Certified Risk Manager (CRM) Exam — Questions and Answers
Question 1: What is the primary purpose of a Business Continuity Plan (BCP)?
- To ensure critical business functions continue during and after a disruption (Correct answer)
- To eliminate all risks associated with business operations
- To document all financial losses from a disaster event
- To provide employee training on workplace safety procedures
Correct answer: To ensure critical business functions continue during and after a disruption
A BCP is designed to maintain critical business operations during and after a disruption, minimizing downtime and financial impact.
Question 2: What is the primary purpose of commercial property insurance for a business?
- To protect against regulatory penalties
- To cover physical assets against loss or damage (Correct answer)
- To fund employee retirement plans
- To provide liability protection for employees
Correct answer: To cover physical assets against loss or damage
Commercial property insurance protects a business's physical assets, including buildings and equipment, from covered perils.
Question 3: What does 'total cost of risk' (TCOR) include?
- Insurance premiums, retained losses, risk management costs, and indirect costs (Correct answer)
- Only actual losses incurred
- Only insurance premiums paid
- Only administrative overhead
Correct answer: Insurance premiums, retained losses, risk management costs, and indirect costs
TCOR is a comprehensive measure that includes premiums, retained losses, risk management administrative costs, and indirect costs like lost productivity.
Question 4: What is the foundational principle of continuing education requirements in the Certified Relationship Manager field?
- Avoiding all challenging situations
- Following the easiest path available
- Maintaining competence, integrity, and service to stakeholders (Correct answer)
- Maximizing personal advancement
Correct answer: Maintaining competence, integrity, and service to stakeholders
The foundational principles of continuing education requirements in Certified Relationship Manager center on maintaining competence, integrity, and quality service.
Question 5: The 'three lines of defense' model in ERM assigns the first line to:
- Internal audit
- Risk management function
- Board of directors
- Operational management (Correct answer)
Correct answer: Operational management
In the three lines of defense model, operational management owns and manages risk as the first line of defense.
Question 6: Why is testing controls important in risk mitigation?
- To delay audits.
- To validate the effectiveness of risk controls. (Correct answer)
- To reduce employee morale.
- To eliminate all risks.
Correct answer: To validate the effectiveness of risk controls.
Testing controls is essential to ensure they are functioning as intended and are effective in mitigating identified risks. Regular testing helps identify weaknesses, gaps, or malfunctions in controls before a risk event occurs. This validation process allows for necessary adjustments and improvements, strengthening the overall risk management framework.
Question 7: Which international standard provides comprehensive guidance on Business Continuity Management Systems?
- ISO 27001
- ISO 22301 (Correct answer)
- ISO 9001
- ISO 31000
Correct answer: ISO 22301
ISO 22301 is the international standard specifically for Business Continuity Management Systems, specifying requirements for planning, establishing, implementing, and improving BCM.
Question 8: Which of the following best describes a proactive risk control?
- Issuing a public apology.
- Responding after a breach.
- Filing an insurance claim.
- Installing fire alarms in advance. (Correct answer)
Correct answer: Installing fire alarms in advance.
A proactive risk control is implemented before a risk event occurs, aiming to prevent it or reduce its potential impact. Installing fire alarms is a classic example, as it's done in anticipation of a fire to provide early warning and facilitate a response. This contrasts with reactive measures taken after an incident has already occurred.
Question 9: What does 'subrogation' mean in insurance?
- The insured's right to cancel a policy
- A premium discount for good loss history
- The process of filing a claim
- The insurer's right to pursue a third party that caused an insurance loss (Correct answer)
Correct answer: The insurer's right to pursue a third party that caused an insurance loss
Subrogation allows an insurer who has paid a claim to pursue recovery from the responsible third party.
Question 10: What ethical standard governs continuing education requirements practice?
- Ethics are personal opinions, not professional requirements
- Adherence to the profession's code of ethics and applicable laws and regulations (Correct answer)
- Ethical standards are optional for certified professionals
- Ethics only apply in academic settings
Correct answer: Adherence to the profession's code of ethics and applicable laws and regulations
Professional ethics codes and applicable laws provide the framework for ethical practice in every professional field.
Question 11: How should challenges in core concepts and principles be addressed?
- Avoid challenges and stick to familiar tasks
- Apply systematic problem-solving, seek expert guidance when needed, and document decisions (Correct answer)
- Ignore challenges until they resolve themselves
- Delegate all challenges to supervisors
Correct answer: Apply systematic problem-solving, seek expert guidance when needed, and document decisions
Systematic problem-solving combined with appropriate consultation and documentation ensures challenges are addressed effectively.
Question 12: In risk terminology, what does 'inherent risk' refer to?
- Risk left after implementing controls
- Risk before controls are in place (Correct answer)
- Risks accepted by management
- The most critical identified risk
Correct answer: Risk before controls are in place
In risk terminology, 'inherent risk' refers to the level of risk that exists before any internal controls or other mitigating factors have been implemented. It represents the raw, unmitigated risk exposure an organization faces from a particular activity or threat. Understanding inherent risk is crucial for designing and implementing appropriate control measures.
Question 13: What is a commercial 'umbrella policy'?
- A policy that covers outdoor business events
- Insurance for seasonal business fluctuations
- Excess liability coverage that extends limits beyond primary policies (Correct answer)
- A bundled property and casualty policy
Correct answer: Excess liability coverage that extends limits beyond primary policies
A commercial umbrella policy provides additional liability limits above and beyond primary insurance policies, covering catastrophic losses.
Question 14: Residual risk is defined as:
- Risk remaining after controls (Correct answer)
- The original unmitigated risk
- Risk transferred to another entity
- Risk accepted by stakeholders
Correct answer: Risk remaining after controls
Residual risk is defined as the amount of risk that remains after an organization has implemented risk mitigation strategies and controls. It is the risk that management has either accepted, transferred, or reduced to an acceptable level, but which has not been entirely eliminated. Organizations must continuously monitor and manage these remaining risks.
Question 15: What distinguishes 'operational risk' from financial risk in enterprise risk management?
- Operational risk only involves employee actions
- Operational risk arises from failures in internal processes, people, systems, or external events (Correct answer)
- Operational risk is always insurable
- Operational risk only affects manufacturing companies
Correct answer: Operational risk arises from failures in internal processes, people, systems, or external events
Operational risk encompasses losses from failed internal processes, human error, systems failures, or external events, distinct from market or credit risk.
Question 16: What is the primary benefit of conducting a risk assessment?
- To comply with all regulations
- To identify and prioritize risks (Correct answer)
- To reduce operational costs
- To eliminate all risks
Correct answer: To identify and prioritize risks
The primary benefit of conducting a risk assessment is to identify and prioritize risks. This systematic process helps organizations discover potential threats and opportunities, evaluate their likelihood and impact, and then rank them based on their significance. This enables effective resource allocation, focusing attention on the most critical areas to protect organizational objectives.
Question 17: What is scenario analysis in the context of ERM?
- Reviewing regulatory compliance reports
- Analyzing competitor risk strategies
- Reviewing past insurance claims
- Evaluating potential future events and their impact on the organization (Correct answer)
Correct answer: Evaluating potential future events and their impact on the organization
Scenario analysis examines plausible future events to understand potential impacts and test organizational resilience.
Question 18: What is a risk register used for?
- To manage human resources.
- To maintain equipment logs.
- To record financial statements.
- To track and document identified risks. (Correct answer)
Correct answer: To track and document identified risks.
A risk register is a central repository used to systematically track and document all identified risks within an organization or project. It typically includes details such as risk descriptions, likelihood, impact, mitigation strategies, owners, and current status. This tool provides a comprehensive overview of the risk landscape, enabling effective management and communication.
Question 19: How can risk be reduced through training programs?
- By ensuring employees are prepared to prevent risks. (Correct answer)
- By outsourcing risk decisions.
- By replacing risk analysis with instinct.
- By minimizing team size.
Correct answer: By ensuring employees are prepared to prevent risks.
Training programs enhance employees' knowledge, skills, and awareness regarding potential risks and appropriate preventative measures. Well-trained staff are better equipped to identify hazards, follow safety protocols, and respond effectively to emerging threats, thereby directly reducing the likelihood and impact of risk events. This proactive approach empowers individuals to contribute to risk reduction.
Question 20: Which liability coverage protects a business against claims arising from its products after they leave the premises?
- Employer liability
- Premises liability
- Professional liability
- Products liability (Correct answer)
Correct answer: Products liability
Products liability coverage protects manufacturers and sellers against claims arising from harm caused by their products.
Question 21: How should professionals apply core concepts and principles in daily practice?
- Apply principles selectively based on convenience
- Only when being evaluated
- Follow standards only for complex tasks
- Consistently integrate best practices into every aspect of professional work (Correct answer)
Correct answer: Consistently integrate best practices into every aspect of professional work
Consistent application of professional standards ensures quality outcomes and builds professional credibility.
Question 22: Which of the following is a risk transfer technique?
- Hazard elimination
- Control implementation
- Insurance policy (Correct answer)
- Risk acceptance
Correct answer: Insurance policy
Risk transfer is a strategy where the financial consequences of a potential risk are shifted to a third party. An insurance policy is a classic example of this technique, as the insurer agrees to compensate the policyholder for specified losses in exchange for premiums. This allows the organization to mitigate its direct financial exposure to certain risks.
Question 23: What is a 'self-insured retention' (SIR) in a commercial liability policy?
- The maximum premium the insured will pay
- A reserve fund maintained by the insurer
- The policy's automatic renewal provision
- The amount an insured pays per claim before the insurer responds (Correct answer)
Correct answer: The amount an insured pays per claim before the insurer responds
An SIR is the amount the insured must pay for each claim before the insurance company begins contributing to the loss.
Question 24: How should core concepts and principles knowledge be maintained and updated?
- Through continuous professional development, current literature review, and professional networking (Correct answer)
- Knowledge updates are only needed every five years
- Initial training provides lifelong competence
- Learning stops after certification
Correct answer: Through continuous professional development, current literature review, and professional networking
Professional competence requires ongoing development through education, literature review, and engagement with the professional community.
Question 25: How should communication and documentation knowledge be maintained and updated?
- Through continuous professional development, current literature review, and professional networking (Correct answer)
- Initial training provides lifelong competence
- Knowledge updates are only needed every five years
- Learning stops after certification
Correct answer: Through continuous professional development, current literature review, and professional networking
Professional competence requires ongoing development through education, literature review, and engagement with the professional community.
Question 26: Which of the following is a quantitative risk assessment technique used in ERM?
- Monte Carlo simulation (Correct answer)
- SWOT Analysis
- Delphi method
- Brainstorming
Correct answer: Monte Carlo simulation
Monte Carlo simulation uses statistical modeling to quantify the probability distribution of possible outcomes and risk impacts.
Question 27: Which of the following is an example of a physical control?
- Financial audit policy.
- Security camera installation. (Correct answer)
- Employee code of conduct.
- Project budgeting guideline.
Correct answer: Security camera installation.
A physical control is a tangible measure designed to prevent or deter unauthorized access, damage, or theft of assets. Installing security cameras directly fits this definition by providing surveillance and acting as a visible deterrent. It physically protects an environment or asset, unlike policies or guidelines which are administrative.
Question 28: What is the goal of risk control?
- To create risks for competitors.
- To avoid stakeholder engagement.
- To eliminate business objectives.
- To reduce the frequency or severity of risks. (Correct answer)
Correct answer: To reduce the frequency or severity of risks.
The primary goal of risk control is to implement measures that either prevent risks from occurring (reducing frequency) or lessen their negative impact if they do materialize (reducing severity). This proactive approach aims to protect an organization's assets, operations, and objectives from potential harm. Effective risk control helps maintain business continuity and minimize losses.
Question 29: What ethical standard governs communication and documentation practice?
- Ethics only apply in academic settings
- Ethics are personal opinions, not professional requirements
- Adherence to the profession's code of ethics and applicable laws and regulations (Correct answer)
- Ethical standards are optional for certified professionals
Correct answer: Adherence to the profession's code of ethics and applicable laws and regulations
Professional ethics codes and applicable laws provide the framework for ethical practice in every professional field.
Question 30: What is 'moral hazard' in insurance?
- The tendency of insured parties to take greater risks because losses are covered (Correct answer)
- Fraudulent misrepresentation on an insurance application
- The risk of natural disasters causing catastrophic losses
- The risk that an insurer will become insolvent
Correct answer: The tendency of insured parties to take greater risks because losses are covered
Moral hazard occurs when insurance coverage reduces an insured's incentive to prevent losses or act carefully.
Question 31: Which source is typically used to identify risks?
- Past project records. (Correct answer)
- Stakeholder feedback.
- Market advertisements.
- Personal opinions.
Correct answer: Past project records.
Past project records, including lessons learned, incident reports, and historical data, are invaluable sources for identifying potential risks. By reviewing previous experiences, organizations can anticipate similar challenges, understand common pitfalls, and leverage insights to proactively identify and mitigate risks in current or future endeavors. This historical perspective provides empirical evidence for risk identification.
Question 32: What type of control is a company policy that limits access to data?
- Administrative control. (Correct answer)
- Physical control.
- Technical control.
- Informal control.
Correct answer: Administrative control.
An administrative control is a policy, procedure, or guideline established by management to govern behavior and manage risk. A company policy limiting data access falls under this category as it defines rules and responsibilities for information security. It's not a technical solution (like software) or a physical barrier (like a lock).
Question 33: What ethical standard governs core concepts and principles practice?
- Adherence to the profession's code of ethics and applicable laws and regulations (Correct answer)
- Ethical standards are optional for certified professionals
- Ethics only apply in academic settings
- Ethics are personal opinions, not professional requirements
Correct answer: Adherence to the profession's code of ethics and applicable laws and regulations
Professional ethics codes and applicable laws provide the framework for ethical practice in every professional field.
Question 34: What is the benefit of using visual tools in risk reporting?
- They simplify complex risk information. (Correct answer)
- They make reports look colorful.
- They increase report size.
- They confuse the audience.
Correct answer: They simplify complex risk information.
Visual tools like charts, graphs, and dashboards can present complex risk data in an easily digestible and understandable format. They help stakeholders quickly grasp key trends, priorities, and relationships, making it easier to identify critical issues and make informed decisions. This enhances comprehension and engagement compared to dense textual reports.
Question 35: How should professionals apply assessment and evaluation in daily practice?
- Follow standards only for complex tasks
- Only when being evaluated
- Apply principles selectively based on convenience
- Consistently integrate best practices into every aspect of professional work (Correct answer)
Correct answer: Consistently integrate best practices into every aspect of professional work
Consistent application of professional standards ensures quality outcomes and builds professional credibility.
Question 36: Which technique is commonly used during the risk identification phase?
- Brainstorming. (Correct answer)
- Control charting.
- Critical path analysis.
- Benchmarking.
Correct answer: Brainstorming.
Brainstorming is a commonly used and highly effective technique during the risk identification phase. It involves a group of stakeholders collaboratively generating a comprehensive list of potential risks, encouraging creative thinking and diverse perspectives. This method helps uncover a wide range of threats and opportunities that might impact objectives.
Question 37: Which document outlines an organization's approach to managing risk?
- Risk management policy (Correct answer)
- Risk register
- Operational handbook
- Code of ethics
Correct answer: Risk management policy
A risk management policy is a formal document that outlines an organization's overall philosophy, objectives, and approach to managing risk. It establishes the framework, roles, responsibilities, and processes for identifying, assessing, treating, monitoring, and communicating risks across the organization. This policy provides the guiding principles for all risk-related activities.
Question 38: What is the first step in the risk management process?
- Monitor and review controls.
- Implement control measures.
- Identify potential risks. (Correct answer)
- Evaluate the risks.
Correct answer: Identify potential risks.
The first step in the risk management process is to identify potential risks. This involves systematically determining what events or circumstances could negatively impact an organization's objectives. Without first identifying these risks, it is impossible to effectively evaluate, treat, or monitor them, making this a foundational and critical initial step.
Question 39: Which strategy is used when an organization decides not to engage in a high-risk activity?
- Risk transfer
- Risk avoidance (Correct answer)
- Risk acceptance
- Risk reduction
Correct answer: Risk avoidance
Risk avoidance is a strategy where an organization decides not to engage in an activity or project that carries a high level of unacceptable risk. By eliminating the source of the risk entirely, the organization prevents the potential negative consequences from occurring. This differs from other strategies like reduction or transfer, which involve managing existing risks.
Question 40: What is the foundational principle of core concepts and principles in the Certified Relationship Manager field?
- Maximizing personal advancement
- Following the easiest path available
- Avoiding all challenging situations
- Maintaining competence, integrity, and service to stakeholders (Correct answer)
Correct answer: Maintaining competence, integrity, and service to stakeholders
The foundational principles of core concepts and principles in Certified Relationship Manager center on maintaining competence, integrity, and quality service.
Question 41: What does 'loss frequency' refer to in insurance and risk management?
- The severity of individual losses
- How often losses occur within a given period (Correct answer)
- The number of insurance policies held
- The total annual premium paid
Correct answer: How often losses occur within a given period
Loss frequency measures how often loss events occur, which helps predict future losses and set appropriate premiums.
Question 42: What does 'risk mitigation' typically involve?
- Escalating the risk.
- Reassigning project leaders.
- Reducing the impact of a risk event. (Correct answer)
- Ignoring the risk.
Correct answer: Reducing the impact of a risk event.
Risk mitigation involves taking actions to lessen the potential negative consequences or likelihood of an identified risk. While it can also aim to reduce the probability, its core focus is often on minimizing the damage or disruption if the risk materializes. This makes the risk more manageable and less costly to the organization.
Question 43: What is the primary goal of risk evaluation?
- To assign risk owners.
- To create contingency plans.
- To eliminate all risks.
- To prioritize risks based on impact and likelihood. (Correct answer)
Correct answer: To prioritize risks based on impact and likelihood.
The primary goal of risk evaluation is to prioritize risks based on their potential impact and likelihood of occurrence. This assessment allows organizations to determine the significance of identified risks, enabling them to allocate resources effectively to the most critical areas. It informs decision-making regarding which risks require immediate attention and treatment.
Question 44: What does 'control environment' refer to in risk mitigation?
- Market competition level.
- Physical building conditions.
- Only the IT infrastructure.
- Organizational culture and structure. (Correct answer)
Correct answer: Organizational culture and structure.
The 'control environment' refers to the overall attitude, awareness, and actions of management and the board of directors regarding internal controls and their importance. It encompasses the ethical values, competence, organizational structure, and assignment of authority and responsibility within an entity. Essentially, it sets the tone at the top for risk management.
Question 45: Workers' compensation insurance provides coverage for:
- Customer injuries on business premises
- Director and officer liability
- Employee injuries or illnesses arising from employment (Correct answer)
- Property damage caused by employees
Correct answer: Employee injuries or illnesses arising from employment
Workers' compensation covers medical expenses and lost wages for employees injured or made ill in the course of their employment.
Question 46: In risk evaluation, what does 'likelihood' refer to?
- How much a risk will cost.
- The probability that a risk event will occur. (Correct answer)
- The risk owner's preferences.
- The severity of a risk's impact.
Correct answer: The probability that a risk event will occur.
In risk evaluation, 'likelihood' refers to the probability or frequency with which a specific risk event is expected to occur. It assesses how often a threat might materialize, often expressed qualitatively (e.g., rare, likely) or quantitatively (e.g., a percentage). Understanding likelihood is crucial for assessing the overall significance of a risk.
Question 47: What ethical standard governs assessment and evaluation practice?
- Adherence to the profession's code of ethics and applicable laws and regulations (Correct answer)
- Ethics are personal opinions, not professional requirements
- Ethical standards are optional for certified professionals
- Ethics only apply in academic settings
Correct answer: Adherence to the profession's code of ethics and applicable laws and regulations
Professional ethics codes and applicable laws provide the framework for ethical practice in every professional field.
Question 48: How does redundancy help in risk mitigation?
- It confuses the workflow.
- It eliminates the need for training.
- It ensures operations continue if the primary system fails. (Correct answer)
- It increases costs with no benefits.
Correct answer: It ensures operations continue if the primary system fails.
Redundancy is a risk mitigation strategy that involves duplicating critical components or systems. Its purpose is to provide a backup or alternative pathway, ensuring that if one part fails, the system or operation can continue without interruption. This significantly enhances resilience and reduces the impact of single points of failure.
Question 49: Which ERM approach considers both upside opportunities and downside threats?
- Enterprise Risk Management (Correct answer)
- Insurance-centric risk management
- Traditional risk management
- Operational risk management
Correct answer: Enterprise Risk Management
ERM uniquely considers both upside opportunities and downside threats, unlike traditional risk management which focuses mainly on losses.
Question 50: How should challenges in assessment and evaluation be addressed?
- Avoid challenges and stick to familiar tasks
- Ignore challenges until they resolve themselves
- Apply systematic problem-solving, seek expert guidance when needed, and document decisions (Correct answer)
- Delegate all challenges to supervisors
Correct answer: Apply systematic problem-solving, seek expert guidance when needed, and document decisions
Systematic problem-solving combined with appropriate consultation and documentation ensures challenges are addressed effectively.
Certified Risk Manager (CRM) Exam
The CRM program consists of five courses and exams, each focusing on a specific aspect of risk management. The overall certification requires passing all five.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds