CRA - Certified Risk Architect Enterprise Risk Management Frameworks Questions and Answers — Questions and Answers
Question 1: A global manufacturing firm is implementing an Enterprise Risk Management (ERM) framework. The board is particularly focused on ensuring that risk management is not treated as a separate, isolated function but is deeply embedded in all significant business activities and strategic decisions. Which principle of ISO 31000:2018 directly addresses this specific concern?
- Risk management is based on the best available information.
- Risk management is dynamic, iterative, and responsive to change.
- Risk management is an integral part of all organizational processes. (Correct answer)
- Risk management is systematic, structured, and timely.
Correct answer: Risk management is an integral part of all organizational processes.
The ISO 31000:2018 standard emphasizes that for risk management to be effective, it must be integrated into the organization's governance, strategy, planning, and operations. This principle ensures that risk considerations are part of decision-making at all levels, rather than being an afterthought or a compliance exercise.
Question 2: In the COSO ERM Framework (2017), which component is primarily concerned with an organization's ethical values, desired behaviors, board oversight, and commitment to building human capital?
- Strategy & Objective-Setting
- Performance
- Review & Revision
- Governance & Culture (Correct answer)
Correct answer: Governance & Culture
The 'Governance & Culture' component of the COSO ERM Framework sets the organization's tone and establishes oversight responsibilities. It encompasses the board's role in risk oversight, the definition of the desired organizational culture, a commitment to core values, and the ability to attract, develop, and retain capable individuals.
Question 3: A financial services company is deciding between adopting the ISO 31000 standard or the COSO ERM framework. The company operates in a highly regulated industry and requires a detailed, prescriptive approach that strongly links risk management with internal controls and strategic performance. Which framework would be more suitable for this organization?
- ISO 31000, because it is an international standard applicable to any organization.
- COSO ERM, because it provides a more structured and detailed model with predefined components that integrate risk with strategy and performance. (Correct answer)
- ISO 31000, because of its emphasis on flexibility and adaptability.
- Both are equally suitable as they share the same core principles and application.
Correct answer: COSO ERM, because it provides a more structured and detailed model with predefined components that integrate risk with strategy and performance.
While both frameworks are robust, COSO ERM is generally considered more prescriptive and detailed, with a strong emphasis on integrating risk management with strategy, performance, and internal controls. This makes it particularly suitable for organizations in highly regulated sectors like finance that require a comprehensive and structured approach. ISO 31000 is more of a high-level, flexible guideline adaptable to any organization.
Question 4: A risk architect is reviewing their company's ERM program, which is based on the COSO framework. They notice that while risks are identified and assessed, the process for evaluating how well the ERM components are functioning over time and making necessary adjustments is weak. Which COSO ERM component needs to be strengthened?
- Performance
- Information, Communication, & Reporting
- Review & Revision (Correct answer)
- Strategy & Objective-Setting
Correct answer: Review & Revision
The 'Review & Revision' component of the COSO ERM framework deals with assessing the performance of the ERM capabilities over time and pursuing continual improvement. If the process for evaluating the effectiveness of the ERM components and making adjustments is weak, this is the specific component that requires attention.
Question 5: Which of the following best describes a key objective of the COSO ERM - Integrating with Strategy and Performance (2017) framework?
- To provide a certifiable standard for risk management practices that is applicable globally.
- To focus primarily on internal financial controls to prevent fraudulent reporting.
- To position risk management as an isolated exercise for compliance and auditing purposes.
- To link enterprise risk management with an organization's strategy-setting process and performance. (Correct answer)
Correct answer: To link enterprise risk management with an organization's strategy-setting process and performance.
A central theme of the 2017 update to the COSO ERM framework was to more explicitly connect and integrate risk management with strategy and performance. The framework is designed to help organizations anticipate risks to their strategy and understand how risk and performance are intertwined in creating, preserving, and realizing value.
Question 6: A technology startup is developing its first ERM framework. The leadership team prioritizes an agile and adaptable approach that can be tailored to their rapidly changing business context. They want a set of principles and guidelines rather than a prescriptive, control-based system. Based on these priorities, which framework is the most logical starting point?
- COSO Internal Control—Integrated Framework
- ISO 31000:2018 (Correct answer)
- Sarbanes-Oxley Act (SOX)
- Basel III
Correct answer: ISO 31000:2018
ISO 31000:2018 is designed as a set of principles and guidelines that offer flexibility and can be customized to an organization's specific context and needs. It is not a certifiable standard but a universally applicable guide, making it ideal for a startup that requires an agile and adaptable approach rather than a rigid, compliance-heavy framework like SOX or Basel III, or the more structured COSO ERM framework.
A global manufacturing firm is implementing an Enterprise Risk Management (ERM) framework.
The board is particularly focused on ensuring that risk management is not treated as a separate, isolated function but is deeply embedded in all significant business activities and strategic decisions.
Which principle of ISO 31000:2018 directly addresses this specific concern?