation to risk management?
What is the responsibility of every support unit within NNPC Limited in relation to risk management?
Which of the following is NOT included in NNPC Limited's risk management training and awareness plan?
Which of the following is NOT included in NNPC Limited's risk management training and awareness plan?
What is the responsibility of the Head of Risk Management at NNPC Limited?
What is the responsibility of the Head of Risk Management at NNPC Limited?
Which of the following is NOT covered in NNPC Limited's risk management training and awareness plan?
Which of the following is NOT covered in NNPC Limited's risk management training and awareness plan?
Which of the following options is NOT mentioned as a potential method for conducting risk management training at NNPC Limited and its subsidiaries?
Which of the following options is NOT mentioned as a potential method for conducting risk management training at NNPC Limited and its subsidiaries?
What is the purpose of the risk awareness program established by the Head of Risk Management at NNPC Limited?
What is the purpose of the risk awareness program established by the Head of Risk Management at NNPC Limited?
Which of the following is NOT a potential frequency for risk monitoring and review at NNPC Limited and its subsidiaries?
Which of the following is NOT a potential frequency for risk monitoring and review at NNPC Limited and its subsidiaries?
Which of the following is NOT mentioned as an option for risk management training and awareness at NNPC Limited?
Which of the following is NOT mentioned as an option for risk management training and awareness at NNPC Limited?
What is the purpose of the risk awareness program established by the Head of Risk Management at NNPC Limited?
What is the purpose of the risk awareness program established by the Head of Risk Management at NNPC Limited?
Which of the following is NOT a component of NNPC Limited's risk governance structure?
Which of the following is NOT a component of NNPC Limited's risk governance structure?
Which of the following is NOT a risk management objective mentioned in the text?
Which of the following is NOT a risk management objective mentioned in the text?
What is the maximum acceptable deviation from specified requirements in any given operation or project per year?
What is the maximum acceptable deviation from specified requirements in any given operation or project per year?
What is the maximum tolerance for financial crime and non-compliance to regulatory standards mentioned in the text?
What is the maximum tolerance for financial crime and non-compliance to regulatory standards mentioned in the text?
What is one of the key objectives of NNPC Limited's risk management process?
What is one of the key objectives of NNPC Limited's risk management process?
What is the maximum number of instances of negative media exposure that NNPC Limited will tolerate in a year?
What is the maximum number of instances of negative media exposure that NNPC Limited will tolerate in a year?
What is the maximum number of instances of asset destruction that NNPC Limited will tolerate in a year?
What is the maximum number of instances of asset destruction that NNPC Limited will tolerate in a year?
What is the maximum occupational accident frequency rate (AFR) that NNPC Limited will tolerate?
What is the maximum occupational accident frequency rate (AFR) that NNPC Limited will tolerate?
Which of the following risk reports is prepared and issued by the Risk Management (RM) team at NNPC Limited?
Which of the following risk reports is prepared and issued by the Risk Management (RM) team at NNPC Limited?
Who is the recipient of the Risk Assessment report prepared by the Risk Management (RM) team at NNPC Limited?
Who is the recipient of the Risk Assessment report prepared by the Risk Management (RM) team at NNPC Limited?
Which of the following risk reports is prepared and issued by the Risk Management (RM) team on a monthly basis at NNPC Limited?
Which of the following risk reports is prepared and issued by the Risk Management (RM) team on a monthly basis at NNPC Limited?
Which department within NNPC Limited is responsible for monitoring and reporting on the risk control self-assessment (RCSA) within their respective business units?
Which department within NNPC Limited is responsible for monitoring and reporting on the risk control self-assessment (RCSA) within their respective business units?
According to the text, what is the purpose of the Quality Assurance Improvement Program (QAIP) at NNPC Limited?
According to the text, what is the purpose of the Quality Assurance Improvement Program (QAIP) at NNPC Limited?
What is the meaning of the term 'GRC' in the context of NNPC Limited?
What is the meaning of the term 'GRC' in the context of NNPC Limited?
Which of the following is NOT mentioned as a key objective of the Quality Assurance and Monitoring Function at NNPC Limited?
Which of the following is NOT mentioned as a key objective of the Quality Assurance and Monitoring Function at NNPC Limited?
Which of the following models does the QA Function at NNPC Limited adopt for resourcing talents?
Which of the following models does the QA Function at NNPC Limited adopt for resourcing talents?
What is the purpose of the peer-to-peer review model in the QA Unit at NNPC Limited?
What is the purpose of the peer-to-peer review model in the QA Unit at NNPC Limited?
How often does the GRC Function at NNPC Limited need to conduct an external assessment?
How often does the GRC Function at NNPC Limited need to conduct an external assessment?
What is the role of the QA Unit in the capacity building of GRC staff at NNPC Limited?
What is the role of the QA Unit in the capacity building of GRC staff at NNPC Limited?
Which of the following is NOT one of the three major elements of the Quality Assurance and Improvement Program at NNPC Limited?
Which of the following is NOT one of the three major elements of the Quality Assurance and Improvement Program at NNPC Limited?
What is the purpose of the annual internal self-assessment conducted by the QA Unit at NNPC Limited?
What is the purpose of the annual internal self-assessment conducted by the QA Unit at NNPC Limited?
What does the QA Unit consider in developing the annual QA plan for ongoing internal assessments at NNPC Limited?
What does the QA Unit consider in developing the annual QA plan for ongoing internal assessments at NNPC Limited?
What is the basis for selecting GRC reviews for quality assurance in the QA plan at NNPC Limited?
What is the basis for selecting GRC reviews for quality assurance in the QA plan at NNPC Limited?
According to the text, what is the mission of the Quality Assurance (QA) unit within the GRC Function of NNPC Limited and its subsidiaries?
According to the text, what is the mission of the Quality Assurance (QA) unit within the GRC Function of NNPC Limited and its subsidiaries?
What is the structure of the Quality Assurance Policies and procedures?
What is the structure of the Quality Assurance Policies and procedures?
What is the vision of the Quality Assurance and Monitoring Function within NNPC Limited and its subsidiaries?
What is the vision of the Quality Assurance and Monitoring Function within NNPC Limited and its subsidiaries?
What is the scope of the QA Unit within NNPC Limited and its subsidiaries?
What is the scope of the QA Unit within NNPC Limited and its subsidiaries?
Which of the following is NOT a key performance indicator (KPI) for the People category in the Quality Assurance Unit's monitoring of the GRC Function at NNPC Limited?
Which of the following is NOT a key performance indicator (KPI) for the People category in the Quality Assurance Unit's monitoring of the GRC Function at NNPC Limited?
Which of the following is NOT a key performance indicator (KPI) for the Processes category in the Quality Assurance Unit's monitoring of the GRC Function at NNPC Limited?
Which of the following is NOT a key performance indicator (KPI) for the Processes category in the Quality Assurance Unit's monitoring of the GRC Function at NNPC Limited?
Which of the following is NOT a key performance indicator (KPI) for the Plan (Efficiency) category in the Quality Assurance Unit's monitoring of the GRC Function at NNPC Limited?
Which of the following is NOT a key performance indicator (KPI) for the Plan (Efficiency) category in the Quality Assurance Unit's monitoring of the GRC Function at NNPC Limited?
Which of the following is a key performance indicator (KPI) for the Stakeholder Management category in the Quality Assurance Unit's monitoring of the GRC Function at NNPC Limited?
Which of the following is a key performance indicator (KPI) for the Stakeholder Management category in the Quality Assurance Unit's monitoring of the GRC Function at NNPC Limited?
Which of the following is NOT a responsibility of the Quality Assurance Manager within NNPC Limited?
Which of the following is NOT a responsibility of the Quality Assurance Manager within NNPC Limited?
What is the objective of consolidating and standardizing the tasks and responsibilities within NNPC Limited's Quality Assurance function?
What is the objective of consolidating and standardizing the tasks and responsibilities within NNPC Limited's Quality Assurance function?
What is one of the overall responsibilities of the QA Unit within NNPC Limited?
What is one of the overall responsibilities of the QA Unit within NNPC Limited?
What is the responsibility of the Systems and Strategy sub-unit under QA within NNPC Limited?
What is the responsibility of the Systems and Strategy sub-unit under QA within NNPC Limited?
Which tool is the key tool designed to aid the quality assurance checks mentioned in the text?
Which tool is the key tool designed to aid the quality assurance checks mentioned in the text?
What is the purpose of the completed QA checklist mentioned in the text?
What is the purpose of the completed QA checklist mentioned in the text?
Who is expected to make inputs into the evaluation of all teams who conducted the various GRC engagements?
Who is expected to make inputs into the evaluation of all teams who conducted the various GRC engagements?
Which of the following tools is the key tool designed to aid quality assurance checks in NNPC Limited?
Which of the following tools is the key tool designed to aid quality assurance checks in NNPC Limited?
What should be documented in the Quality Assurance Checklist according to the text?
What should be documented in the Quality Assurance Checklist according to the text?
Who is expected to make inputs into the evaluation of all teams who conducted the various GRC engagements?
Who is expected to make inputs into the evaluation of all teams who conducted the various GRC engagements?
Which of the following is NOT a consideration during the planning stage of an investigation?
Which of the following is NOT a consideration during the planning stage of an investigation?
According to the text, what critical questions can a clear plan for an investigation help answer?
According to the text, what critical questions can a clear plan for an investigation help answer?
According to the text, why is it important for the investigation team to be flexible and prepared to address changes during the investigation?
According to the text, why is it important for the investigation team to be flexible and prepared to address changes during the investigation?
Which party is responsible for providing the Investigation Team with all available information regarding the case in question?
Which party is responsible for providing the Investigation Team with all available information regarding the case in question?
Which party is responsible for reviewing the work plan for adequacy and updating it, where applicable?
Which party is responsible for reviewing the work plan for adequacy and updating it, where applicable?
Which party is responsible for assigning roles and responsibilities to the Investigation team members based on knowledge and expertise?
Which party is responsible for assigning roles and responsibilities to the Investigation team members based on knowledge and expertise?
Which party is responsible for establishing the timeframe for completing the investigation?
Which party is responsible for establishing the timeframe for completing the investigation?
According to the text, what is the purpose of a work plan in an investigation?
According to the text, what is the purpose of a work plan in an investigation?
Who should be involved in the investigation team for a reported incident?
Who should be involved in the investigation team for a reported incident?
What is the recommended level of seniority for the personnel responsible for heading the investigation team?
What is the recommended level of seniority for the personnel responsible for heading the investigation team?
Which departments within the company may be required to provide resources for an investigation team?
Which departments within the company may be required to provide resources for an investigation team?
According to the text, what is the responsibility of the Chief Compliance Officer in the event of a conflict of interest involving a GRC Manager?
According to the text, what is the responsibility of the Chief Compliance Officer in the event of a conflict of interest involving a GRC Manager?
What is one of the reasons for appointing independent investigators in an investigation?
What is one of the reasons for appointing independent investigators in an investigation?
According to the text, what should be considered when selecting external investigators for an investigation?
According to the text, what should be considered when selecting external investigators for an investigation?
What is the responsibility of the Chief Compliance Officer or Head of Business Ethics in planning an investigation?
What is the responsibility of the Chief Compliance Officer or Head of Business Ethics in planning an investigation?
Which of the following is NOT a type of information that could be required for an investigation, according to the text?
Which of the following is NOT a type of information that could be required for an investigation, according to the text?
According to the text, investigators should be cautious when gathering information for investigations because:
According to the text, investigators should be cautious when gathering information for investigations because:
According to the text, investigations should be based on:
According to the text, investigations should be based on:
Which of the following measures should be implemented when interviewing alleged fraud perpetrators or witnesses who are employees according to the text?
Which of the following measures should be implemented when interviewing alleged fraud perpetrators or witnesses who are employees according to the text?
What types of parameters can be used to analyze information gathered during an investigation according to the text?
What types of parameters can be used to analyze information gathered during an investigation according to the text?
Which of the following is NOT a component of a risk governance structure according to the text?
Which of the following is NOT a component of a risk governance structure according to the text?
Which party is responsible for conducting interviews to gather information from individuals in a position to have relevant knowledge or facts on the investigation?
Which party is responsible for conducting interviews to gather information from individuals in a position to have relevant knowledge or facts on the investigation?
What should be captured per information received by the Investigation Team?
What should be captured per information received by the Investigation Team?
What should be done with original documents received by the Investigation Team?
What should be done with original documents received by the Investigation Team?
What should be done if there is non-availability of information or lack of cooperation from staff during the investigation?
What should be done if there is non-availability of information or lack of cooperation from staff during the investigation?
Which of the following is NOT a tip for conducting interviews according to the NNPC Limited Investigation Processes and Procedures?
Which of the following is NOT a tip for conducting interviews according to the NNPC Limited Investigation Processes and Procedures?
Which of the following is NOT a procedure for handling evidence according to the NNPC Limited Investigation Processes and Procedures?
Which of the following is NOT a procedure for handling evidence according to the NNPC Limited Investigation Processes and Procedures?
According to the NNPC Limited Investigation Processes and Procedures, when should forced entry into premises be made?
According to the NNPC Limited Investigation Processes and Procedures, when should forced entry into premises be made?
According to the NNPC Limited Investigation Processes and Procedures, what are the key aspects of surveillance procedures?
According to the NNPC Limited Investigation Processes and Procedures, what are the key aspects of surveillance procedures?
Which of the following practices should be adopted during investigations to safeguard the rights of employees at NNPC Limited?
Which of the following practices should be adopted during investigations to safeguard the rights of employees at NNPC Limited?
What should be done when interviewing alleged fraud perpetrators or witnesses who are employees at NNPC Limited?
What should be done when interviewing alleged fraud perpetrators or witnesses who are employees at NNPC Limited?
What types of analysis can be conducted on the gathered information during an investigation at NNPC Limited?
What types of analysis can be conducted on the gathered information during an investigation at NNPC Limited?
Which type of analysis involves reviewing financial information to identify anomalies and potential risk areas?
Which type of analysis involves reviewing financial information to identify anomalies and potential risk areas?
What is the purpose of non-financial analysis in an investigation?
What is the purpose of non-financial analysis in an investigation?
How can visual analysis aid investigators in identifying irregular trends and relationships?
How can visual analysis aid investigators in identifying irregular trends and relationships?
When should an escalation matrix be used in an investigation?
When should an escalation matrix be used in an investigation?
According to the text, who is responsible for providing an update on the outcome of the investigation to the party who reported the suspicious incident?
According to the text, who is responsible for providing an update on the outcome of the investigation to the party who reported the suspicious incident?
According to the text, who is responsible for preparing a weekly summary report of all investigations outstanding and completed in the previous week?
According to the text, who is responsible for preparing a weekly summary report of all investigations outstanding and completed in the previous week?
According to the text, what is the purpose of the Investigation file in NNPC Limited's Investigation Processes and Procedures?
According to the text, what is the purpose of the Investigation file in NNPC Limited's Investigation Processes and Procedures?
Which of the following questions should be answered in an investigation report according to the text?
Which of the following questions should be answered in an investigation report according to the text?
What should the Investigation Team do with information received during the course of an investigation, according to the text?
What should the Investigation Team do with information received during the course of an investigation, according to the text?
Who is responsible for taking disciplinary action based on the factual findings captured in the investigation report, according to the text?
Who is responsible for taking disciplinary action based on the factual findings captured in the investigation report, according to the text?
Which of the following is NOT a step in the reporting and recommendation process of an investigation, according to the text?
Which of the following is NOT a step in the reporting and recommendation process of an investigation, according to the text?
Who is responsible for reviewing the investigation report and updating recommendations on action(s) to take in response to the findings, according to the text?
Who is responsible for reviewing the investigation report and updating recommendations on action(s) to take in response to the findings, according to the text?
Which party is responsible for updating the investigation database with the summary of internal recipients for reviews and inputs, according to the text?
Which party is responsible for updating the investigation database with the summary of internal recipients for reviews and inputs, according to the text?
Which of the following is NOT a key performance indicator (KPI) for the closure of an investigation, according to the text?
Which of the following is NOT a key performance indicator (KPI) for the closure of an investigation, according to the text?
According to the text, who is authorized to grant exceptions to the application of the policy and seek ratification from the NNPC Limited Board?
According to the text, who is authorized to grant exceptions to the application of the policy and seek ratification from the NNPC Limited Board?
How often is the NNPC Limited Policy Management Processes and Procedures manual intended to be updated, unless there is a specific requirement for an immediate revision?
How often is the NNPC Limited Policy Management Processes and Procedures manual intended to be updated, unless there is a specific requirement for an immediate revision?
Who does the NNPC Limited Policy Management Processes and Procedures manual apply to?
Who does the NNPC Limited Policy Management Processes and Procedures manual apply to?
Which of the following is NOT a component of NNPC Limited's policy management processes and procedures?
Which of the following is NOT a component of NNPC Limited's policy management processes and procedures?
What does the SIPOC model stand for in NNPC Limited's policy management processes and procedures?
What does the SIPOC model stand for in NNPC Limited's policy management processes and procedures?
What is the purpose of the Relationship Map for the Efficiency Function in NNPC Limited's policy management processes and procedures?
What is the purpose of the Relationship Map for the Efficiency Function in NNPC Limited's policy management processes and procedures?
Which department is responsible for drafting the policy and presenting it to the Efficiency Unit and Board Committee?
Which department is responsible for drafting the policy and presenting it to the Efficiency Unit and Board Committee?
What is the timeframe for measuring the performance indicator 'Existence of the drivers of policy formulation'?
What is the timeframe for measuring the performance indicator 'Existence of the drivers of policy formulation'?
What is the basis of measurement for the performance indicator 'Use appropriate template'?
What is the basis of measurement for the performance indicator 'Use appropriate template'?
Which department is responsible for managing NNPC Limited's policies within the company?
Which department is responsible for managing NNPC Limited's policies within the company?
Who has the overall responsibility for Corporate Policies in NNPC Limited?
Who has the overall responsibility for Corporate Policies in NNPC Limited?
What is the objective of the policy formulation process in NNPC Limited?
What is the objective of the policy formulation process in NNPC Limited?
Which party is responsible for driving policy implementation within the relevant business processes, according to the text?
Which party is responsible for driving policy implementation within the relevant business processes, according to the text?
Who is responsible for reviewing the policy for adequacy and strategic alignment, according to the text?
Who is responsible for reviewing the policy for adequacy and strategic alignment, according to the text?
What is the minimum frequency at which the risk assessment pack is inputted in the ERM process at NNPC Limited, according to the text?
What is the minimum frequency at which the risk assessment pack is inputted in the ERM process at NNPC Limited, according to the text?
Who is responsible for preparing a presentation summarizing the policy and its benefits, according to the text?
Who is responsible for preparing a presentation summarizing the policy and its benefits, according to the text?
What is the responsibility of the Head of Efficiency unit in relation to policy changes in NNPC Limited?
What is the responsibility of the Head of Efficiency unit in relation to policy changes in NNPC Limited?
Which of the following triggers may lead to the update or renewal of NNPC Limited's policies?
Which of the following triggers may lead to the update or renewal of NNPC Limited's policies?
Who is responsible for approving policy changes that involve any change in or impact the implementation of Company strategy in NNPC Limited?
Who is responsible for approving policy changes that involve any change in or impact the implementation of Company strategy in NNPC Limited?
Which department is responsible for drafting and presenting policies to the Efficiency Unit and Board Committee?
Which department is responsible for drafting and presenting policies to the Efficiency Unit and Board Committee?
How often are periodic reviews of policies conducted at NNPC Limited?
How often are periodic reviews of policies conducted at NNPC Limited?
What is the role of the Efficiency Unit in the policy management process at NNPC Limited?
What is the role of the Efficiency Unit in the policy management process at NNPC Limited?
What is the responsibility of the Process Owner in the policy modification process at NNPC Limited?
What is the responsibility of the Process Owner in the policy modification process at NNPC Limited?
Which of the following is NOT a purpose of NNPC Limited's Business Continuity Policy?
Which of the following is NOT a purpose of NNPC Limited's Business Continuity Policy?
What is the purpose of NNPC Limited's Business Continuity Policy?
What is the purpose of NNPC Limited's Business Continuity Policy?
What is the general approach to Business Continuity Management (BCM) described in NNPC Limited's Business Continuity Policy?
What is the general approach to Business Continuity Management (BCM) described in NNPC Limited's Business Continuity Policy?
What is the purpose of NNPC Limited's Business Continuity (BC) Policy?
What is the purpose of NNPC Limited's Business Continuity (BC) Policy?
What does NNPC Limited's Business Continuity Policy aim to minimize?
What does NNPC Limited's Business Continuity Policy aim to minimize?
What does NNPC's general approach to Business Continuity Management (BCM) include?
What does NNPC's general approach to Business Continuity Management (BCM) include?
Which of the following triggers may lead to the renewal or update of NNPC Limited's policies?
Which of the following triggers may lead to the renewal or update of NNPC Limited's policies?
Who is responsible for reviewing and approving draft changes to the policy template at NNPC Limited?
Who is responsible for reviewing and approving draft changes to the policy template at NNPC Limited?
Which level of seniority is recommended for the personnel responsible for updating and renewing NNPC Limited's policies?
Which level of seniority is recommended for the personnel responsible for updating and renewing NNPC Limited's policies?
Which department is responsible for retiring corporate policies at NNPC Limited?
Which department is responsible for retiring corporate policies at NNPC Limited?
Who is responsible for evaluating proposed updates to policies at NNPC Limited?
Who is responsible for evaluating proposed updates to policies at NNPC Limited?
What is the role of the Board Audit Committee (BAC) in the policy retirement process at NNPC Limited?
What is the role of the Board Audit Committee (BAC) in the policy retirement process at NNPC Limited?
When should a policy at NNPC Limited be reviewed to ascertain if any modification is required?
When should a policy at NNPC Limited be reviewed to ascertain if any modification is required?
Which of the following is NOT a component of NNPC Limited's Business Continuity Policy?
Which of the following is NOT a component of NNPC Limited's Business Continuity Policy?
What is the purpose of NNPC Limited's Business Continuity Policy?
What is the purpose of NNPC Limited's Business Continuity Policy?
Which department is responsible for drafting NNPC Limited's Business Continuity Policy?
Which department is responsible for drafting NNPC Limited's Business Continuity Policy?
Which of the following is NOT covered by the scope of NNPC Limited's Business Continuity Policy?
Which of the following is NOT covered by the scope of NNPC Limited's Business Continuity Policy?
What is the purpose of Business Continuity Management at NNPC Limited?
What is the purpose of Business Continuity Management at NNPC Limited?
Which of the following events may have regional or nationwide impact, rendering multiple NNPC facilities inaccessible?
Which of the following events may have regional or nationwide impact, rendering multiple NNPC facilities inaccessible?
Which of the following is NOT a goal of NNPC Limited's Business Continuity Management (BCM) program?
Which of the following is NOT a goal of NNPC Limited's Business Continuity Management (BCM) program?
What is the purpose of providing awareness on business continuity to all employees and relevant external parties?
What is the purpose of providing awareness on business continuity to all employees and relevant external parties?
What is the responsibility of the Systems and Strategy sub-unit under Quality Assurance (QA) within NNPC Limited?
What is the responsibility of the Systems and Strategy sub-unit under Quality Assurance (QA) within NNPC Limited?
What is the responsibility of the Crisis Management Team (CMT) at NNPC Limited?
What is the responsibility of the Crisis Management Team (CMT) at NNPC Limited?
What is one of the key responsibilities of the Incident Management Team at NNPC Limited?
What is one of the key responsibilities of the Incident Management Team at NNPC Limited?
What is the purpose of defining and assessing key roles and responsibilities in establishing a business continuity programme?
What is the purpose of defining and assessing key roles and responsibilities in establishing a business continuity programme?
Which of the following is NOT a responsibility of the Business Continuity Manager at NNPC Limited?
Which of the following is NOT a responsibility of the Business Continuity Manager at NNPC Limited?
What is the role of the Business Continuity Champions (Emergency Response/Business Recovery Team) at NNPC Limited?
What is the role of the Business Continuity Champions (Emergency Response/Business Recovery Team) at NNPC Limited?
What is the responsibility of the Information Technology Team (Technical Recovery Team) at NNPC Limited?
What is the responsibility of the Information Technology Team (Technical Recovery Team) at NNPC Limited?
What is the responsibility of the Department Managers in relation to business continuity at NNPC Limited?
What is the responsibility of the Department Managers in relation to business continuity at NNPC Limited?
Which of the following is NOT a reason for updating the Business Continuity Plans?
Which of the following is NOT a reason for updating the Business Continuity Plans?
Who is responsible for reviewing and updating the Business Continuity Plans annually?
Who is responsible for reviewing and updating the Business Continuity Plans annually?
What should be done after identifying changes in business arrangements that have not yet been reflected in the Business Continuity Plan?
What should be done after identifying changes in business arrangements that have not yet been reflected in the Business Continuity Plan?
Which of the following is NOT a responsibility of NNPC in relation to its Business Continuity Plan?
Which of the following is NOT a responsibility of NNPC in relation to its Business Continuity Plan?
Who are considered key stakeholders in NNPC's Business Continuity Management (BCM) program?
Who are considered key stakeholders in NNPC's Business Continuity Management (BCM) program?
What is the purpose of the Business Impact Analysis (BIA) process?
What is the purpose of the Business Impact Analysis (BIA) process?
What is the frequency of reviewing and updating the Business Impact Analysis (BIA) and Risk Assessment (RA) processes?
What is the frequency of reviewing and updating the Business Impact Analysis (BIA) and Risk Assessment (RA) processes?
Which of the following is the primary objective of NNPC's Business Continuity Policy?
Which of the following is the primary objective of NNPC's Business Continuity Policy?
What is the purpose of the Competency and Training Requirements mentioned in the text?
What is the purpose of the Competency and Training Requirements mentioned in the text?
What is the purpose of the NNPC Business Continuity Policy?
What is the purpose of the NNPC Business Continuity Policy?
Which of the following is NOT a component of the business continuity planning process mentioned in the text?
Which of the following is NOT a component of the business continuity planning process mentioned in the text?
What is the purpose of testing the Business Continuity Plans (BCPs) according to the text?
What is the purpose of testing the Business Continuity Plans (BCPs) according to the text?
How often should the Business Continuity Plans (BCPs) be reviewed?
How often should the Business Continuity Plans (BCPs) be reviewed?
What is the responsibility of the owners of the appropriate business resources or processes involved in the business continuity planning process?
What is the responsibility of the owners of the appropriate business resources or processes involved in the business continuity planning process?
Which of the following is NOT a term/abbreviation mentioned in the glossary of terms in the text?
Which of the following is NOT a term/abbreviation mentioned in the glossary of terms in the text?
Which of the following is NOT a stakeholder mentioned in NNPC Limited's due diligence policy?
Which of the following is NOT a stakeholder mentioned in NNPC Limited's due diligence policy?
Which of the following is NOT a purpose of NNPC Limited's due diligence processes?
Which of the following is NOT a purpose of NNPC Limited's due diligence processes?
Who is responsible for overseeing the due diligence review process at NNPC Limited?
Who is responsible for overseeing the due diligence review process at NNPC Limited?
Who administers the due diligence process at NNPC Limited?
Who administers the due diligence process at NNPC Limited?
Who makes recommendations to approve or reject the business relationship at NNPC Limited?
Who makes recommendations to approve or reject the business relationship at NNPC Limited?
Who performs the initial risk categorization at NNPC Limited?
Who performs the initial risk categorization at NNPC Limited?
Which organization is responsible for the lift and sale of royalty oil and tax oil on behalf of the Nigerian Upstream Regulatory Commission and the Federal Inland Revenue Service?
Which organization is responsible for the lift and sale of royalty oil and tax oil on behalf of the Nigerian Upstream Regulatory Commission and the Federal Inland Revenue Service?
What is the purpose of the Frontier Exploration Fund?
What is the purpose of the Frontier Exploration Fund?
Who is responsible for carrying out test marketing to ascertain the value of crude oil?
Who is responsible for carrying out test marketing to ascertain the value of crude oil?
What is the role of NNPC Limited in promoting the domestic use of natural gas?
What is the role of NNPC Limited in promoting the domestic use of natural gas?
Which of the following is considered a Third Party in the context of NNPC Limited's Due Diligence Policy?
Which of the following is considered a Third Party in the context of NNPC Limited's Due Diligence Policy?
What is the objective of NNPC Limited's Due Diligence Policy?
What is the objective of NNPC Limited's Due Diligence Policy?
What is the definition of 'Beneficial Owner' according to NNPC Limited's Due Diligence Policy?
What is the definition of 'Beneficial Owner' according to NNPC Limited's Due Diligence Policy?
What does 'KYC' stand for in the context of NNPC Limited's Due Diligence Policy?
What does 'KYC' stand for in the context of NNPC Limited's Due Diligence Policy?
Which of the following factors is NOT considered when determining the risk rating of an employee's job role at NNPC Limited?
Which of the following factors is NOT considered when determining the risk rating of an employee's job role at NNPC Limited?
Which of the following is responsible for performing the initial risk categorization based on the General IDD and EDD at NNPC Limited?
Which of the following is responsible for performing the initial risk categorization based on the General IDD and EDD at NNPC Limited?
What are the possible risk categories at NNPC Limited?
What are the possible risk categories at NNPC Limited?
Which of the following is NOT a requirement for Level C due diligence according to the text?
Which of the following is NOT a requirement for Level C due diligence according to the text?
What is one of the factors considered when assessing the financial strength of a prospective partner according to the text?
What is one of the factors considered when assessing the financial strength of a prospective partner according to the text?
What type of information is NOT mentioned as potentially required for an investigation according to the text?
What type of information is NOT mentioned as potentially required for an investigation according to the text?
Which type of due diligence is conducted on third parties providing services classified as low risk at NNPC Limited?
Which type of due diligence is conducted on third parties providing services classified as low risk at NNPC Limited?
What is the risk classification that would require weighty reasons and an extensive EDD proportionate to the risk at NNPC Limited?
What is the risk classification that would require weighty reasons and an extensive EDD proportionate to the risk at NNPC Limited?
Which risk classification at NNPC Limited may not move forward with the proposed activity unless there exist substantial reasons for continuing with the project?
Which risk classification at NNPC Limited may not move forward with the proposed activity unless there exist substantial reasons for continuing with the project?
What does a high-risk counterparty at NNPC Limited being listed on a Sanctions List indicate?
What does a high-risk counterparty at NNPC Limited being listed on a Sanctions List indicate?
Which of the following is NOT a component of NNPC Limited's general integrity due diligence review?
Which of the following is NOT a component of NNPC Limited's general integrity due diligence review?
What is the purpose of the general integrity due diligence review conducted by NNPC Limited?
What is the purpose of the general integrity due diligence review conducted by NNPC Limited?
What is the purpose of reviewing sanctions lists as part of the general integrity due diligence review conducted by NNPC Limited?
What is the purpose of reviewing sanctions lists as part of the general integrity due diligence review conducted by NNPC Limited?
According to the text, what is the purpose of pre-employment screening for potential or new employees of NNPC Limited?
According to the text, what is the purpose of pre-employment screening for potential or new employees of NNPC Limited?
What is the basis of risk classification for existing or prospective customers of NNPC Limited?
What is the basis of risk classification for existing or prospective customers of NNPC Limited?
What type of due diligence must be conducted on customers identified as medium to high risk before any business transaction?
What type of due diligence must be conducted on customers identified as medium to high risk before any business transaction?
What should the relevant unit establish, record, maintain, and operate procedures and controls for in respect of new customers or occasional transactions?
What should the relevant unit establish, record, maintain, and operate procedures and controls for in respect of new customers or occasional transactions?
Which of the following statements is true about NNPC Limited's due diligence procedure for doing business with third-party service providers and suppliers?
Which of the following statements is true about NNPC Limited's due diligence procedure for doing business with third-party service providers and suppliers?
What is the purpose of NNPC Limited's due diligence procedure for doing business with third-party service providers and suppliers?
What is the purpose of NNPC Limited's due diligence procedure for doing business with third-party service providers and suppliers?
What is the minimum required due diligence procedure for doing business with certain third-party service providers and suppliers at NNPC Limited?
What is the minimum required due diligence procedure for doing business with certain third-party service providers and suppliers at NNPC Limited?
Which of the following is NOT a factor considered in the assessment of Politically Exposed Persons (PEPs) linked to the counterparty or the relevant NNPC Limited activity?
Which of the following is NOT a factor considered in the assessment of Politically Exposed Persons (PEPs) linked to the counterparty or the relevant NNPC Limited activity?
What is the purpose of conducting a contingency measures review at the outset of any business relationship?
What is the purpose of conducting a contingency measures review at the outset of any business relationship?
Which of the following is NOT a mitigating measure that could be applied in the event of an identified risk?
Which of the following is NOT a mitigating measure that could be applied in the event of an identified risk?
When is an Enhanced Due Diligence (EDD) review carried out by the GRC team or an external provider?
When is an Enhanced Due Diligence (EDD) review carried out by the GRC team or an external provider?
How often should recertifications be performed on vendors and third-party service providers in existing contracts at NNPC Limited?
How often should recertifications be performed on vendors and third-party service providers in existing contracts at NNPC Limited?
Which of the following is NOT a requirement for third parties that undertake regulated business on behalf of NNPC Limited?
Which of the following is NOT a requirement for third parties that undertake regulated business on behalf of NNPC Limited?
What types of processes may NNPC Limited use to perform ongoing monitoring of its counterparties?
What types of processes may NNPC Limited use to perform ongoing monitoring of its counterparties?
Which of the following is NOT a responsibility of the GRC Division/Chief Compliance Officer at NNPC Limited?
Which of the following is NOT a responsibility of the GRC Division/Chief Compliance Officer at NNPC Limited?
What is the minimum educational requirement for the GRC Manager or other relevant officers responsible for implementing the Due Diligence Policy at NNPC Limited?
What is the minimum educational requirement for the GRC Manager or other relevant officers responsible for implementing the Due Diligence Policy at NNPC Limited?
How long should the findings of the Risk monitoring be archived for future reference?
How long should the findings of the Risk monitoring be archived for future reference?
Who is responsible for reviewing the Due Diligence Policy at NNPC Limited every two (2) years and submitting recommendations to the Board of Directors for any necessary amendments or revisions?
Who is responsible for reviewing the Due Diligence Policy at NNPC Limited every two (2) years and submitting recommendations to the Board of Directors for any necessary amendments or revisions?
Flashcards
Risk Appetite
Risk Appetite
The amount of risk NNPC Limited is willing to take to achieve its goals.
Key Objective of Risk Management
Key Objective of Risk Management
The primary goal of risk management is to identify, evaluate, and minimize risks that could hinder NNPC Limited's objectives.
Broad Corporate Objectives
Broad Corporate Objectives
NNPC Limited's risk appetite is based on these broad corporate objectives: strategic, financial, operational, and compliance.
Enterprise Risk Management (ERM) Function
Enterprise Risk Management (ERM) Function
Signup and view all the flashcards
Risk Management Framework
Risk Management Framework
Signup and view all the flashcards
Governance, Risk and Compliance Function
Governance, Risk and Compliance Function
Signup and view all the flashcards
Risk Governance Structure
Risk Governance Structure
Signup and view all the flashcards
Board of Directors' Role in Risk Management
Board of Directors' Role in Risk Management
Signup and view all the flashcards
Management Risk Committee's Role
Management Risk Committee's Role
Signup and view all the flashcards
Risk Management Process
Risk Management Process
Signup and view all the flashcards
Risk Assessment
Risk Assessment
Signup and view all the flashcards
Risk Treatment
Risk Treatment
Signup and view all the flashcards
Risk Monitoring and Reporting
Risk Monitoring and Reporting
Signup and view all the flashcards
Key Risk Indicators (KRIs)
Key Risk Indicators (KRIs)
Signup and view all the flashcards
Risk Management Framework Review
Risk Management Framework Review
Signup and view all the flashcards
Risk Management Training and Awareness
Risk Management Training and Awareness
Signup and view all the flashcards
Risk Management Training and Awareness Plan
Risk Management Training and Awareness Plan
Signup and view all the flashcards
Risk Awareness Program
Risk Awareness Program
Signup and view all the flashcards
Head of Risk Management's Role
Head of Risk Management's Role
Signup and view all the flashcards
Heads of Risk Management in Subsidiaries
Heads of Risk Management in Subsidiaries
Signup and view all the flashcards
Functional Heads' Role
Functional Heads' Role
Signup and view all the flashcards
Risk Management Policy
Risk Management Policy
Signup and view all the flashcards
Risk Management Policy Review
Risk Management Policy Review
Signup and view all the flashcards
Risk Management Policy Exceptions
Risk Management Policy Exceptions
Signup and view all the flashcards
Risk Management Exception Approval
Risk Management Exception Approval
Signup and view all the flashcards
Risk Management Categories
Risk Management Categories
Signup and view all the flashcards
Risk Prioritization
Risk Prioritization
Signup and view all the flashcards
Risk Management Parameters
Risk Management Parameters
Signup and view all the flashcards
Risk Management Frequency
Risk Management Frequency
Signup and view all the flashcards
Risk Management Tools
Risk Management Tools
Signup and view all the flashcards
Risk Management Review
Risk Management Review
Signup and view all the flashcards
Study Notes
Risk Appetite and Objectives
- NNPC Limited's risk appetite is the amount of risk the organization is willing to accept to achieve its objectives.
- The key objective of risk management is to identify, assess, and mitigate risks that could impact the achievement of NNPC Limited's objectives.
- The broad corporate objectives on which NNPC Limited's risk appetite is based include strategic, financial, operational, and compliance objectives.
Risk Management Framework
- The Enterprise Risk Management (ERM) function is responsible for developing and implementing the risk management framework.
- The risk management framework is based on the three lines of defense model.
- The Governance, Risk and Compliance Function is responsible for overseeing the risk management activities at NNPC Limited and its subsidiaries.
Risk Governance Structure
- The risk governance structure consists of the Board of Directors, Management Risk Committee, Heads of Risk Management, and Functional Heads.
- The Board of Directors is responsible for reviewing and approving the risk management framework.
- The Management Risk Committee is responsible for reviewing the risk management framework and recommending it to the Board for approval.
Risk Management Process
- The risk management process involves identifying, assessing, and mitigating risks.
- The risk assessment process involves identifying and assessing risks, and prioritizing them based on their likelihood and impact.
- The risk treatment process involves selecting and implementing risk mitigation strategies.
Risk Monitoring and Reporting
- The risk monitoring and reporting process involves tracking and reporting on risk mitigation efforts.
- Key risk indicators (KRIs) are used to monitor and report on risks.
- The risk management framework is reviewed and updated annually.
Risk Management Training and Awareness
- The risk management training and awareness plan is designed to educate employees on risk management principles and practices.
- The plan includes training programs, workshops, and awareness campaigns.
- The risk awareness program is designed to promote a risk-aware culture within the organization.
Risk Management Roles and Responsibilities
- The Head of Risk Management is responsible for developing and implementing the risk management framework.
- The Heads of Risk Management at NNPC Limited and its subsidiaries are responsible for overseeing risk management activities.
- Functional Heads are responsible for implementing risk management practices within their respective departments.
- The ERM Function is responsible for developing and implementing the risk management framework.
- The Management Risk Committee is responsible for reviewing and approving the risk management framework.
Risk Management Policy
- The risk management policy outlines the organization's approach to risk management.
- The policy is reviewed and updated annually.
- The policy is approved by the Board of Directors.
Risk Management Exceptions
- The Board of Directors is authorized to grant exceptions to the application of the risk management policy.
- Exceptions are granted on a case-by-case basis.
Risk Management Categories
- Risks are categorized based on their likelihood and impact.
- The categories include high, medium, and low risks.
- Risks are prioritized based on their likelihood and impact.
Risk Management Parameters
- The risk management framework considers several parameters, including the organization's risk appetite, risk tolerance, and risk threshold.
- The parameters are used to determine the acceptable level of risk for the organization.
Risk Management Frequency
- Risk management activities are performed at various frequencies, including quarterly, bi-annually, and annually.
- The frequency of risk management activities depends on the organization's risk appetite and risk tolerance.
Risk Management Tools
- Several tools are used in the risk management process, including risk assessment templates, risk registers, and key risk indicators.
- The tools are used to identify, assess, and mitigate risks.
Risk Management Review
- The risk management framework is reviewed annually.
- The review is performed by the Management Risk Committee.
- The review is used to update the risk management framework and ensure it remains effective.
Studying That Suits You
Use AI to generate personalized quizzes and flashcards to suit your learning preferences.