CCEP Risk Assessment & Monitoring 2 — Questions and Answers
Question 1: Which methodology assigns numerical values to the likelihood and impact of risks to calculate an overall risk score?
- Qualitative risk assessment
- Quantitative risk assessment (Correct answer)
- Residual risk analysis
- Inherent risk mapping
Correct answer: Quantitative risk assessment
Quantitative risk assessment uses numerical values to calculate risk scores, enabling more precise prioritization and resource allocation.
Question 2: A compliance officer discovers that a business unit consistently underreports incidents. What is the BEST initial response?
- Immediately escalate to the board
- Conduct a root-cause analysis to identify why underreporting occurs (Correct answer)
- Impose financial penalties on the unit
- Shut down the unit's operations pending review
Correct answer: Conduct a root-cause analysis to identify why underreporting occurs
Root-cause analysis identifies whether underreporting stems from cultural, process, or training issues before prescribing a remedy.
Question 3: What does a 'risk appetite statement' formally communicate?
- The maximum loss a company is willing to accept while pursuing its objectives (Correct answer)
- The list of all identified compliance risks
- The regulatory penalties the company expects to incur
- The audit schedule for high-risk departments
Correct answer: The maximum loss a company is willing to accept while pursuing its objectives
A risk appetite statement defines the level and type of risk an organization is willing to accept in pursuit of its strategic goals.
Question 4: Which control type is designed to detect a compliance violation AFTER it has occurred?
- Preventive control
- Directive control
- Detective control (Correct answer)
- Corrective control
Correct answer: Detective control
Detective controls identify and surface compliance violations after they occur, such as audits, reconciliations, and monitoring reports.
Question 5: An organization operates in a highly regulated industry with rapidly changing rules. Which monitoring approach is MOST appropriate?
- Annual compliance audits only
- Continuous regulatory monitoring integrated with real-time alerts (Correct answer)
- Periodic self-assessments every three years
- Relying on regulators to notify the company of changes
Correct answer: Continuous regulatory monitoring integrated with real-time alerts
Continuous monitoring with real-time alerts allows organizations to detect and respond to regulatory changes and compliance gaps as they emerge.
Question 6: What is the purpose of a 'risk register' in compliance programs?
- To record disciplinary actions taken against employees
- To document identified risks, their ratings, owners, and mitigation status (Correct answer)
- To log all regulatory communications received
- To track the progress of internal audits
Correct answer: To document identified risks, their ratings, owners, and mitigation status
A risk register serves as a centralized repository that captures identified risks, their assessed severity, responsible owners, and current mitigation efforts.
Question 7: When prioritizing compliance risks, which factor most directly influences whether a risk should be treated as 'critical'?
- The age of the risk identification
- The combination of high likelihood and high impact (Correct answer)
- The number of employees who reported the risk
- The department from which the risk originated
Correct answer: The combination of high likelihood and high impact
Risks that are both highly likely to occur and carry severe impact are typically classified as critical and require immediate attention.
Which methodology assigns numerical values to the likelihood and impact of risks to calculate an overall risk score?