CPP Risk Management in Process Improvement 1 — Questions and Answers
Question 1: What is the primary purpose of risk management in process improvement initiatives?
- To eliminate all potential risks before proceeding
- To identify, assess, and mitigate risks that could impact process improvement outcomes (Correct answer)
- To transfer all risks to external stakeholders
- To document risks only after they have occurred
Correct answer: To identify, assess, and mitigate risks that could impact process improvement outcomes
Risk management in process improvement aims to proactively identify, assess, and mitigate risks to protect the initiative's outcomes and objectives.
Question 2: Which internationally recognized framework provides principles and guidelines for risk management in process improvement projects?
- PRINCE2
- ISO 31000 (Correct answer)
- COBIT 2019
- ITIL v4
Correct answer: ISO 31000
ISO 31000 is the internationally recognized standard that provides principles, a framework, and a process for managing risk across organizations.
Question 3: In a risk matrix, which two dimensions are used to evaluate and prioritize risks?
- Cost and time
- Probability and impact (Correct answer)
- Complexity and scope
- Resources and constraints
Correct answer: Probability and impact
A risk matrix evaluates risks based on their probability (likelihood of occurrence) and impact (consequence if the risk materializes) to determine priority.
Question 4: What is a 'risk trigger' in the context of process improvement?
- The initial event that launches a process improvement project
- A condition or event indicating a risk is about to occur or has occurred (Correct answer)
- The point at which risk management activities formally begin
- A tool used to generate hypothetical risk scenarios
Correct answer: A condition or event indicating a risk is about to occur or has occurred
A risk trigger is a warning sign or condition that indicates a risk event is imminent or has begun to materialize, prompting execution of contingency plans.
Question 5: Which of the following best describes 'residual risk' in process improvement?
- Risk that has been completely eliminated by control measures
- Risk that remains after risk response measures have been implemented (Correct answer)
- Risk that was not identified during the initial risk assessment
- Risk that has been formally transferred to a third party
Correct answer: Risk that remains after risk response measures have been implemented
Residual risk is the level of risk that remains after risk control measures and mitigation strategies have been applied to the original risk.
Question 6: What does the FMEA technique primarily analyze in a process improvement context?
- Financial modeling and economic return analysis
- Potential failure modes, their causes, and their effects within a process (Correct answer)
- Forward-looking market evaluation and competitive assessment
- Functional mapping and enterprise architecture design
Correct answer: Potential failure modes, their causes, and their effects within a process
FMEA (Failure Mode and Effects Analysis) systematically analyzes potential failure modes within a process to identify causes and effects, prioritizing risk reduction efforts.
Question 7: In risk management terminology, what does 'risk appetite' refer to?
- The maximum financial loss an organization can sustain from a single event
- The amount and type of risk an organization is willing to accept in pursuit of its objectives (Correct answer)
- The total number of risks identified and logged in a project
- The financial reserves set aside specifically for risk management activities
Correct answer: The amount and type of risk an organization is willing to accept in pursuit of its objectives
Risk appetite is the amount and type of risk an organization is willing to accept in pursuit of its strategic objectives before further action is required.
What is the primary purpose of risk management in process improvement initiatives?