[TYPE THE COMPANY NAME]
RSK2601 Assignment 1 (COMPLETE
ANSWERS) Semester 1 2026 - DUE 1 April
2026
NO PLAGIARISM
[Pick the date]
[Type the abstract of the document here. The abstract is typically a short summary of the contents of
the document. Type the abstract of the document here. The abstract is typically a short summary of
the contents of the document.]
,Exam (elaborations)
RSK2601 Assignment 1 (COMPLETE
ANSWERS) Semester 1 2026 - DUE 1 April
2026
RSK2601 Assignment 1 (COMPLETE ANSWERS) Semester 1 2026 - DUE 1
April 2026; 100% TRUSTED Complete, trusted solutions and explanations.
Part 1: Assessment of Information Governance (King IV
Principle 12)
Scenario: Retail company digital expansion, data breach, and compliance failure.
1. Introduction
In the contemporary digital economy, Principle 12 of the King IV Report on Corporate
Governance asserts that the board should govern technology and information in a way that
supports the organization setting and achieving its strategic objectives. For a retail company
launching e-commerce and loyalty apps, information is no longer a back-office concern but a
primary strategic asset and a significant source of risk.
2. Evaluation with Examples
The board in this scenario failed in its fiduciary duty to exercise ethical and effective leadership
regarding data protection.
Lack of Governance Frameworks: While the board approved the "digital expansion," it
failed to approve a supporting Information Technology (IT) policy. This oversight led
to data being stored without "adequate safeguards," a direct violation of the Protection of
Personal Information Act (POPIA).
Accountability Gap: King IV emphasizes that the board is responsible for the
governance of risk, even if it delegates the management of risk. By failing to ensure
compliance with data protection legislation, the board allowed a "compliance risk" to
transform into a "reputational and financial crisis" following the breach.
Example: Similar to the Liberty Group data breach (2018), where vulnerabilities were
exploited, the board’s failure to mandate regular penetration testing or encryption
protocols for payment details demonstrates a lack of oversight.
3. Suggested Actions
, Adopt an Integrated Governance Framework: The board must implement a data
governance framework that aligns with ISO/IEC 27001 and POPIA requirements.
Establish a Technology & Information Committee: This committee should provide
specialized oversight of the e-commerce platform's security posture.
Mandate Regular Audits: Independent third-party audits of the loyalty app’s data
security should be reported directly to the Audit and Risk Committee.
4. Conclusion
The board’s failure to integrate Principle 12 into its digital expansion strategy resulted in a
predictable data breach. Governance is not an obstacle to innovation; it is the safeguard that
ensures innovation is sustainable.
Part 2: Report to Mrs. Vilakazi (CEO) on ERM
Implementation
TO: Mrs. Vilakazi (CEO, Local Coal Mining Ltd)
FROM: Risk Manager
DATE: 24 May 2024
SUBJECT: Understanding the Implementation of Enterprise Risk Management (ERM)
1. Difference between ERM Framework, Policy, and Process
To effectively implement risk management, we must distinguish between these three
foundational elements:
ERM Framework: This is the "blueprint." It includes the culture, concepts, and
structures that provide the foundations for risk management throughout the company. It
aligns the organization's strategy with ISO 31000 or COSO standards.
ERM Policy: This is the "rulebook." It is a formal document approved by the board that
communicates the organization's risk appetite, tolerance levels, and the roles and
responsibilities of staff regarding risk.
ERM Process: This is the "activity." It is the systematic application of management
policies, procedures, and practices to the activities of communicating, consulting, and
establishing the context of risk.
2. Risk Removal vs. Risk Transfer
Risk Removal (Avoidance): This involves exiting the activity that gives rise to the risk.
RSK2601 Assignment 1 (COMPLETE
ANSWERS) Semester 1 2026 - DUE 1 April
2026
NO PLAGIARISM
[Pick the date]
[Type the abstract of the document here. The abstract is typically a short summary of the contents of
the document. Type the abstract of the document here. The abstract is typically a short summary of
the contents of the document.]
,Exam (elaborations)
RSK2601 Assignment 1 (COMPLETE
ANSWERS) Semester 1 2026 - DUE 1 April
2026
RSK2601 Assignment 1 (COMPLETE ANSWERS) Semester 1 2026 - DUE 1
April 2026; 100% TRUSTED Complete, trusted solutions and explanations.
Part 1: Assessment of Information Governance (King IV
Principle 12)
Scenario: Retail company digital expansion, data breach, and compliance failure.
1. Introduction
In the contemporary digital economy, Principle 12 of the King IV Report on Corporate
Governance asserts that the board should govern technology and information in a way that
supports the organization setting and achieving its strategic objectives. For a retail company
launching e-commerce and loyalty apps, information is no longer a back-office concern but a
primary strategic asset and a significant source of risk.
2. Evaluation with Examples
The board in this scenario failed in its fiduciary duty to exercise ethical and effective leadership
regarding data protection.
Lack of Governance Frameworks: While the board approved the "digital expansion," it
failed to approve a supporting Information Technology (IT) policy. This oversight led
to data being stored without "adequate safeguards," a direct violation of the Protection of
Personal Information Act (POPIA).
Accountability Gap: King IV emphasizes that the board is responsible for the
governance of risk, even if it delegates the management of risk. By failing to ensure
compliance with data protection legislation, the board allowed a "compliance risk" to
transform into a "reputational and financial crisis" following the breach.
Example: Similar to the Liberty Group data breach (2018), where vulnerabilities were
exploited, the board’s failure to mandate regular penetration testing or encryption
protocols for payment details demonstrates a lack of oversight.
3. Suggested Actions
, Adopt an Integrated Governance Framework: The board must implement a data
governance framework that aligns with ISO/IEC 27001 and POPIA requirements.
Establish a Technology & Information Committee: This committee should provide
specialized oversight of the e-commerce platform's security posture.
Mandate Regular Audits: Independent third-party audits of the loyalty app’s data
security should be reported directly to the Audit and Risk Committee.
4. Conclusion
The board’s failure to integrate Principle 12 into its digital expansion strategy resulted in a
predictable data breach. Governance is not an obstacle to innovation; it is the safeguard that
ensures innovation is sustainable.
Part 2: Report to Mrs. Vilakazi (CEO) on ERM
Implementation
TO: Mrs. Vilakazi (CEO, Local Coal Mining Ltd)
FROM: Risk Manager
DATE: 24 May 2024
SUBJECT: Understanding the Implementation of Enterprise Risk Management (ERM)
1. Difference between ERM Framework, Policy, and Process
To effectively implement risk management, we must distinguish between these three
foundational elements:
ERM Framework: This is the "blueprint." It includes the culture, concepts, and
structures that provide the foundations for risk management throughout the company. It
aligns the organization's strategy with ISO 31000 or COSO standards.
ERM Policy: This is the "rulebook." It is a formal document approved by the board that
communicates the organization's risk appetite, tolerance levels, and the roles and
responsibilities of staff regarding risk.
ERM Process: This is the "activity." It is the systematic application of management
policies, procedures, and practices to the activities of communicating, consulting, and
establishing the context of risk.
2. Risk Removal vs. Risk Transfer
Risk Removal (Avoidance): This involves exiting the activity that gives rise to the risk.