Risk Assessment & Management Flashcards
7 cards from real CAE practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Assessment & Management flashcards as text
An adult education program operates in a state with specific cybersecurity breach notification laws. This is an example of which type of risk?
Answer: Compliance risk
Compliance risk arises from the obligation to follow laws and regulations, such as state-level data breach notification requirements.
When using a Likelihood x Impact scoring model, a risk rated 'High Likelihood / Low Impact' should be:
Answer: Monitored and managed with simple, low-cost controls
High-likelihood/low-impact risks are best managed with efficient, routine controls rather than intensive mitigation resources.
An adult educator is designing a program for older adults with limited digital literacy. The MOST significant technology-related risk is:
Answer: Digital exclusion due to insufficient tech support and skill gaps
Older adults with limited digital literacy face the risk of being excluded from program content if adequate technical support and training are not provided.
Which stakeholder is MOST responsible for approving an organization-wide risk management framework in an adult education institution?
Answer: Senior leadership or board of directors
Senior leadership or the board of directors bears ultimate accountability for approving and overseeing the organization's risk management framework.
A program director notices declining enrollment in one site but not others. From a risk management perspective, this should be treated as:
Answer: An early warning signal requiring root cause investigation
Declining enrollment at one site is a risk indicator that may signal quality, accessibility, or community-fit issues requiring investigation before escalation.
Under FERPA, the primary risk adult education programs must manage regarding student records is:
Answer: Unauthorized disclosure of personally identifiable student information
FERPA creates legal obligations around protecting the privacy of student educational records, and unauthorized disclosure is the central compliance risk.
Which approach BEST supports a 'risk-aware culture' in an adult education organization?
Answer: Encouraging open reporting, learning from errors, and rewarding proactive risk identification
A risk-aware culture thrives when staff at all levels feel safe reporting issues and are rewarded for proactive identification of risks.