🇵🇰 ACCA Pakistan · flashcards

ACCA Pakistan Strategic Business Leader (SBL) Flashcards

53 question-and-answer cards covering Strategic Business Leader (SBL) as it is examined in ACCA Pakistan. 24 of them are printed below, taken from across the deck — no signup, no paywall on the preview.

53Cards in deck
24Free preview
21Syllabus topics
~177Chars per answer
FreePrice

24 sample cards from the Strategic Business Leader (SBL) deck

Sampled from the end of the deck, so these are different cards from the ones shown on the syllabus page.

  1. Define risk and distinguish it from uncertainty.

    Risk is a measurable chance of an outcome differing from expectation, where probabilities can be estimated. Uncertainty is where outcomes and probabilities cannot be reliably quantified.

  2. Distinguish gross (inherent) risk from net (residual) risk.

    Gross/inherent risk is the level of risk before controls are applied. Net/residual risk is the remaining risk after controls and mitigation. Risk appetite is the residual risk the organisation accepts.

  3. What two dimensions are used to assess and map risks?

    Likelihood (probability of occurrence) and impact (severity/consequence). They are plotted on a risk map/heat map to prioritise responses.

  4. What are the four TARA risk responses?

    Transfer (e.g. insurance/hedging), Avoid (stop the activity), Reduce (controls to lower likelihood/impact), Accept (retain low-level risk). Mapped to the likelihood/impact grid.

  5. What is the difference between business risk and financial risk?

    Business risk arises from the nature of operations (strategic, operational, compliance, reputational). Financial risk arises from financing and markets (credit, liquidity, interest rate, currency/gearing).

  6. Define a risk register and its typical contents.

    A document recording identified risks with details such as description, owner, likelihood, impact, current controls, residual risk rating, and planned mitigating actions.

  7. What is the COSO definition of internal control and its five components?

    A process to provide reasonable assurance over operations, reporting and compliance. Components: Control environment, Risk assessment, Control activities, Information & communication, and Monitoring activities.

  8. What is the difference between embedded and standalone risk management?

    Embedded (enterprise risk management) integrates risk management into everyday processes and culture across the whole organisation. Standalone treats risk as a separate, periodic exercise, which is less effective.

  9. What is the three lines model (formerly three lines of defence)?

    First line: operational management owning and managing risk/controls. Second line: risk and compliance functions overseeing. Third line: internal audit providing independent assurance to the board.

  10. What is the difference between a fundamental ethical principle approach and a rules approach (IFAC/ACCA Code)?

    ACCA's Code is principles-based, requiring judgement against five fundamental principles, supported by a conceptual framework to identify, evaluate and address threats, rather than prescriptive rules.

  11. List the five fundamental principles of the ACCA Code of Ethics.

    Integrity, Objectivity, Professional competence and due care, Confidentiality, and Professional behaviour.

  12. Name the five categories of threats to ethical compliance in the ACCA conceptual framework.

    Self-interest, Self-review, Advocacy, Familiarity, and Intimidation threats. Safeguards are applied to reduce them to an acceptable level.

  13. What is Kohlberg's classification of moral development?

    Three levels: Pre-conventional (self-interest, reward/punishment), Conventional (conformity to norms/law), and Post-conventional (universal ethical principles).

  14. What is the CIA triad in information/cyber security?

    Confidentiality (data accessed only by authorised parties), Integrity (data is accurate and unaltered), and Availability (data/systems accessible when needed).

  15. Name common cybersecurity threats an organisation must manage.

    Phishing/social engineering, malware and ransomware, denial-of-service (DoS/DDoS) attacks, hacking/unauthorised access, insider threats, and data breaches.

  16. What are typical controls to mitigate cyber/information risk?

    Firewalls, encryption, access controls and authentication (e.g. MFA), staff training, patch management, intrusion detection, back-ups, and incident response/business continuity plans.

  17. What are the four Vs commonly used to characterise Big Data?

    Volume (scale), Velocity (speed of generation), Variety (different types/sources), and Veracity (trustworthiness/quality). Some add Value as a fifth V.

  18. Distinguish descriptive, diagnostic, predictive and prescriptive analytics.

    Descriptive (what happened), Diagnostic (why it happened), Predictive (what is likely to happen), and Prescriptive (what action should be taken). They increase in value and complexity.

  19. What are key examples of disruptive technologies affecting business strategy?

    Artificial intelligence/machine learning, cloud computing, the Internet of Things (IoT), blockchain/distributed ledgers, robotic process automation (RPA), and 3D printing.

  20. What is the difference between automation (RPA) and artificial intelligence?

    RPA automates repetitive, rule-based tasks following defined logic. AI can learn from data, recognise patterns and make decisions/predictions, handling unstructured problems beyond fixed rules.

  21. What is the purpose and independence requirement of internal audit?

    Internal audit provides independent, objective assurance and consulting on risk, control and governance. It should report functionally to the audit committee to safeguard its independence.

  22. What are the four perspectives of the Balanced Scorecard?

    Financial, Customer, Internal business process, and Learning & growth (innovation). It links performance measures to strategy beyond purely financial metrics.

  23. What does ROCE measure and how is it calculated?

    Return on Capital Employed measures operating efficiency/profitability of capital. ROCE = Operating profit (PBIT) / Capital employed, where capital employed = total assets less current liabilities (or equity + debt).

  24. What is Economic Value Added (EVA) and its basic formula?

    EVA measures value created above the cost of capital. EVA = Net Operating Profit After Tax (NOPAT) - (WACC x Capital employed). Positive EVA means value is being created for shareholders.

What this deck covers

The Strategic Business Leader (SBL) deck follows the ACCA Pakistan Strategic Business Leader (SBL) syllabus — 7 chapters and 21 topics — so questions land on material that is genuinely examinable rather than trivia around it. That works out to roughly 7.6 cards per chapter.

Answers are written to be recallable, not just readable — averaging about 177 characters, which is long enough to carry the reasoning and short enough to say out loud.

A deck like this earns its keep on the second and third pass. Read the syllabus first so you know the shape of the subject, then use the cards to find the specific facts that have not stuck.

Strategic Business Leader (SBL) flashcards FAQ

How many Strategic Business Leader (SBL) flashcards are in this ACCA Pakistan deck?

53 cards. This page previews 24 of them, sampled evenly across the deck so you can judge the difficulty before installing anything.

Are these ACCA Pakistan flashcards free?

Yes. The preview here is free to read with no signup, and the full 53-card deck is free inside the Examius app.

What do the Strategic Business Leader (SBL) cards cover?

They follow the ACCA Pakistan Strategic Business Leader (SBL) syllabus — 7 chapters and 21 topics — so the questions track what is actually examinable.

How should I use these flashcards?

Read the syllabus first so you know the shape of the subject, then drill the deck. Examius schedules each card with spaced repetition, so cards you keep missing come back sooner and ones you know drift further apart.