Certified Internal Auditor Risk Assessment & Management 5 β Questions and Answers
Question 1: The Three Lines Model assigns primary responsibility for risk management and internal controls to:
- The internal audit function (third line)
- Risk and compliance functions (second line)
- Operational management (first line) (Correct answer)
- The board of directors (governing body)
Correct answer: Operational management (first line)
In the Three Lines Model, operational management (first line) owns and manages risks as part of day-to-day activities.
Question 2: Scenario analysis differs from sensitivity analysis in that scenario analysis:
- Changes one variable at a time to measure impact
- Examines the effect of multiple simultaneous variable changes (Correct answer)
- Uses historical data exclusively
- Requires precise probability estimates
Correct answer: Examines the effect of multiple simultaneous variable changes
Scenario analysis evaluates the combined impact of multiple risk factors changing simultaneously, while sensitivity analysis varies one variable at a time.
Question 3: An auditor is evaluating a risk that has a 10% probability of occurring and would result in a $500,000 loss. The expected value of this risk is:
- $500,000
- $50,000 (Correct answer)
- $5,000
- $450,000
Correct answer: $50,000
Expected value = probability Γ impact = 0.10 Γ $500,000 = $50,000.
Question 4: Which of the following is a primary limitation of relying solely on historical data for risk assessment?
- Historical data is too expensive to collect
- Past events may not reflect future risk exposures accurately (Correct answer)
- Historical analysis requires too many auditors
- Past data always overstates risk severity
Correct answer: Past events may not reflect future risk exposures accurately
Historical data reflects past conditions; new technologies, markets, or operating environments can produce novel risks not captured in historical records.
Question 5: A control that reduces the likelihood of a risk event occurring is classified as a:
- Detective control
- Corrective control
- Preventive control (Correct answer)
- Compensating control
Correct answer: Preventive control
Preventive controls are designed to stop risk events from happening, reducing their probability of occurrence.
Question 6: Which of the following best describes 'inherent risk' in an audit context?
- Risk remaining after management applies controls
- The gross risk exposure before any controls are applied (Correct answer)
- Risk that cannot be mitigated under any circumstances
- Risk identified only through substantive testing
Correct answer: The gross risk exposure before any controls are applied
Inherent risk is the level of risk that exists in the absence of any management controls or mitigating actions.
Question 7: A risk culture assessment by internal audit would MOST likely include evaluating:
- The mathematical accuracy of the risk register scores
- Whether employees feel safe reporting risk concerns without retaliation (Correct answer)
- The adequacy of cyber insurance coverage limits
- Accuracy of financial statement disclosures about risk
Correct answer: Whether employees feel safe reporting risk concerns without retaliation
A healthy risk culture requires psychological safety; auditors assess whether employees can raise concerns freely, which underpins the entire risk management system.
The Three Lines Model assigns primary responsibility for risk management and internal controls to: