โ† All CCEP Flashcard Decks

Risk Assessment & Monitoring Flashcards

7 cards from real CCEP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Assessment & Monitoring flashcards as text
  1. Which methodology assigns numerical values to the likelihood and impact of risks to calculate an overall risk score?

    Answer: Quantitative risk assessment

    Quantitative risk assessment uses numerical values to calculate risk scores, enabling more precise prioritization and resource allocation.

  2. A compliance officer discovers that a business unit consistently underreports incidents. What is the BEST initial response?

    Answer: Conduct a root-cause analysis to identify why underreporting occurs

    Root-cause analysis identifies whether underreporting stems from cultural, process, or training issues before prescribing a remedy.

  3. What does a 'risk appetite statement' formally communicate?

    Answer: The maximum loss a company is willing to accept while pursuing its objectives

    A risk appetite statement defines the level and type of risk an organization is willing to accept in pursuit of its strategic goals.

  4. Which control type is designed to detect a compliance violation AFTER it has occurred?

    Answer: Detective control

    Detective controls identify and surface compliance violations after they occur, such as audits, reconciliations, and monitoring reports.

  5. An organization operates in a highly regulated industry with rapidly changing rules. Which monitoring approach is MOST appropriate?

    Answer: Continuous regulatory monitoring integrated with real-time alerts

    Continuous monitoring with real-time alerts allows organizations to detect and respond to regulatory changes and compliance gaps as they emerge.

  6. What is the purpose of a 'risk register' in compliance programs?

    Answer: To document identified risks, their ratings, owners, and mitigation status

    A risk register serves as a centralized repository that captures identified risks, their assessed severity, responsible owners, and current mitigation efforts.

  7. When prioritizing compliance risks, which factor most directly influences whether a risk should be treated as 'critical'?

    Answer: The combination of high likelihood and high impact

    Risks that are both highly likely to occur and carry severe impact are typically classified as critical and require immediate attention.