Risk Management & Internal Controls Flashcards
7 cards from real CCCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Management & Internal Controls flashcards as text
Which element distinguishes an 'emerging risk' from a 'known risk' in enterprise risk management?
Answer: Emerging risks have uncertain probability and limited historical data
Emerging risks are characterized by high uncertainty, novel circumstances, and limited historical data, making them difficult to quantify using traditional risk assessment methods.
A compliance officer is evaluating whether to implement a control that costs $200,000 annually to reduce a risk with an expected annual loss of $150,000. The BEST decision framework to apply is:
Answer: Cost-benefit analysis
Cost-benefit analysis compares the cost of implementing a control against the financial benefit (reduced expected loss), and in this case the control cost exceeds the benefit.
Which of the following is an example of a 'detective' rather than a 'preventive' internal control?
Answer: Conducting monthly bank reconciliations
Monthly bank reconciliations detect discrepancies that have already occurred, making them a detective control, whereas the other options prevent problems before they happen.
In the context of internal controls over financial reporting (ICFR), a 'significant deficiency' differs from a 'material weakness' in that it:
Answer: Is less severe and represents a lower risk of material misstatement
A significant deficiency is a control deficiency that is less severe than a material weakness but important enough to warrant the attention of those responsible for oversight.
A compliance team is using a 'bow-tie' risk analysis. What does the LEFT side of the bow-tie represent?
Answer: Causes and threat pathways leading to the risk event
In a bow-tie analysis, the left side maps the threats and causes (with preventive controls) leading to the central risk event, while the right side maps consequences and recovery controls.
Which internal audit standard requires internal auditors to be independent of the activities they audit?
Answer: IIA International Standards for the Professional Practice of Internal Auditing
The IIA International Standards specifically mandate organizational independence for internal audit functions to ensure objective and unbiased assessments.
A compliance officer notices that a key control has not been tested in 18 months due to staff turnover. This situation BEST represents which type of risk?
Answer: Operational risk — people and process failure
The failure to execute a control due to staff turnover is an operational risk arising from inadequate people and process management within the compliance function itself.