Certified Internal Auditor Risk Assessment & Management 3 — Questions and Answers
Question 1: Which framework is most commonly referenced for enterprise risk management (ERM) in the United States?
- ISO 31000
- COSO ERM Framework (Correct answer)
- COBIT 2019
- NIST Cybersecurity Framework
Correct answer: COSO ERM Framework
The COSO Enterprise Risk Management—Integrating with Strategy and Performance framework is the predominant ERM standard in the U.S.
Question 2: An internal auditor assessing strategic risk should focus primarily on risks that could affect:
- Day-to-day operational efficiency
- Individual transaction accuracy
- Achievement of long-term organizational objectives (Correct answer)
- Compliance with payroll regulations
Correct answer: Achievement of long-term organizational objectives
Strategic risks threaten an organization's ability to achieve its high-level goals and long-term direction.
Question 3: Velocity of risk refers to:
- The frequency with which a risk event occurs each year
- How quickly a risk can impact the organization once triggered (Correct answer)
- The rate at which residual risk grows over time
- The speed of management's response to audit findings
Correct answer: How quickly a risk can impact the organization once triggered
Risk velocity measures how rapidly an event can manifest and cause harm, which affects the time available for detection and response.
Question 4: When auditing an ERM program, the internal auditor's role is best described as:
- Designing the risk management process on behalf of management
- Owning risk responses for high-priority risks
- Providing objective assurance and consulting on the ERM process (Correct answer)
- Approving the organization's risk appetite statement
Correct answer: Providing objective assurance and consulting on the ERM process
Internal auditors provide independent assurance that the ERM process is effective and may offer consulting services, but must avoid owning or managing risk on behalf of management.
Question 5: A risk that arises from the potential for legal or regulatory sanctions due to non-compliance is classified as:
- Operational risk
- Compliance risk (Correct answer)
- Reputational risk
- Strategic risk
Correct answer: Compliance risk
Compliance risk is the exposure to fines, penalties, or legal action stemming from failure to adhere to laws, regulations, or internal policies.
Question 6: Which of the following best illustrates 'correlation risk' in a risk portfolio?
- A single vendor supplying 90% of raw materials
- Two unrelated risks that both increase during economic downturns (Correct answer)
- A control that addresses only one risk at a time
- An inherent risk that is identical to residual risk
Correct answer: Two unrelated risks that both increase during economic downturns
Correlation risk occurs when multiple risks move together under certain conditions, amplifying overall exposure beyond what individual risk assessments suggest.
Question 7: Which quantitative technique estimates potential losses by simulating thousands of possible outcomes using random variables?
- Sensitivity analysis
- Monte Carlo simulation (Correct answer)
- Decision tree analysis
- Failure mode and effects analysis (FMEA)
Correct answer: Monte Carlo simulation
Monte Carlo simulation runs many iterations with randomly sampled inputs to produce a probability distribution of potential outcomes.
Which framework is most commonly referenced for enterprise risk management (ERM) in the United States?