Risk Assessment & Management Flashcards
6 cards from real Certified Internal Auditor practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Risk Assessment & Management flashcards as text
What is the COSO Internal Control Framework?
Answer: A framework defining five components of internal control: control environment, risk assessment, control activities, information/communication, and monitoring
The COSO framework provides a comprehensive model for internal controls with five interrelated components that help organizations achieve objectives related to operations, reporting, and compliance.
What is inherent risk versus residual risk?
Answer: Inherent risk exists before controls; residual risk remains after controls are applied
Inherent risk is the level of risk present before any controls are implemented, while residual risk is the risk remaining after management applies controls and mitigation measures.
What is a risk-based audit plan?
Answer: An audit plan prioritized by the organization's most significant risks rather than auditing everything equally
A risk-based audit plan allocates audit resources to areas of highest risk, ensuring the most significant threats to organizational objectives receive audit attention first.
What is the three lines of defense model in risk management?
Answer: First line: operational management; Second line: risk/compliance functions; Third line: internal audit
The three lines model assigns risk management roles: operational management owns and manages risk (1st), risk and compliance functions provide oversight (2nd), and internal audit provides independent assurance (3rd).
How should internal auditors assess fraud risk?
Answer: By evaluating the fraud triangle elements: opportunity, pressure/incentive, and rationalization
Internal auditors assess fraud risk by evaluating the three elements of the fraud triangle — opportunity (weak controls), pressure (financial or personal), and rationalization (justification) — during all engagements.
What is a risk appetite statement?
Answer: A board-level declaration of the amount of risk an organization is willing to accept in pursuit of its objectives
A risk appetite statement, set by the board, defines the types and levels of risk the organization is willing to accept, providing guidance for management decision-making.