Risk Management & Mitigation Flashcards
7 cards from real CBA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Management & Mitigation flashcards as text
Which internal control mechanism MOST directly mitigates the risk of unauthorized or fraudulent expenditures in a government budget?
Answer: Segregation of duties between authorization, custody, and record-keeping functions
Segregation of duties ensures that no single individual controls all aspects of a financial transaction, which is the foundational control against fraud and error.
A budget analyst performs a Monte Carlo simulation on a major capital project. The primary purpose of this technique is to:
Answer: Model a range of possible budget outcomes by running thousands of scenarios with variable inputs
Monte Carlo simulation runs thousands of iterations with randomized inputs to produce a probability distribution of possible budget outcomes, quantifying uncertainty.
When an agency purchases an insurance policy to cover potential losses from natural disasters affecting its facilities, this is an example of risk:
Answer: Transfer
Purchasing insurance transfers the financial consequences of a risk to a third party (the insurer) rather than bearing the cost internally.
Which of the following is an example of a 'secondary risk' in budget management?
Answer: A new risk that arises as a direct result of implementing a risk response action
Secondary risks are unintended new risks created by the act of implementing a mitigation strategy, requiring their own assessment and response.
A city budget office is preparing for potential revenue shortfalls due to an economic downturn. The MOST prudent risk mitigation step would be to:
Answer: Develop tiered budget reduction scenarios (e.g., 5%, 10%, 15% cuts) for potential activation
Pre-developing tiered reduction scenarios enables rapid, coordinated response if revenues fall short without disrupting operations unnecessarily.
In the context of federal risk management frameworks (e.g., COSO ERM), 'risk tolerance' differs from 'risk appetite' in that:
Answer: Risk tolerance is the acceptable variation around specific risk appetite thresholds
Risk appetite is the broad level of risk an organization accepts, while risk tolerance defines the acceptable variance or deviation around specific risk objectives.
Which federal statute provides the primary legal framework requiring agencies to maintain internal controls to mitigate financial management risks?
Answer: The Federal Managers' Financial Integrity Act (FMFIA)
FMFIA requires federal agency heads to annually assess and report on the adequacy of internal controls, forming the backbone of federal financial risk management.