Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 22 pages
Exam (elaborations)

RSK2601 Assignment 1 (COMPLETE ANSWERS) Semester 1 2026 - DUE 1 April 2026

Document preview thumbnail
Preview 3 out of 22 pages

RSK2601 Assignment 1 (COMPLETE ANSWERS) Semester 1 2026 - DUE 1 April 2026

Content preview

[TYPE THE COMPANY NAME]




RSK2601 Assignment 1 (COMPLETE
ANSWERS) Semester 1 2026 - DUE 1 April
2026
NO PLAGIARISM
[Pick the date]




[Type the abstract of the document here. The abstract is typically a short summary of the contents of
the document. Type the abstract of the document here. The abstract is typically a short summary of
the contents of the document.]

,Exam (elaborations)

RSK2601 Assignment 1 (COMPLETE
ANSWERS) Semester 1 2026 - DUE 1 April
2026
RSK2601 Assignment 1 (COMPLETE ANSWERS) Semester 1 2026 - DUE 1
April 2026; 100% TRUSTED Complete, trusted solutions and explanations.




Part 1: Assessment of Information Governance (King IV
Principle 12)
Scenario: Retail company digital expansion, data breach, and compliance failure.

1. Introduction

In the contemporary digital economy, Principle 12 of the King IV Report on Corporate
Governance asserts that the board should govern technology and information in a way that
supports the organization setting and achieving its strategic objectives. For a retail company
launching e-commerce and loyalty apps, information is no longer a back-office concern but a
primary strategic asset and a significant source of risk.

2. Evaluation with Examples

The board in this scenario failed in its fiduciary duty to exercise ethical and effective leadership
regarding data protection.

 Lack of Governance Frameworks: While the board approved the "digital expansion," it
failed to approve a supporting Information Technology (IT) policy. This oversight led
to data being stored without "adequate safeguards," a direct violation of the Protection of
Personal Information Act (POPIA).
 Accountability Gap: King IV emphasizes that the board is responsible for the
governance of risk, even if it delegates the management of risk. By failing to ensure
compliance with data protection legislation, the board allowed a "compliance risk" to
transform into a "reputational and financial crisis" following the breach.
 Example: Similar to the Liberty Group data breach (2018), where vulnerabilities were
exploited, the board’s failure to mandate regular penetration testing or encryption
protocols for payment details demonstrates a lack of oversight.

3. Suggested Actions

,  Adopt an Integrated Governance Framework: The board must implement a data
governance framework that aligns with ISO/IEC 27001 and POPIA requirements.
 Establish a Technology & Information Committee: This committee should provide
specialized oversight of the e-commerce platform's security posture.
 Mandate Regular Audits: Independent third-party audits of the loyalty app’s data
security should be reported directly to the Audit and Risk Committee.

4. Conclusion

The board’s failure to integrate Principle 12 into its digital expansion strategy resulted in a
predictable data breach. Governance is not an obstacle to innovation; it is the safeguard that
ensures innovation is sustainable.




Part 2: Report to Mrs. Vilakazi (CEO) on ERM
Implementation
TO: Mrs. Vilakazi (CEO, Local Coal Mining Ltd)

FROM: Risk Manager

DATE: 24 May 2024

SUBJECT: Understanding the Implementation of Enterprise Risk Management (ERM)

1. Difference between ERM Framework, Policy, and Process

To effectively implement risk management, we must distinguish between these three
foundational elements:

 ERM Framework: This is the "blueprint." It includes the culture, concepts, and
structures that provide the foundations for risk management throughout the company. It
aligns the organization's strategy with ISO 31000 or COSO standards.
 ERM Policy: This is the "rulebook." It is a formal document approved by the board that
communicates the organization's risk appetite, tolerance levels, and the roles and
responsibilities of staff regarding risk.
 ERM Process: This is the "activity." It is the systematic application of management
policies, procedures, and practices to the activities of communicating, consulting, and
establishing the context of risk.

2. Risk Removal vs. Risk Transfer

 Risk Removal (Avoidance): This involves exiting the activity that gives rise to the risk.

Connected book
 image
Publisher: 2011 ISBN: 9781119995531 Edition: Unknown

Document information

Uploaded on
March 1, 2026
Number of pages
22
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$3.00

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
tabithamwendwa73
3.5
(68)
Sold
413
Followers
82
Items
1162
Last sold
3 weeks ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions