|
We have all the information we need to manage risk at an enterprise-wide level
|
|
|
|
|
|
We have a common terminology and set of standards for managing risk
|
|
|
|
|
|
Company objectives and risk appetite/tolerance are clearly articulated
|
|
|
|
|
|
Risk management is fully integrated within our strategic planning process
|
|
|
|
|
|
Risks are quantified to the greatest possible extent
|
|
|
|
|
|
Risk management is fully integrated across all functions and business units
|
|
|
|
|
|
Everyone in the organization understands his/her level of accountability with respect to managing risk
|
|
|
|
|
|
We have a formal structure and process for monitoring risk and the effectiveness of risk response plans
|
|
|
|
|