Risk Assessment & Management Flashcards
7 cards from real Certified Public Accountant practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Assessment & Management flashcards as text
Which of the following best describes 'risk appetite' in the context of enterprise risk management?
Answer: The amount of risk an entity is willing to accept in pursuit of its objectives
Risk appetite is the broad amount of risk an entity is willing to accept in pursuit of value, established by the board and senior management.
A control that detects errors after they have already occurred is classified as a:
Answer: Detective control
Detective controls are designed to identify errors or irregularities that have already occurred, such as account reconciliations or exception reports.
Which scenario best illustrates the risk of 'concentration risk'?
Answer: A manufacturer sources 90% of a critical component from a single supplier
Concentration risk arises when a company is overly dependent on a single source, customer, supplier, or geography, increasing vulnerability to disruption.
Under AU-C Section 315, when must an auditor perform risk assessment procedures?
Answer: Throughout the planning phase and early fieldwork
AU-C 315 requires auditors to perform risk assessment procedures during planning to obtain an understanding of the entity and its environment, including internal controls.
A company discovers that its fraud risk assessments did not consider the risk of management override of controls. This represents a gap in which COSO Internal Control component?
Answer: Risk Assessment
Risk Assessment in the COSO framework requires identifying and analyzing risks to achieving objectives, including the risk of management override and fraud.
Which measure best quantifies the potential loss from a risk at a specific confidence level over a defined time horizon?
Answer: Value at Risk (VaR)
Value at Risk (VaR) quantifies the maximum expected loss over a defined period at a given confidence level (e.g., 95% or 99%).
When evaluating the severity of a risk, which two dimensions are typically used?
Answer: Likelihood and impact
Risk severity is most commonly assessed using likelihood (probability of occurrence) and impact (magnitude of effect if the risk occurs).