โ† All CED Flashcard Decks

Risk Assessment & Management Flashcards

7 cards from real CED practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Assessment & Management flashcards as text
  1. A nonprofit executive director discovers that a key grant funder represents 60% of the organization's annual budget. Which risk management strategy is most appropriate?

    Answer: Mitigate the risk by actively diversifying funding sources

    Diversifying funding sources reduces concentration risk and decreases dependency on any single funder.

  2. What is the primary purpose of a SWOT analysis in the context of organizational risk management?

    Answer: To identify internal and external factors that may affect organizational objectives

    SWOT analysis identifies Strengths, Weaknesses, Opportunities, and Threats to inform strategic and risk planning.

  3. An organization's risk register should be reviewed and updated at minimum:

    Answer: Annually, or whenever significant organizational changes occur

    Risk registers should be reviewed at least annually and after significant changes to keep risk information current and actionable.

  4. Which of the following best describes residual risk?

    Answer: The risk remaining after mitigation measures have been applied

    Residual risk is the level of risk that remains after controls, mitigation strategies, or other risk responses have been implemented.

  5. A CED is preparing for a potential cyberattack on the organization's donor database. Which response plan element is MOST critical to establish in advance?

    Answer: Clear roles, communication protocols, and a data recovery procedure

    Effective incident response requires pre-defined roles, communication chains, and recovery steps to minimize damage and restore operations quickly.

  6. When evaluating a new program expansion, an executive director should conduct a risk assessment PRIMARILY to:

    Answer: Identify potential barriers and plan mitigation before launch

    Risk assessment before a program launch allows leaders to anticipate problems and build mitigation strategies into the implementation plan.

  7. Which type of risk is associated with an organization failing to comply with state nonprofit reporting requirements?

    Answer: Compliance risk

    Compliance risk arises from failing to adhere to applicable laws, regulations, or reporting requirements.