Risk Management & Internal Controls Flashcards
7 cards from real CFE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Management & Internal Controls flashcards as text
Which NAIC model regulation requires insurance holding companies to maintain an Own Risk and Solvency Assessment (ORSA)?
Answer: Risk Management and Own Risk and Solvency Assessment Model Act
The NAIC Risk Management and Own Risk and Solvency Assessment (ORSA) Model Act requires qualifying insurers to conduct and document an internal assessment of their risk and capital needs.
A heat map is used in risk management to visually display:
Answer: The relative position of risks by likelihood and impact
A heat map plots identified risks on a grid of likelihood versus impact, allowing management to visually prioritize which risks require the most attention.
In the context of insurance financial examination, 'inherent risk' refers to:
Answer: Risk arising from the nature of the account or activity before controls are considered
Inherent risk is the susceptibility of an account or process to material misstatement before considering the effectiveness of internal controls.
Which control is an example of a PREVENTIVE control in an insurance company's claims department?
Answer: Requiring two approvals before issuing a claims payment above a threshold
Requiring dual approval before issuing large claims payments is a preventive control because it stops unauthorized or erroneous payments from occurring in the first place.
When evaluating an insurer's liquidity risk, a financial examiner would MOST likely focus on which metric?
Answer: Cash flow adequacy and the ability to meet policyholder obligations as they come due
Liquidity risk assessment focuses on whether the insurer can meet its policyholder and other obligations on time without having to liquidate assets at a loss.
An insurance company relies on a single vendor for its claims processing system. This situation MOST directly creates which type of risk?
Answer: Concentration risk / vendor dependency risk
Relying on a single vendor for a critical function creates concentration risk, meaning a failure of that vendor could severely disrupt the insurer's operations.
A financial examiner reviews an insurer's business continuity plan (BCP). The PRIMARY objective of a BCP from a risk management perspective is to:
Answer: Ensure the organization can continue critical functions after a disruptive event
A business continuity plan ensures that critical business functions can be maintained or quickly restored following a disruption such as a disaster or system failure.