Risk Management & Internal Controls Flashcards
7 cards from real CCCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Management & Internal Controls flashcards as text
What is the PRIMARY purpose of a Key Risk Indicator (KRI)?
Answer: To provide early warning signals of increasing risk exposure
KRIs are forward-looking metrics that signal when risk levels are trending toward or beyond acceptable thresholds before an event occurs.
Which of the following best describes 'inherent risk' in a compliance context?
Answer: Risk that exists before any mitigating controls are in place
Inherent risk is the raw or gross risk level existing in a business process or activity before any controls or mitigation measures are applied.
A compliance officer discovers that controls designed to prevent money laundering are operating but are insufficient to reduce risk to an acceptable level. The BEST next step is to:
Answer: Implement additional or enhanced compensating controls
When existing controls are insufficient, the appropriate response is to strengthen or add compensating controls to close the gap before considering acceptance or escalation.
Under the Three Lines of Defense model, which line is responsible for setting risk appetite and overseeing the overall risk management framework?
Answer: Board and senior management
The board and senior management sit above the three lines and are responsible for establishing risk appetite and providing overall governance of the risk framework.
Which control activity is MOST effective at detecting unauthorized access to sensitive systems after the fact?
Answer: System access log reviews
Reviewing system access logs is a detective control that identifies unauthorized or suspicious access activities after they have occurred.
A risk that cannot be further reduced through practical controls and must be consciously accepted by management is called:
Answer: Tolerated risk
Tolerated risk refers to residual risk that management has evaluated, deemed acceptable within the risk appetite, and formally decided to accept rather than further mitigate.
Which scenario represents a 'risk transfer' strategy in corporate compliance?
Answer: Purchasing cyber liability insurance
Purchasing insurance transfers the financial consequences of a risk event to a third party (the insurer), which is the defining characteristic of a risk transfer strategy.