BMO Risk Management & Compliance 1 — Questions and Answers
Question 1: What is the primary purpose of a risk register in an organization?
- To document identified risks, their likelihood, impact, and mitigation strategies (Correct answer)
- To record all financial transactions for audit purposes
- To list all employees responsible for safety violations
- To track regulatory fines and penalties assessed against the organization
Correct answer: To document identified risks, their likelihood, impact, and mitigation strategies
A risk register serves as a central repository that documents identified risks along with their probability, potential impact, assigned owners, and planned mitigation or response strategies.
Question 2: Which of the following best defines 'residual risk' in a business management context?
- The total risk before any controls are applied
- The risk remaining after controls and mitigation measures have been implemented (Correct answer)
- The financial cost of all identified risks combined
- The risk transferred to a third-party vendor or insurer
Correct answer: The risk remaining after controls and mitigation measures have been implemented
Residual risk is the level of risk that remains after an organization has applied its controls, safeguards, and mitigation strategies to address inherent risk.
Question 3: In risk management, what does the acronym COSO stand for?
- Committee of Sponsoring Organizations of the Treadway Commission (Correct answer)
- Certified Officers of Strategic Operations
- Compliance and Oversight Standards Organization
- Corporate Operations and Security Office
Correct answer: Committee of Sponsoring Organizations of the Treadway Commission
COSO stands for the Committee of Sponsoring Organizations of the Treadway Commission, which developed widely used frameworks for internal control and enterprise risk management.
Question 4: Which type of risk control is specifically designed to PREVENT a risk event from occurring in the first place?
- Detective control
- Corrective control
- Preventive control (Correct answer)
- Compensating control
Correct answer: Preventive control
Preventive controls are designed to stop risk events before they occur, such as access controls, training programs, and segregation of duties.
Question 5: What is 'risk appetite' in an organizational risk management framework?
- The total financial budget allocated to risk management activities
- The amount and type of risk an organization is willing to accept in pursuit of its objectives (Correct answer)
- The maximum number of risk events an organization can experience annually
- The legal threshold at which risks must be reported to regulators
Correct answer: The amount and type of risk an organization is willing to accept in pursuit of its objectives
Risk appetite represents the level and type of risk an organization is willing to take on in pursuit of its strategic goals, set by leadership to guide decision-making.
Question 6: A business management officer discovers a significant compliance gap during an internal review. What is the MOST appropriate immediate action?
- Terminate the employees responsible for the gap
- Document the finding, notify appropriate stakeholders, and develop a corrective action plan (Correct answer)
- Report the gap directly to external regulators before conducting any internal review
- Delay reporting until the gap can be resolved to avoid organizational embarrassment
Correct answer: Document the finding, notify appropriate stakeholders, and develop a corrective action plan
Upon discovering a compliance gap, the proper response is to document the finding, escalate to appropriate management and legal counsel, and create a structured plan to remediate the issue.
Question 7: Which of the following is a key element of an effective organizational compliance program according to U.S. Federal Sentencing Guidelines?
- Outsourcing all compliance functions to an external consulting firm
- Implementing high ethical standards and having designated compliance personnel with authority (Correct answer)
- Limiting compliance training only to senior management and executives
- Keeping all compliance investigations confidential from the board of directors
Correct answer: Implementing high ethical standards and having designated compliance personnel with authority
The U.S. Federal Sentencing Guidelines identify high-level commitment to ethics and designated compliance personnel with real authority as essential elements of an effective compliance program.
What is the primary purpose of a risk register in an organization?