GRC - Governance, Risk, and Compliance Enterprise Risk Management Frameworks Questions and Answers — Questions and Answers
Question 1: A global manufacturing company is implementing an Enterprise Risk Management (ERM) framework. The Chief Risk Officer (CRO) wants to ensure the framework is adaptable to different business units and promotes a proactive risk culture. Which ERM framework is best known for its flexible, principles-based approach that can be customized to any organization's context?
- NIST Risk Management Framework
- COBIT Framework
- ISO 31000 (Correct answer)
- COSO ERM - Integrating with Strategy and Performance
Correct answer: ISO 31000
ISO 31000 is recognized for its flexible and principles-based approach, providing guidelines rather than mandatory requirements. This allows organizations to tailor the framework to their specific size, industry, and risk context. COSO ERM is more prescriptive, particularly for organizations focused on financial reporting and internal controls. NIST RMF is primarily for managing information security risk within U.S. federal agencies, and COBIT is a framework for the governance and management of enterprise IT.
Question 2: A financial services firm is updating its ERM framework to better align with its strategic objectives and performance metrics. The board of directors has emphasized the importance of integrating risk management directly into the strategy-setting process. Which of the following is a key component of the COSO ERM 2017 framework that directly addresses this requirement?
- Risk Assessment
- Control Activities
- Strategy and Objective-Setting (Correct answer)
- Monitoring Activities
Correct answer: Strategy and Objective-Setting
The COSO ERM 2017 framework, titled "Enterprise Risk Management—Integrating with Strategy and Performance," explicitly includes 'Strategy and Objective-Setting' as one of its five core components. This component emphasizes considering risk during the strategic planning process to ensure that the chosen strategy aligns with the organization's risk appetite.
Question 3: Which of the following best describes a primary objective of establishing an ERM framework within an organization?
- To completely eliminate all strategic and operational risks.
- To provide a structured and consistent approach for identifying, assessing, and managing risks across the enterprise. (Correct answer)
- To satisfy the requirements of external auditors exclusively.
- To replace the need for internal controls and departmental risk management.
Correct answer: To provide a structured and consistent approach for identifying, assessing, and managing risks across the enterprise.
The core purpose of an ERM framework is to establish a consistent, enterprise-wide approach to managing risk. It provides a structure for identifying potential events that may affect the entity, managing risk to be within its risk appetite, and providing reasonable assurance regarding the achievement of entity objectives. It is not possible to eliminate all risks, and while it aids audits, its purpose is much broader. ERM integrates with, rather than replaces, internal controls.
Question 4: A technology company is deciding between the COSO ERM and ISO 31000 frameworks. The company operates globally and has a diverse range of stakeholders. A key difference the GRC team should consider is that:
- ISO 31000 results in a formal certification, whereas COSO ERM does not.
- COSO ERM is primarily used in Europe, while ISO 31000 is dominant in North America.
- COSO ERM is more prescriptive and detailed, often favored by audit and accounting professionals, while ISO 31000 is a more concise, high-level guideline. (Correct answer)
- ISO 31000 focuses solely on financial risks, while COSO ERM covers all risk categories.
Correct answer: COSO ERM is more prescriptive and detailed, often favored by audit and accounting professionals, while ISO 31000 is a more concise, high-level guideline.
A significant distinction between the two frameworks is their presentation and level of detail. COSO's framework is substantially longer and more detailed, with a historical focus on internal controls and accounting, making it popular with auditors. ISO 31000 is a shorter, more flexible set of principles and guidelines. Neither framework offers a formal certification for compliance. Geographically, ISO 31000 has broader international adoption, while COSO is more prevalent in North America.
Question 5: During a risk committee meeting, a new manager suggests that the company's ERM framework should focus on responding to risks by either avoiding or accepting them. A GRC professional should advise that this view is incomplete because a comprehensive risk response strategy also includes:
- Ignoring and delaying
- Transferring and escalating
- Reducing and sharing (Correct answer)
- Enhancing and exploiting
Correct answer: Reducing and sharing
A standard ERM framework includes four primary risk responses: Avoid, Accept, Reduce (or Mitigate), and Share (or Transfer). Reducing risk involves implementing controls to lower its likelihood or impact. Sharing risk typically involves transferring a portion of it to a third party, such as through insurance.
Question 6: According to the principles of ISO 31000, for risk management to be effective, it must be:
- Managed by a separate, independent risk department.
- A one-time project implemented by external consultants.
- Focused exclusively on downside risks and potential losses.
- Integrated into all of the organization's activities and decision-making processes. (Correct answer)
Correct answer: Integrated into all of the organization's activities and decision-making processes.
A core principle of ISO 31000 is that risk management should be integrated into an organization's governance, strategy, planning, and operations. It should not be a siloed activity but an integral part of how the organization makes decisions at all levels to create and protect value.
A global manufacturing company is implementing an Enterprise Risk Management (ERM) framework.
The Chief Risk Officer (CRO) wants to ensure the framework is adaptable to different business units and promotes a proactive risk culture.
Which ERM framework is best known for its flexible, principles-based approach that can be customized to any organization's context?