โ† All CRM Flashcard Decks

Risk Assessment & Mitigation Flashcards

7 cards from real CRM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Assessment & Mitigation flashcards as text
  1. Which risk indicator would MOST likely trigger a records manager to conduct an unscheduled risk reassessment?

    Answer: A major merger, acquisition, or organizational restructuring

    Major organizational changes such as mergers or restructuring significantly alter the records risk landscape and warrant an immediate reassessment.

  2. A risk heat map is used in records management primarily to:

    Answer: Visually prioritize risks by likelihood and impact

    A risk heat map plots risks on a grid of probability versus impact, enabling managers to visually identify and prioritize the most critical risks.

  3. Which of the following is an example of risk transfer in a records management context?

    Answer: Purchasing cyber liability insurance to cover a data breach

    Risk transfer shifts the financial consequences of a risk to a third party, such as an insurer, rather than eliminating the risk itself.

  4. A records manager is evaluating the risk of a legacy records system becoming unsupported. This is classified as which type of risk?

    Answer: Technological obsolescence risk

    Technological obsolescence risk occurs when systems or media formats become outdated, threatening the accessibility and integrity of records over time.

  5. When a risk assessment reveals a low-probability, low-impact risk, the MOST appropriate response is typically to:

    Answer: Accept the risk and monitor it periodically

    Low-probability, low-impact risks are generally accepted and placed on a watch list for periodic monitoring rather than requiring costly immediate action.

  6. Which standard provides the most comprehensive international guidance on risk management that records managers should align with?

    Answer: ISO 31000

    ISO 31000 provides principles and guidelines for risk management applicable across all sectors and is widely used to structure records risk programs.

  7. A records manager discovers employees are storing records on personal cloud accounts. Which risk does this PRIMARILY represent?

    Answer: Data sovereignty and security risk

    Personal cloud storage creates data sovereignty and security risks because organizational records are outside IT governance, encryption controls, and jurisdictional oversight.