Compliance and Auditing Risk Management 1 — Questions and Answers
Question 1: In enterprise risk management, what does 'risk appetite' refer to?
- The total amount of risk in a portfolio
- The amount of risk an organization is willing to accept in pursuit of its objectives (Correct answer)
- The probability of a risk event occurring
- The financial impact of all identified risks
Correct answer: The amount of risk an organization is willing to accept in pursuit of its objectives
Risk appetite is the total amount of risk that an organization is willing to accept in pursuit of its strategic objectives, as determined by leadership.
Question 2: The COSO ERM framework identifies how many components of enterprise risk management?
- 4
- 5
- 8 (Correct answer)
- 12
Correct answer: 8
The original COSO ERM framework (2004) identified eight interrelated components: internal environment, objective setting, event identification, risk assessment, risk response, control activities, information and communication, and monitoring.
Question 3: What is a risk heat map used for in compliance and risk management?
- Tracking employee locations
- Visually plotting risks by likelihood and impact to prioritize responses (Correct answer)
- Monitoring server temperatures
- Displaying geographic distribution of customers
Correct answer: Visually plotting risks by likelihood and impact to prioritize responses
A risk heat map is a visual tool that plots identified risks on a matrix of likelihood versus impact to help prioritize risk responses and communicate risk levels to stakeholders.
Question 4: Which risk response strategy involves transferring risk to a third party such as an insurer?
- Risk avoidance
- Risk mitigation
- Risk transfer (Correct answer)
- Risk acceptance
Correct answer: Risk transfer
Risk transfer shifts the financial consequences of a risk to a third party, such as purchasing insurance or using contractual agreements to transfer liability.
Question 5: What is 'residual risk' in risk management?
- The initial risk before any controls are applied
- The risk remaining after controls and mitigation measures have been applied (Correct answer)
- The risk of control failure
- The total risk exposure of an organization
Correct answer: The risk remaining after controls and mitigation measures have been applied
Residual risk is the level of risk that remains after an organization has implemented its risk responses and internal controls to address the inherent risk.
Question 6: Which of the following best describes a 'Key Risk Indicator' (KRI)?
- A measure of past losses from risk events
- A forward-looking metric that signals increasing risk exposure (Correct answer)
- A list of all identified organizational risks
- An audit finding from a prior engagement
Correct answer: A forward-looking metric that signals increasing risk exposure
A Key Risk Indicator (KRI) is a forward-looking metric that signals when risk is increasing and may exceed the organization's risk appetite, enabling proactive management.
In enterprise risk management, what does 'risk appetite' refer to?