Mixed Deck — All ARM Topics Flashcards
100 cards from real ARM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All ARM Topics flashcards as text
What is the FIRST step in developing a business continuity program?
Answer: Conducting a Business Impact Analysis (BIA)
The BIA must be conducted first to identify critical business functions and prioritize recovery efforts before developing specific continuity strategies.
Which regulatory body oversees financial risk management in the U.S.?
Answer: Securities and Exchange Commission (SEC).
The Securities and Exchange Commission (SEC) is a U.S. federal government agency responsible for protecting investors, maintaining fair and orderly functioning of securities markets, and facilitating capital formation. It oversees financial risk management by regulating public companies, financial markets, and investment professionals, ensuring transparency and compliance with financial reporting standards.
How does risk pooling benefit insurance companies?
Answer: By distributing risk among multiple policyholders.
Risk pooling is a fundamental principle of insurance where many policyholders contribute premiums to a common fund. This allows the insurer to distribute the financial burden of losses across a large group. When a loss occurs to one policyholder, the cost is shared by the collective, making individual losses manageable and predictable for the insurer.
When evaluating a potential risk control measure, a risk manager performs a cost-benefit analysis. Which of the following is the primary goal of this analysis in the context of risk treatment?
Answer: To ensure the financial cost of implementing the control is justified by the expected reduction in losses.
The core principle of a cost-benefit analysis for risk controls is to determine if the investment is economically sensible. The goal is to ensure that the resources expended on the control are less than or equal to the financial benefit gained from the reduction in risk.
Which analysis tool assesses an organization's internal strengths and weaknesses alongside external opportunities and threats?
Answer: SWOT analysis
SWOT analysis evaluates internal Strengths and Weaknesses and external Opportunities and Threats to inform strategic risk decisions.
Business interruption insurance in the context of business continuity primarily covers:
Answer: Lost income and ongoing expenses when operations are disrupted by a covered event
Business interruption insurance replaces lost revenue and covers fixed operating expenses during the period when normal operations are suspended due to a covered loss.
In business continuity planning, a Business Impact Analysis (BIA) primarily determines:
Answer: The critical business functions and the impact of their disruption
A BIA identifies which business functions are critical and quantifies the potential financial and operational impact of disrupting those functions.
What is the primary difference between risk management and strategic risk management?
Answer: Risk management deals with day-to-day operations while strategic risk management addresses long-term organizational threats
Strategic risk management specifically addresses risks that threaten long-term organizational objectives and competitive positioning, extending beyond daily operational concerns.
After installing a state-of-the-art fire suppression system and conducting mandatory employee fire safety training, a risk manager evaluates the likelihood and impact of a potential fire at the facility. The level of risk that remains after these control measures have been implemented is known as:
Answer: Residual Risk
Residual risk is the amount of risk left over after risk treatment measures, such as controls, have been put in place. Inherent risk is the level of risk before any controls are applied.
What is the primary purpose of integrating risk management into strategic planning?
Answer: To align risk-taking with organizational objectives
Integrating risk management into strategic planning ensures risk-taking activities support and align with the organization's stated objectives.
A manufacturing firm establishes a clear organizational structure where every employee understands their role and responsibilities regarding risk management. The board of directors actively oversees the risk management program to ensure it aligns with the company's strategic goals. This scenario primarily demonstrates which component of the COSO ERM Framework?
Answer: Governance and Culture
The 'Governance and Culture' component of the COSO ERM framework addresses the importance of board oversight, defining operating structures, and establishing the overall tone and culture regarding risk. The scenario directly reflects these principles.
An organization aims to place the financial burden of a potential loss on the party best able to control or prevent the incident. Which risk financing objective is this organization primarily trying to achieve through its contractual agreements?
Answer: Achieving effective contractual risk transfer
The overarching goal of contractual risk transfer is to assign the financial responsibility for a loss to the party that is in the best position to control or prevent the loss from occurring. [21, 25, 30] This is typically accomplished through mechanisms like hold-harmless and indemnity agreements.
An organization, after identifying and analyzing the risk of minor, frequent inventory damage, makes a conscious and planned decision to not purchase insurance for this exposure. Instead, it allocates funds in its budget to cover these expected losses as they occur. This form of risk retention is known as:
Answer: Active Retention
Active risk retention is a planned, deliberate decision to assume the financial consequences of a particular risk. This is in contrast to passive retention, where an organization retains a risk unknowingly, often because the risk was never identified.
In ARM studies, organizational resilience integrates business continuity with:
Answer: Risk management, crisis management, and adaptive capacity
True organizational resilience combines business continuity with broader risk management, crisis response capabilities, and the adaptive capacity to thrive through disruption.
A project team is creating a risk register for an upcoming software development project. Which of the following pieces of information is LEAST likely to be included for each identified risk in the initial risk register?
Answer: The detailed, step-by-step mitigation plan.
While a risk register documents identified risks, their probability, impact, and owner, the detailed, step-by-step mitigation plan is typically developed as part of the risk response planning phase, after the initial identification and analysis. The register might initially note the response strategy (e.g., avoid, mitigate, transfer, accept), but the full plan comes later. [16, 17, 23]
What is the purpose of a risk heat map?
Answer: To visually assess risk impact and likelihood.
A risk heat map is a visual tool used to plot identified risks based on their likelihood of occurrence and their potential impact. This graphical representation helps organizations quickly prioritize risks, as those falling into the 'high impact, high likelihood' quadrant are immediately visible as critical. It provides a clear, concise overview for decision-makers to understand the overall risk landscape.
A risk manager for an airline wants to create a single, comprehensive diagram to visualize a specific high-consequence risk, such as an engine failure. The diagram should show the potential causes (threats) on the left, the critical event in the center, and the potential consequences on the right, along with the preventative and mitigating controls. Which analysis method would be most appropriate?
Answer: Bow-Tie Analysis
Bow-Tie analysis is a visual risk assessment tool that combines elements of Fault Tree Analysis (left side, for threats/causes) and Event Tree Analysis (right side, for consequences) into a single diagram. The 'knot' in the middle represents the critical event or hazard. [7, 12, 14]
Enterprise-wide stress testing helps organizations primarily by:
Answer: Identifying potential vulnerabilities across the entire balance sheet under severe adverse scenarios to support capital planning
Enterprise-wide stress testing aggregates risk exposures across all business lines and applies severe hypothetical scenarios, helping leadership understand aggregate vulnerabilities and ensure sufficient capital buffers are maintained.
Credit derivatives such as credit default swaps (CDS) are primarily used to:
Answer: Transfer credit risk from one party to another without transferring the underlying asset
A CDS allows the protection buyer to transfer the credit risk of a reference entity to the protection seller, who receives periodic payments in exchange for compensating the buyer if a credit event (e.g., default) occurs.
An organization's ERM function is tasked with evaluating two major strategic alternatives: an aggressive expansion into a new, volatile international market or a conservative strategy of optimizing domestic operations. The ERM team analyzes the full spectrum of risks and potential opportunities for both options, aligning the analysis with the company's stated risk appetite. This activity best demonstrates how a mature ERM program:
Answer: Improves strategic decision-making.
A key value of a mature Enterprise Risk Management program is its integration with strategy-setting. By providing a comprehensive view of both risks and opportunities associated with major strategic choices, ERM enables the board and management to make more informed, risk-aware decisions that align with objectives and enhance performance.