Risk Classification
Domains
Enterprise Risk Management
Change Management
Mixed
100

What individual perceives as an unwanted event (opinion)

What is subjective risk?

100

This domain risks affect the financial sustainability of the organization.

What is the Financial Domain?

100

This modern management system breaks down silos and promotes a comprehensive and wholistic attitude towards risk throughout an organization.  

What is an Enterprise Risk Management System (ERM)?

100

This is an overlooked aspect of change management. IT often refers to the norms or values of an organization, which is shared amongst the colleagues in an organization. 

Culture

100

The role of a risk manager.

What is to make everyone a risk manager?

200

A risk that is measurable or quantifiable.

What is objective risk? 

200

This domain's risks are associated with the delivery of care to patients.

What is the Clinical/Patient Safety Domain?

200

This is 1 of the 5 key elements in the ERM process.

What is... 

strategy setting, risk ID, risk assessment, risk response, and communication?

200

The ___ phase of the three phase process of resistance process recognizes and determine what needs to change. 

Phase 1- Unfreeze 


200

This tool can be used to assess a risk's frequency and severity characteristics.

What is a Risk Map?

300

A risk brought on by sudden or unpredictable changes (ex: global risks)

What is dynamic risk?

300

This domain is associated with competition, brand, and the failure to adapt to changing times.

What is the Strategic Domain?

300

This new senior role was developed to manage the implementation and maintenance of the ERM system across the organization.

What is the Chief Risk Officer position (CRO)?

300

An example of how to create urgency within an organization.

Have honest discussions and provide convincing reasons to get people of your organization to continue dialogue to push others to want the change. 

300

This domain is not related to malpractice litigation but is associated with fraud, accreditation, or breaking a law.

What is the Legal/Regulatory Domain?

400

  The factors of this risk do not change (ex: Natural disasters)

What is static risk?

400

This ASHRM domain covers assets and their value.

What is the Hazard Domain?

400

As hospitals modernized and their sensitive healthcare data was put on computers, they became vulnerable to this new type of organization wide risk.

What are cyberattacks and computer failures?

400

You must develop a  ___ in order to address any resistance that comes to the implementation of a new change.

Structured process

400

This relates to the increase in frequency and severity of an adverse event. 

What is a Hazard?

500

The CEO of Penn Medicine has asked you to discuss the risk of surgical errors. Are surgical errors considered an objective or subjective risk? Explain.  

What is Objective risk since it is measurable?

500

A patient has a HAC due to a deviation in the standard of care by a physician who believed he was right about a treatment. This falls under the patient safety domain but the best correlated risk domain is.

What is the Operational Domain?

500

Leadership support is the _____ action step in the ERM process, executives and senior leaders must buy into the value provided by ERM and promote it internally.  

What is the first action step in the ERM implementation process?  

500

Name a type of resistance that could arise and give an example of how to address it. 

Emotional – fear, loss, sadness, anger, anxiety, frustration, 

depression, and focusing on self

• Disengaged – quiet, avoidance, ignoring communications, 

indifference, apathy, and low morale

• Work impact – reduced productivity/efficiency, non-compliance, 

absenteeism, and mistakes

• Acting out – conflict, overbearing, arguments, sabotage, 

aggressive, passive-aggressive, and celebrate failure

• Negativity – rumors/gossip, miscommunication, objections, 

complaining, sarcasm, and focusing on problems

• Avoidance – ignoring change, reverting to old behaviors, 

workarounds, and abdicating responsibilities

• Building barriers – excuses, counter-approaches, recruiting 

dissenters, secrecy, breakdown of trusts

• Controlling – asking many questions, influencing outcomes, 

defending the current state, using status


addressing it: training managers and supervisors to handle conversations with concerned employees. Inviting participation in solutions and enlisting resources of support.

500

This type of hazard relates to loss due to carelessness when one fails to comply with set protocols. This carelessness causes an increase in frequency and severity.

What is Morale Hazard?