CRA Risk Mitigation and Controls 2 — Questions and Answers
Question 1: A company implements dual authorization for all transactions above $50,000. This control is best classified as which type?
- Detective control
- Preventive control (Correct answer)
- Corrective control
- Compensating control
Correct answer: Preventive control
Dual authorization prevents unauthorized transactions from occurring by requiring two approvals before execution, making it a preventive control.
Question 2: Which risk treatment option involves purchasing insurance against potential losses?
- Risk avoidance
- Risk reduction
- Risk transfer (Correct answer)
- Risk acceptance
Correct answer: Risk transfer
Insurance transfers the financial consequence of a risk to a third party (the insurer), making it a classic risk transfer mechanism.
Question 3: An organization discovers its residual risk exceeds its risk appetite after implementing controls. What should happen next?
- Accept the residual risk unconditionally
- Implement additional or stronger controls (Correct answer)
- Remove existing controls and start over
- Transfer all risk to a third party immediately
Correct answer: Implement additional or stronger controls
When residual risk exceeds risk appetite, additional or enhanced controls must be implemented to bring the risk within acceptable thresholds.
Question 4: The COSO framework's control activities component includes which of the following?
- Risk appetite statements
- Entity-level objectives
- Physical controls and IT general controls (Correct answer)
- Stakeholder communication plans
Correct answer: Physical controls and IT general controls
COSO's control activities encompass both physical controls (locks, access badges) and IT general controls (access management, change control) that help ensure risk responses are carried out.
Question 5: A risk architect recommends segregation of duties (SoD) for a financial process. What risk does SoD primarily mitigate?
- Market risk from price fluctuations
- Fraud and error through collusion or mistake (Correct answer)
- Reputational risk from public disclosure
- Liquidity risk from cash shortfalls
Correct answer: Fraud and error through collusion or mistake
Segregation of duties mitigates fraud and error by ensuring no single individual controls all aspects of a critical transaction.
Question 6: Which metric best measures the effectiveness of a risk control over time?
- Gross risk rating before controls
- Key Risk Indicator (KRI) trend analysis (Correct answer)
- Number of controls documented
- Inherent risk score
Correct answer: Key Risk Indicator (KRI) trend analysis
KRI trend analysis tracks whether control performance is improving, stable, or deteriorating, making it the best measure of control effectiveness over time.
Question 7: A compensating control is most appropriate when:
- The primary control is too expensive to implement
- The organization wants to eliminate all residual risk
- A primary control cannot be implemented due to technical or business constraints (Correct answer)
- Residual risk is below the risk appetite threshold
Correct answer: A primary control cannot be implemented due to technical or business constraints
Compensating controls are substitutes used when the ideal primary control cannot be implemented due to technical limitations, cost, or operational constraints.
A company implements dual authorization for all transactions above $50,000.
This control is best classified as which type?