ARM - Associate in Risk Management — Questions and Answers
Question 1: A plastics manufacturing plant experiences a fire that severely damages its primary production line, forcing a shutdown for three months. While property insurance covers the cost to repair the machinery, the company loses $5 million in profits and incurs extra expenses to outsource some production temporarily. These lost profits and extra expenses are classified as what type of loss?
- Asset depreciation loss
- Business income (interruption) loss (Correct answer)
- General liability loss
- Direct loss
Correct answer: Business income (interruption) loss
A business income loss, also known as business interruption, is an indirect or consequential loss. It results from a direct loss (the physical damage from the fire) and is designed to cover the net income that would have been earned and any continuing normal operating expenses. Direct loss refers only to the physical damage to the property itself.
Question 2: What distinguishes a disaster recovery plan from a business continuity plan?
- Disaster recovery applies only to financial institutions
- There is no distinction between the two plans
- Disaster recovery focuses on preventing disasters while BCP focuses on response
- Disaster recovery specifically addresses IT and technology restoration, while BCP covers all critical business functions (Correct answer)
Correct answer: Disaster recovery specifically addresses IT and technology restoration, while BCP covers all critical business functions
Disaster recovery focuses primarily on restoring IT systems and data, while a BCP encompasses the full range of critical business operations.
Question 3: An organization is implementing multi-factor authentication (MFA) as a security control. This measure is primarily designed to mitigate the risk associated with what common cyber threat?
- Compromised credentials (Correct answer)
- Unpatched software vulnerabilities
- Distributed Denial-of-Service (DDoS) attacks
- Fileless malware
Correct answer: Compromised credentials
Multi-factor authentication (MFA) requires a user to provide two or more verification factors to gain access to a resource. Its primary purpose is to add another layer of security beyond just a password. If a user's password (their credential) is stolen or compromised, MFA prevents an attacker from using it to gain unauthorized access because they would still need the second factor (e.g., a code from a mobile app).
Question 4: A key principle of a holistic risk assessment is the recognition that risks are often interconnected and can cascade across an organization. Which of the following best describes this principle?
- Comprehensiveness
- Siloed Analysis
- Interconnectedness (Correct answer)
- Systemic Perspective
Correct answer: Interconnectedness
The principle of interconnectedness explicitly acknowledges that risks are rarely isolated events; they are often linked and can impact different parts of an organization. This is a core concept in holistic risk assessment, which moves away from viewing risks in isolation (siloed analysis).
Question 5: What is the difference between inherent and residual risk?
- Inherent risk is always lower than residual risk.
- Residual risk refers to unidentified risks.
- Residual risk remains after mitigation measures. (Correct answer)
- Inherent risk is eliminated through assessment.
Correct answer: Residual risk remains after mitigation measures.
Inherent risk is the level of risk before any risk control measures have been applied. Residual risk, on the other hand, is the risk that remains after an organization has implemented its risk mitigation strategies, controls, and other treatments. It represents the remaining exposure that the organization accepts or has not yet fully addressed.
Question 6: Liquidity risk in financial risk management refers to:
- The risk that an organization cannot easily buy or sell an asset without significantly affecting its price, or cannot meet short-term obligations (Correct answer)
- The probability that a company's stock will be delisted from an exchange
- The risk that cash reserves will earn below-inflation returns
- The chance that customers will pay their invoices late
Correct answer: The risk that an organization cannot easily buy or sell an asset without significantly affecting its price, or cannot meet short-term obligations
Liquidity risk encompasses both the inability to convert assets to cash at fair value (market liquidity risk) and the inability to fund obligations when due (funding liquidity risk).
Question 7: In a holistic approach to risk, senior management's role is critical. What is one of their primary responsibilities in establishing a holistic framework?
- Personally investigating every minor operational failure.
- Conducting daily risk monitoring for every department.
- Selecting the insurance broker for every individual policy.
- Establishing the organization's overall risk appetite and cascading it down through the organization. (Correct answer)
Correct answer: Establishing the organization's overall risk appetite and cascading it down through the organization.
A key aspect of a holistic or ERM approach is that senior management establishes the enterprise's appetite for risk in the context of its strategic objectives. They then determine how to communicate and implement this appetite down through the organization via risk tolerances and limits.
Question 8: What is the purpose of a risk heat map?
- To visually assess risk impact and likelihood. (Correct answer)
- To eliminate all risks.
- To replace traditional risk assessments.
- To assign blame for risk occurrences.
Correct answer: To visually assess risk impact and likelihood.
A risk heat map is a visual tool used to plot identified risks based on their likelihood of occurrence and their potential impact. This graphical representation helps organizations quickly prioritize risks, as those falling into the 'high impact, high likelihood' quadrant are immediately visible as critical. It provides a clear, concise overview for decision-makers to understand the overall risk landscape.
Question 9: Effective supply chain resilience strategies most commonly include:
- Reducing inventory to zero to improve efficiency
- Consolidating to a single supplier for lower costs
- Diversifying suppliers, maintaining safety stock, and building alternative sourcing arrangements (Correct answer)
- Eliminating all international sourcing
Correct answer: Diversifying suppliers, maintaining safety stock, and building alternative sourcing arrangements
Supply chain resilience requires redundancy through supplier diversification, buffer inventory, and pre-established alternative sourcing to withstand disruptions.
Question 10: Which of the following is a primary goal of adopting a holistic risk assessment framework over a traditional, fragmented approach?
- To assign blame for risk events more efficiently.
- To understand the interrelationships among risks and optimize the overall risk management strategy. (Correct answer)
- To focus exclusively on insurable financial risks.
- To eliminate the need for departmental risk managers.
Correct answer: To understand the interrelationships among risks and optimize the overall risk management strategy.
A holistic approach, often associated with Enterprise Risk Management (ERM), aims to understand the interrelationships between various risks to manage them in a coordinated way. This enterprise-level, portfolio view helps optimize the overall risk management performance rather than managing risks in isolated functional or departmental silos.
Question 11: Which of the following is an example of risk retention?
- Purchasing additional insurance coverage.
- Setting aside financial reserves for potential losses. (Correct answer)
- Transferring risk to a third party.
- Ignoring financial risks entirely.
Correct answer: Setting aside financial reserves for potential losses.
Risk retention occurs when an organization chooses to accept the financial burden of a potential loss rather than transferring it to another party (like an insurer) or avoiding the risk. Setting aside financial reserves, such as a self-insurance fund or contingency budget, is a classic example of planned risk retention, preparing the organization to cover losses internally.
Question 12: Which international standard provides guidance on business continuity management systems?
- ISO 14001
- ISO 22301 (Correct answer)
- ISO 9001
- ISO 31000
Correct answer: ISO 22301
ISO 22301 is the international standard specifically designed to specify requirements for a business continuity management system (BCMS).
Question 13: What is the purpose of risk avoidance in risk control?
- Accepting all risks without action.
- Eliminating exposure to specific risks. (Correct answer)
- Minimizing insurance costs.
- Reducing the impact of an unavoidable risk.
Correct answer: Eliminating exposure to specific risks.
Risk avoidance is a strategy where an organization decides not to undertake an activity or engage in a situation that carries a specific risk. By completely avoiding the source of the risk, the organization eliminates its exposure to that particular threat. This is distinct from mitigation, which aims to reduce the risk rather than remove it entirely.
Question 14: Credit rating agencies such as Moody's and S&P primarily assess:
- Environmental and social governance scores for ESG investors
- The market liquidity of publicly traded securities
- The relative creditworthiness and probability of default of debt issuers and their instruments (Correct answer)
- A borrower's operational efficiency and production capacity
Correct answer: The relative creditworthiness and probability of default of debt issuers and their instruments
Credit rating agencies evaluate the financial health and default risk of issuers, providing letter-grade ratings that investors and lenders use to price credit risk.
Question 15: Which factor is most important when assessing risk severity?
- The potential impact of the risk. (Correct answer)
- The ease of transferring the risk to another party.
- The speed at which the risk occurs.
- The likelihood of the risk occurring.
Correct answer: The potential impact of the risk.
Risk severity refers to the magnitude of harm or loss that a risk could cause if it materializes. While likelihood (probability) is also a critical factor in risk assessment, severity specifically measures the consequence or impact. A risk with a low likelihood but catastrophic impact would still be considered severe, highlighting the importance of understanding its potential effects.
Question 16: What does a risk matrix primarily help risk managers visualize?
- The legal requirements for risk disclosure
- The relationship between risk likelihood and potential impact (Correct answer)
- The cost of insurance premiums over time
- The organizational hierarchy for risk reporting
Correct answer: The relationship between risk likelihood and potential impact
A risk matrix plots risks by probability of occurrence against severity of impact to prioritize management attention.
Question 17: Supply chain disruption is best categorized as which type of business continuity risk?
- Regulatory compliance risk
- Reputational risk only
- Internal operational risk
- External dependency risk (Correct answer)
Correct answer: External dependency risk
Supply chain disruptions arise from dependencies on external suppliers and partners, making them external dependency risks that affect business continuity.
Question 18: Key Risk Indicators (KRIs) in strategic risk management are primarily used to:
- Provide early warning signals of increasing risk exposure (Correct answer)
- Eliminate the need for risk assessments
- Determine executive compensation levels
- Replace traditional financial reporting
Correct answer: Provide early warning signals of increasing risk exposure
KRIs are metrics that signal when risk levels are approaching unacceptable thresholds, enabling proactive management response.
Question 19: A 'warm site' in disaster recovery differs from a hot site in that it:
- Is a fully redundant facility ready for immediate use
- Requires some setup and activation time but has essential infrastructure already in place (Correct answer)
- Is located in a warmer climate region
- Is used exclusively for archiving records
Correct answer: Requires some setup and activation time but has essential infrastructure already in place
A warm site has basic infrastructure and systems in place but requires additional configuration and data loading before it can assume full operations.
Question 20: A company's 'Maximum Tolerable Period of Disruption' (MTPD) refers to:
- The total annual budget for business continuity
- The maximum time a business function can be disrupted before it causes irreversible harm (Correct answer)
- The minimum time required to train recovery staff
- The longest period any single employee can be absent
Correct answer: The maximum time a business function can be disrupted before it causes irreversible harm
MTPD establishes the outer boundary for acceptable downtime beyond which consequences become catastrophic or irreversible.
Question 21: Which of the following is an example of a risk mitigation strategy?
- Ignoring potential risks.
- Installing fire alarms and safety systems. (Correct answer)
- Delaying risk analysis.
- Reducing insurance coverage.
Correct answer: Installing fire alarms and safety systems.
Risk mitigation involves implementing measures to reduce the likelihood or impact of a risk. Installing fire alarms and safety systems is a direct example of mitigation, as it aims to reduce the damage from a fire (impact) and potentially provide early warning to prevent widespread loss. This proactive step helps to control the consequences of a potential hazard.
Question 22: Which analysis tool assesses an organization's internal strengths and weaknesses alongside external opportunities and threats?
- Fault tree analysis
- SWOT analysis (Correct answer)
- Monte Carlo simulation
- PESTLE analysis
Correct answer: SWOT analysis
SWOT analysis evaluates internal Strengths and Weaknesses and external Opportunities and Threats to inform strategic risk decisions.
Question 23: Which of the following best defines financial risk in the context of risk management?
- The likelihood of regulatory fines for accounting errors
- The possibility of physical damage to company assets
- The potential for loss due to adverse movements in financial markets or counterparty failure (Correct answer)
- The risk of reputational damage from poor financial disclosures
Correct answer: The potential for loss due to adverse movements in financial markets or counterparty failure
Financial risk encompasses the potential for loss arising from changes in financial market variables or the failure of counterparties to meet obligations.
Question 24: Crisis communication planning is critical to business continuity because it:
- Replaces the need for a formal BCP
- Is required only for publicly traded companies
- Reduces the organization's tax liabilities
- Ensures stakeholders receive timely, accurate information during disruptions (Correct answer)
Correct answer: Ensures stakeholders receive timely, accurate information during disruptions
Effective crisis communication maintains stakeholder trust and prevents misinformation from compounding the impact of a disruption.
Question 25: What is the primary purpose of integrating risk management into strategic planning?
- To align risk-taking with organizational objectives (Correct answer)
- To reduce insurance premiums
- To eliminate all identified risks
- To comply with regulatory requirements only
Correct answer: To align risk-taking with organizational objectives
Integrating risk management into strategic planning ensures risk-taking activities support and align with the organization's stated objectives.
Question 26: A high debt-to-equity ratio indicates that an organization:
- Is heavily reliant on borrowed funds, increasing its financial leverage and credit risk (Correct answer)
- Carries minimal financial risk due to conservative financing
- Is unlikely to face liquidity problems in the near term
- Has strong cash flow relative to its long-term liabilities
Correct answer: Is heavily reliant on borrowed funds, increasing its financial leverage and credit risk
A high debt-to-equity ratio signals significant financial leverage, meaning the company relies heavily on debt financing, which amplifies both returns and risks, including default risk.
Question 27: Which of the following is a primary advantage of using a captive insurer for risk financing?
- Increased control over claims management and customized coverage design (Correct answer)
- Complete exemption from regulatory oversight and capital requirements
- Guaranteed access to all global reinsurance markets without restriction
- Elimination of all underwriting and investment risk
Correct answer: Increased control over claims management and customized coverage design
A key benefit of a captive is that the parent company gains greater control over the entire insurance process, including claims handling and the ability to tailor coverage to its specific needs, which might be unavailable in the commercial market. [24, 28, 29] Captives do not eliminate all risks, access to reinsurance can still be limited, and they are subject to regulatory oversight.
Question 28: Following a significant operational failure where a batch of product was contaminated, a risk manager leads an investigation. The team repeatedly asks "Why?" to trace the issue from the immediate cause back to underlying management system weaknesses. Which analysis technique is being applied?
- Event Tree Analysis (ETA)
- Failure Mode and Effects Analysis (FMEA)
- Root Cause Analysis (RCA) (Correct answer)
- Scenario Analysis
Correct answer: Root Cause Analysis (RCA)
Root Cause Analysis (RCA) is a retrospective problem-solving method used to identify the fundamental causes of an incident. The "5 Whys" is a common technique used within RCA to drill down past superficial causes to the true root of the problem, ensuring corrective actions prevent recurrence.
Question 29: A project team is creating a risk register for an upcoming software development project. Which of the following pieces of information is LEAST likely to be included for each identified risk in the initial risk register?
- The detailed, step-by-step mitigation plan. (Correct answer)
- The probability and potential impact of the risk.
- A description of the risk.
- The name of the assigned risk owner.
Correct answer: The detailed, step-by-step mitigation plan.
While a risk register documents identified risks, their probability, impact, and owner, the detailed, step-by-step mitigation plan is typically developed as part of the risk response planning phase, after the initial identification and analysis. The register might initially note the response strategy (e.g., avoid, mitigate, transfer, accept), but the full plan comes later. [16, 17, 23]
Question 30: An organization is heavily dependent on its lead software architect, who possesses unique, undocumented knowledge critical to the company's core product. Which of the following best describes this operational risk and a common risk financing technique used to address it?
- Reputational risk; managed by public relations campaigns.
- Key person risk; managed by purchasing key person life and disability insurance. (Correct answer)
- Systemic risk; managed by diversifying the company's product lines.
- Legal risk; managed by retaining a corporate law firm.
Correct answer: Key person risk; managed by purchasing key person life and disability insurance.
This is a classic example of key person risk, an operational risk stemming from over-reliance on a specific individual's skills and knowledge. Key person life and/or disability insurance is a common risk financing tool that provides the company with funds to manage the financial impact and transition if that person is unexpectedly lost.
ARM - Associate in Risk Management
The ARM designation from The Institutes validates expertise in identifying, assessing, and treating organizational risks across three exams: ARM 400 (Risk in an Evolving World), ARM 401 (Holistically Assessing Risk), and ARM 402 (Successfully Treating Risk).
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds