CCCP Risk Management & Internal Controls 2 — Questions and Answers
Question 1: Which risk appetite framework component defines the maximum level of risk an organization is willing to accept before action is required?
- Risk tolerance
- Risk capacity
- Risk threshold (Correct answer)
- Risk appetite statement
Correct answer: Risk threshold
Risk threshold is the specific level at which a risk triggers mandatory escalation or corrective action.
Question 2: A company discovers that two employees in the accounts payable department have been colluding to approve fraudulent invoices. Which control failure does this best illustrate?
- Inadequate segregation of duties
- Insufficient authorization controls
- Breakdown in collusion-resistant controls (Correct answer)
- Failure of the tone at the top
Correct answer: Breakdown in collusion-resistant controls
Collusion-resistant controls are specifically designed to prevent two or more employees from circumventing controls together, and their failure enables collaborative fraud.
Question 3: Under the COSO ERM framework, which component involves identifying events that may affect the organization's ability to achieve its objectives?
- Risk assessment
- Event identification (Correct answer)
- Control activities
- Risk response
Correct answer: Event identification
Event identification is the COSO ERM component focused on recognizing potential internal and external events that could impact organizational objectives.
Question 4: A Chief Compliance Officer wants to quantify the financial impact of a data breach scenario. Which risk assessment technique is MOST appropriate?
- Bow-tie analysis
- Monte Carlo simulation (Correct answer)
- SWOT analysis
- Control self-assessment
Correct answer: Monte Carlo simulation
Monte Carlo simulation uses probability distributions to model a range of possible financial outcomes for uncertain events like data breaches.
Question 5: Which internal control principle requires that an employee who records a transaction should NOT also have custody of the related assets?
- Dual authorization
- Segregation of duties (Correct answer)
- Mandatory rotation
- Least privilege
Correct answer: Segregation of duties
Segregation of duties separates the functions of record-keeping and asset custody to reduce the risk of fraud or error going undetected.
Question 6: In a risk heat map, a risk plotted in the upper-right quadrant is characterized by:
- Low likelihood and high impact
- High likelihood and high impact (Correct answer)
- Low likelihood and low impact
- High likelihood and low impact
Correct answer: High likelihood and high impact
The upper-right quadrant of a risk heat map represents risks with both high likelihood of occurrence and high potential impact, requiring immediate priority attention.
Question 7: A compliance team implements a control requiring supervisory approval for all wire transfers above $50,000. This is an example of which control type?
- Compensating control
- Detective control
- Preventive control (Correct answer)
- Corrective control
Correct answer: Preventive control
A preventive control is designed to stop an undesirable event from occurring before it happens, such as requiring approval before a transaction is executed.
Which risk appetite framework component defines the maximum level of risk an organization is willing to accept before action is required?