Risk Management & Internal Controls Flashcards
7 cards from real CFE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Management & Internal Controls flashcards as text
Under the COSO ERM framework, which component involves identifying potential events that could affect an organization's ability to achieve its objectives?
Answer: Event Identification
Event Identification is the COSO ERM component focused on recognizing potential events—both internal and external—that could impact achievement of objectives.
A financial examiner discovers that a company's management has the ability to override established internal controls. This situation MOST directly threatens which objective of internal controls?
Answer: Reliability of financial reporting
Management override of controls most directly undermines the reliability of financial reporting, as it creates a pathway for intentional misstatement.
A residual risk level that exceeds an organization's risk appetite should MOST appropriately trigger which action?
Answer: Implementing additional controls or revising risk response
When residual risk exceeds risk appetite, management must implement additional controls or adjust the risk response strategy to bring exposure within acceptable limits.
Which type of insurance mechanism allows an insurer to limit exposure by passing a portion of risk to another insurer?
Answer: Reinsurance
Reinsurance is the mechanism by which an insurer transfers a portion of its risk exposure to a reinsurer to limit its own potential losses.
During an examination of an insurance company, which internal control is MOST effective at detecting unauthorized changes to policy reserve calculations?
Answer: Periodic reconciliation of reserve reports to the general ledger
Periodic reconciliation of reserve reports to the general ledger is a detective control that identifies discrepancies between actuarial records and financial records.
The 'three lines of defense' model assigns internal audit to which line?
Answer: Third line
Internal audit occupies the third line of defense, providing independent assurance over the effectiveness of risk management and control activities.
A key risk indicator (KRI) that shows a metric approaching a threshold level MOST likely serves what purpose for management?
Answer: Providing an early warning signal for emerging risks
KRIs provide early warning signals, alerting management when risk exposure is trending toward an unacceptable level before a loss event occurs.