CB Risk Management & Mitigation 2 — Questions and Answers
Question 1: A company discovers that a single employee can both approve purchase orders and issue checks. Which type of internal control weakness does this represent?
- Lack of physical controls
- Inadequate segregation of duties (Correct answer)
- Insufficient documentation
- Poor authorization procedures
Correct answer: Inadequate segregation of duties
When one person can both approve transactions and handle related assets, it eliminates the checks-and-balances that segregation of duties provides.
Question 2: Which risk mitigation strategy involves purchasing insurance to cover potential losses from a specific business risk?
- Risk avoidance
- Risk reduction
- Risk transfer (Correct answer)
- Risk acceptance
Correct answer: Risk transfer
Risk transfer shifts the financial consequences of a loss to a third party, such as an insurance company, rather than bearing the risk internally.
Question 3: A bookkeeper notices that bank reconciliations have not been performed for three months. Which risk does this create?
- Increased tax liability
- Undetected errors and fraud (Correct answer)
- Higher borrowing costs
- Reduced depreciation accuracy
Correct answer: Undetected errors and fraud
Timely bank reconciliations are a key detective control that catches discrepancies between bank records and company books, including fraudulent transactions.
Question 4: Under the COSO framework, which component focuses on the company's overall attitude and awareness toward risk?
- Control Activities
- Risk Assessment
- Control Environment (Correct answer)
- Monitoring
Correct answer: Control Environment
The Control Environment is the foundation of all internal controls and reflects management's tone, ethical values, and commitment to integrity.
Question 5: A company requires two signatures on checks exceeding $10,000. This is an example of which type of control?
- Detective control
- Preventive control (Correct answer)
- Corrective control
- Directive control
Correct answer: Preventive control
Dual-signature requirements prevent unauthorized disbursements before they occur, making this a preventive control.
Question 6: Which document formally identifies, assesses, and prioritizes risks within an organization?
- Balance sheet
- Risk register (Correct answer)
- Trial balance
- Audit report
Correct answer: Risk register
A risk register is a tool used to document identified risks, their likelihood, potential impact, and planned responses.
Question 7: A bookkeeper learns that the company's key financial data is stored only on local hard drives with no backups. Which risk category does this primarily represent?
- Credit risk
- Operational risk (Correct answer)
- Market risk
- Compliance risk
Correct answer: Operational risk
Operational risk arises from failures in internal processes, people, systems, or external events — including data loss from inadequate backup procedures.
A company discovers that a single employee can both approve purchase orders and issue checks.
Which type of internal control weakness does this represent?