CCCP Risk Management & Internal Controls 5 — Questions and Answers
Question 1: Which element distinguishes an 'emerging risk' from a 'known risk' in enterprise risk management?
- Emerging risks have already materialized at least once
- Emerging risks have uncertain probability and limited historical data (Correct answer)
- Emerging risks are always low-impact by definition
- Emerging risks require immediate escalation to the board
Correct answer: Emerging risks have uncertain probability and limited historical data
Emerging risks are characterized by high uncertainty, novel circumstances, and limited historical data, making them difficult to quantify using traditional risk assessment methods.
Question 2: A compliance officer is evaluating whether to implement a control that costs $200,000 annually to reduce a risk with an expected annual loss of $150,000. The BEST decision framework to apply is:
- Cost-benefit analysis (Correct answer)
- Qualitative risk assessment
- Residual risk evaluation
- Control self-assessment
Correct answer: Cost-benefit analysis
Cost-benefit analysis compares the cost of implementing a control against the financial benefit (reduced expected loss), and in this case the control cost exceeds the benefit.
Question 3: Which of the following is an example of a 'detective' rather than a 'preventive' internal control?
- Requiring dual signatures on checks above $10,000
- Conducting monthly bank reconciliations (Correct answer)
- Encrypting sensitive data at rest
- Blocking unauthorized websites through a firewall
Correct answer: Conducting monthly bank reconciliations
Monthly bank reconciliations detect discrepancies that have already occurred, making them a detective control, whereas the other options prevent problems before they happen.
Question 4: In the context of internal controls over financial reporting (ICFR), a 'significant deficiency' differs from a 'material weakness' in that it:
- Requires immediate public disclosure under SEC rules
- Is less severe and represents a lower risk of material misstatement (Correct answer)
- Only applies to non-public companies
- Cannot be remediated within the same fiscal year
Correct answer: Is less severe and represents a lower risk of material misstatement
A significant deficiency is a control deficiency that is less severe than a material weakness but important enough to warrant the attention of those responsible for oversight.
Question 5: A compliance team is using a 'bow-tie' risk analysis. What does the LEFT side of the bow-tie represent?
- Consequences and impacts of the risk event
- Recovery controls and corrective actions
- Causes and threat pathways leading to the risk event (Correct answer)
- Key risk indicators and monitoring metrics
Correct answer: Causes and threat pathways leading to the risk event
In a bow-tie analysis, the left side maps the threats and causes (with preventive controls) leading to the central risk event, while the right side maps consequences and recovery controls.
Question 6: Which internal audit standard requires internal auditors to be independent of the activities they audit?
- COSO Internal Control — Integrated Framework
- IIA International Standards for the Professional Practice of Internal Auditing (Correct answer)
- ISO 31000 Risk Management Guidelines
- PCAOB Auditing Standards
Correct answer: IIA International Standards for the Professional Practice of Internal Auditing
The IIA International Standards specifically mandate organizational independence for internal audit functions to ensure objective and unbiased assessments.
Question 7: A compliance officer notices that a key control has not been tested in 18 months due to staff turnover. This situation BEST represents which type of risk?
- Strategic risk
- Reputational risk
- Operational risk — people and process failure (Correct answer)
- Systemic risk
Correct answer: Operational risk — people and process failure
The failure to execute a control due to staff turnover is an operational risk arising from inadequate people and process management within the compliance function itself.
Which element distinguishes an 'emerging risk' from a 'known risk' in enterprise risk management?