CCCP Risk Management & Internal Controls 3 — Questions and Answers
Question 1: What is the PRIMARY purpose of a Key Risk Indicator (KRI)?
- To measure the effectiveness of past controls
- To provide early warning signals of increasing risk exposure (Correct answer)
- To document the root cause of a risk event
- To assign ownership of a specific risk
Correct answer: To provide early warning signals of increasing risk exposure
KRIs are forward-looking metrics that signal when risk levels are trending toward or beyond acceptable thresholds before an event occurs.
Question 2: Which of the following best describes 'inherent risk' in a compliance context?
- Risk remaining after controls are applied
- Risk that exists before any mitigating controls are in place (Correct answer)
- Risk accepted by management after analysis
- Risk transferred to a third party through insurance
Correct answer: Risk that exists before any mitigating controls are in place
Inherent risk is the raw or gross risk level existing in a business process or activity before any controls or mitigation measures are applied.
Question 3: A compliance officer discovers that controls designed to prevent money laundering are operating but are insufficient to reduce risk to an acceptable level. The BEST next step is to:
- Accept the residual risk and document the decision
- Implement additional or enhanced compensating controls (Correct answer)
- Report the deficiency to external auditors immediately
- Terminate the business activity generating the risk
Correct answer: Implement additional or enhanced compensating controls
When existing controls are insufficient, the appropriate response is to strengthen or add compensating controls to close the gap before considering acceptance or escalation.
Question 4: Under the Three Lines of Defense model, which line is responsible for setting risk appetite and overseeing the overall risk management framework?
- First line (business operations)
- Second line (risk and compliance functions)
- Third line (internal audit)
- Board and senior management (Correct answer)
Correct answer: Board and senior management
The board and senior management sit above the three lines and are responsible for establishing risk appetite and providing overall governance of the risk framework.
Question 5: Which control activity is MOST effective at detecting unauthorized access to sensitive systems after the fact?
- Multi-factor authentication
- Access control lists
- System access log reviews (Correct answer)
- Role-based access controls
Correct answer: System access log reviews
Reviewing system access logs is a detective control that identifies unauthorized or suspicious access activities after they have occurred.
Question 6: A risk that cannot be further reduced through practical controls and must be consciously accepted by management is called:
- Transferred risk
- Residual risk
- Tolerated risk (Correct answer)
- Secondary risk
Correct answer: Tolerated risk
Tolerated risk refers to residual risk that management has evaluated, deemed acceptable within the risk appetite, and formally decided to accept rather than further mitigate.
Question 7: Which scenario represents a 'risk transfer' strategy in corporate compliance?
- Stopping a high-risk business line entirely
- Purchasing cyber liability insurance (Correct answer)
- Strengthening employee training programs
- Adding a supervisory approval step to a process
Correct answer: Purchasing cyber liability insurance
Purchasing insurance transfers the financial consequences of a risk event to a third party (the insurer), which is the defining characteristic of a risk transfer strategy.
What is the PRIMARY purpose of a Key Risk Indicator (KRI)?