โ† All CED Flashcard Decks

Risk Assessment & Management Flashcards

7 cards from real CED practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Assessment & Management flashcards as text
  1. A CED discovers that a vendor handling donor payment processing does not comply with PCI DSS standards. The immediate priority should be:

    Answer: Terminate the contract and migrate to a compliant payment processor

    Using a non-PCI-compliant payment processor exposes the organization to serious data breach liability and should be remedied immediately.

  2. Which approach to risk prioritization weighs both the probability of occurrence and the magnitude of impact?

    Answer: Risk scoring matrix

    A risk scoring matrix assigns numerical values to likelihood and impact, enabling organizations to rank and prioritize risks objectively.

  3. An executive director is informed of allegations of staff misconduct. The risk management response that best protects the organization is to:

    Answer: Immediately conduct a documented investigation following HR policy

    A prompt, documented investigation following established HR policy protects the organization from legal liability and demonstrates due diligence.

  4. Succession planning for the executive director role is primarily a risk management strategy addressing:

    Answer: Key person dependency and leadership continuity risk

    Succession planning ensures organizational leadership can continue effectively if the executive director departs unexpectedly.

  5. When a risk event occurs that was not in the organization's risk register, the executive director should FIRST:

    Answer: Add it to the register and assess likelihood and impact for future planning

    Unplanned risk events should be added to the risk register and assessed so the organization learns and improves its risk identification process.

  6. Which best describes the relationship between risk tolerance and risk appetite in organizational management?

    Answer: Risk appetite is the broad willingness to take risk; risk tolerance sets specific acceptable variation limits

    Risk appetite defines the overall level of risk an organization will pursue, while risk tolerance specifies acceptable deviations from targets within that appetite.

  7. A nonprofit is considering a merger with another organization. Which category of risk is MOST unique to this strategic decision?

    Answer: Integration risk from cultural, financial, and mission alignment challenges

    Mergers carry distinct integration risks including misaligned cultures, duplicate systems, and unclear mission fit that can undermine the combined organization.