Certified Internal Auditor Risk Assessment & Management 2 — Questions and Answers
Question 1: Which risk assessment technique uses a structured group process to elicit expert opinions anonymously across multiple rounds?
- Delphi technique (Correct answer)
- Nominal group technique
- Brainstorming
- Root cause analysis
Correct answer: Delphi technique
The Delphi technique gathers anonymous expert input through iterative questionnaire rounds until consensus is reached.
Question 2: Residual risk is best defined as the risk that remains after:
- Risk identification is complete
- Management implements controls (Correct answer)
- The audit committee reviews findings
- Risk appetite is established
Correct answer: Management implements controls
Residual risk is the exposure that remains after management has applied controls to address inherent risk.
Question 3: An organization's risk appetite differs from its risk tolerance in that risk appetite represents:
- The maximum loss acceptable before controls fail
- The broad level of risk an entity is willing to accept in pursuit of objectives (Correct answer)
- The specific variance permitted around individual risk targets
- The residual risk after mitigation is applied
Correct answer: The broad level of risk an entity is willing to accept in pursuit of objectives
Risk appetite is the overall amount of risk an entity is willing to accept, while risk tolerance is the acceptable deviation around specific objectives.
Question 4: When using a heat map to present risk assessment results, the axes typically represent:
- Cost and time
- Likelihood and impact (Correct answer)
- Inherent and residual risk
- Quantitative and qualitative scores
Correct answer: Likelihood and impact
Heat maps plot risks on a two-dimensional grid of likelihood (probability) versus impact (consequence) to prioritize audit attention.
Question 5: Which of the following is an example of a risk response strategy known as 'risk sharing'?
- Discontinuing a high-risk product line
- Purchasing insurance for property damage (Correct answer)
- Installing fire suppression systems
- Accepting the potential loss from minor fraud
Correct answer: Purchasing insurance for property damage
Insurance transfers a portion of financial risk to a third party, which is the essence of the risk sharing (transfer) response.
Question 6: Key Risk Indicators (KRIs) are most useful to internal auditors because they:
- Replace the need for substantive testing
- Provide a historical record of losses incurred
- Signal emerging risk before it materializes into loss (Correct answer)
- Define the maximum risk the board will accept
Correct answer: Signal emerging risk before it materializes into loss
KRIs are forward-looking metrics that alert management and auditors to increasing risk exposure before a loss event occurs.
Question 7: During a risk assessment, the internal auditor discovers that a control is effective but the underlying risk is very low. The auditor should conclude that:
- The control is unnecessary and should be removed immediately
- The cost-benefit of the control should be evaluated by management (Correct answer)
- Additional controls should be added for defense-in-depth
- The risk should be escalated to the board
Correct answer: The cost-benefit of the control should be evaluated by management
When a control's cost may exceed the benefit given a low-risk environment, it is the auditor's role to recommend that management evaluate the cost-effectiveness, not to unilaterally remove controls.
Which risk assessment technique uses a structured group process to elicit expert opinions anonymously across multiple rounds?