BMO Risk Management & Compliance 2 — Questions and Answers
Question 1: What is Enterprise Risk Management (ERM) primarily designed to accomplish?
- To eliminate all organizational risks and guarantee operational success
- To provide a structured approach for identifying, assessing, and managing risks across the entire organization (Correct answer)
- To transfer financial liability for risks to external insurance providers
- To satisfy regulatory requirements without actually changing operational practices
Correct answer: To provide a structured approach for identifying, assessing, and managing risks across the entire organization
ERM is a holistic framework that integrates risk identification, assessment, and response across all business units to support strategy execution and value protection.
Question 2: Which framework is most commonly referenced for IT-related risk management and compliance in business organizations?
- ISO 9001
- COBIT (Control Objectives for Information and Related Technologies) (Correct answer)
- GAAP (Generally Accepted Accounting Principles)
- OSHA 1910 Standards
Correct answer: COBIT (Control Objectives for Information and Related Technologies)
COBIT is a widely adopted framework developed by ISACA that provides guidance on IT governance, risk management, and compliance for business operations.
Question 3: What is the primary role of an internal audit function within a compliance and risk management program?
- To prepare and file the organization's annual tax returns
- To provide independent assurance that risk management and internal controls are operating effectively (Correct answer)
- To manage day-to-day operational decisions in all business units
- To negotiate contracts with external vendors and suppliers
Correct answer: To provide independent assurance that risk management and internal controls are operating effectively
Internal audit provides independent, objective assurance and consulting services to evaluate whether risk management, control, and governance processes are adequate and effective.
Question 4: In risk management, what are the four primary risk treatment (response) options?
- Report, Record, Review, Resolve
- Accept, Avoid, Transfer, Mitigate (Correct answer)
- Assess, Plan, Implement, Monitor
- Identify, Analyze, Prioritize, Eliminate
Correct answer: Accept, Avoid, Transfer, Mitigate
The four standard risk response strategies are: Accept (tolerate the risk), Avoid (eliminate the activity causing the risk), Transfer (shift risk to a third party), and Mitigate (reduce likelihood or impact).
Question 5: What distinguishes a compliance audit from a financial audit?
- Compliance audits are conducted only by external regulatory agencies, while financial audits are always internal
- Compliance audits evaluate adherence to laws, regulations, and policies, while financial audits focus on the accuracy of financial statements (Correct answer)
- Compliance audits are less important than financial audits in regulated industries
- Compliance audits only apply to public companies listed on stock exchanges
Correct answer: Compliance audits evaluate adherence to laws, regulations, and policies, while financial audits focus on the accuracy of financial statements
A compliance audit assesses whether an organization is adhering to applicable laws, regulations, policies, and procedures, whereas a financial audit examines whether financial statements accurately represent the organization's financial position.
Question 6: What is the significance of 'tone at the top' in an organizational compliance program?
- It refers to the volume level of compliance training sessions in conference rooms
- It describes senior leadership's visible commitment to ethical behavior, which drives the organization's compliance culture (Correct answer)
- It is a regulatory requirement mandating that executives personally sign all compliance reports
- It refers to the ranking of compliance priorities from most to least important
Correct answer: It describes senior leadership's visible commitment to ethical behavior, which drives the organization's compliance culture
'Tone at the top' refers to the ethical culture that senior executives establish through their own behavior and stated values, which significantly influences how seriously all employees take compliance obligations.
Question 7: A BMO is reviewing vendor contracts for compliance risk. Which clause type is most critical for managing third-party compliance obligations?
- Price escalation clauses that adjust vendor costs over time
- Right-to-audit clauses that allow the organization to inspect vendor compliance practices (Correct answer)
- Force majeure clauses that excuse performance during natural disasters
- Arbitration clauses that resolve disputes outside of court
Correct answer: Right-to-audit clauses that allow the organization to inspect vendor compliance practices
Right-to-audit clauses allow the organization to inspect and assess vendor operations, records, and controls to verify that third parties are meeting contractual compliance and regulatory requirements.
What is Enterprise Risk Management (ERM) primarily designed to accomplish?