CCM Risk Management and Compliance 2 — Questions and Answers
Question 1: A commercial manager discovers that a supplier has a single-source dependency for a critical component. Which risk response strategy is MOST appropriate?
- Accept the risk and continue as-is
- Transfer the risk to the supplier via contract
- Mitigate by qualifying an alternative supplier (Correct answer)
- Avoid by terminating the supplier relationship
Correct answer: Mitigate by qualifying an alternative supplier
Qualifying an alternative supplier reduces single-source dependency and is a classic mitigation strategy for supply chain concentration risk.
Question 2: Under the Foreign Corrupt Practices Act (FCPA), which of the following payments to a foreign government official is generally permissible?
- Payments to secure a large contract award
- Facilitating payments to expedite routine governmental actions (Correct answer)
- Payments disguised as consulting fees to an official's relative
- Gifts exceeding company policy thresholds
Correct answer: Facilitating payments to expedite routine governmental actions
The FCPA provides a narrow exception for facilitating payments made to expedite routine, non-discretionary governmental actions, though many companies prohibit even these.
Question 3: A risk heat map plots risks on axes of probability and impact. A risk in the upper-right quadrant should be treated as:
- Low priority — monitor passively
- Medium priority — review quarterly
- High priority — immediate action required (Correct answer)
- Transferred automatically to insurer
Correct answer: High priority — immediate action required
Upper-right placement indicates both high probability and high impact, making the risk a top priority requiring immediate mitigation action.
Question 4: Which document formally records identified risks, their likelihood, impact, owners, and response plans?
- Risk Appetite Statement
- Risk Register (Correct answer)
- Control Self-Assessment
- Business Impact Analysis
Correct answer: Risk Register
A Risk Register is the primary tool for capturing, tracking, and managing all identified risks throughout the project or organization.
Question 5: A company's compliance team finds that an employee submitted false expense reports totaling $4,000. This is best classified as:
- Strategic risk
- Credit risk
- Operational risk — internal fraud (Correct answer)
- Reputational risk
Correct answer: Operational risk — internal fraud
Internal fraud by an employee is a textbook operational risk event under frameworks such as Basel II/III.
Question 6: When conducting a Third-Party Risk Assessment (TPRA), which due diligence element is MOST critical for a supplier handling sensitive customer data?
- Supplier's marketing budget
- Information security and data privacy controls (Correct answer)
- Number of employees at the supplier
- Supplier's office location
Correct answer: Information security and data privacy controls
For suppliers with access to sensitive data, assessing their information security controls is the highest-priority due diligence item.
Question 7: The principle of 'segregation of duties' in compliance and internal control primarily aims to:
- Increase operational efficiency by combining tasks
- Reduce errors and fraud by requiring multiple individuals to complete sensitive processes (Correct answer)
- Simplify auditing by centralizing responsibilities
- Eliminate the need for management review
Correct answer: Reduce errors and fraud by requiring multiple individuals to complete sensitive processes
Segregation of duties ensures no single individual controls all steps of a critical process, reducing the opportunity for errors or fraud.
A commercial manager discovers that a supplier has a single-source dependency for a critical component.
Which risk response strategy is MOST appropriate?