CCM Risk and Internal Controls 2 — Questions and Answers
Question 1: Which risk assessment methodology assigns a numerical score to risks based on probability and impact, allowing for quantitative comparison?
- Risk heat map
- Monte Carlo simulation
- Risk scoring matrix (Correct answer)
- SWOT analysis
Correct answer: Risk scoring matrix
A risk scoring matrix multiplies probability by impact scores to produce a numerical risk score that enables objective, quantitative comparison across risks.
Question 2: Under the COSO ERM framework, which component ensures that risk responses are aligned with the entity's risk appetite?
- Risk identification
- Risk response (Correct answer)
- Event identification
- Control activities
Correct answer: Risk response
The Risk Response component of COSO ERM involves selecting responses (avoid, reduce, share, accept) that bring residual risk within the entity's risk appetite.
Question 3: A compliance officer discovers that a key control is being bypassed by senior management. This situation is best described as:
- Control deficiency
- Management override (Correct answer)
- Tone at the top failure
- Segregation of duties gap
Correct answer: Management override
Management override occurs when senior leaders circumvent established internal controls, representing one of the most serious internal control risks.
Question 4: Which type of risk represents the possibility that a compliance program will fail due to inadequate policies, procedures, or controls?
- Inherent risk
- Residual risk
- Control risk (Correct answer)
- Detection risk
Correct answer: Control risk
Control risk is the risk that a material misstatement or compliance failure will not be prevented or detected by internal controls.
Question 5: When performing a Business Impact Analysis (BIA), the primary goal is to:
- Identify all potential threats to the organization
- Determine the financial cost of each risk
- Prioritize recovery of business functions by criticality (Correct answer)
- Assign ownership of each identified risk
Correct answer: Prioritize recovery of business functions by criticality
A BIA identifies and prioritizes critical business functions to determine recovery time objectives and the order in which operations should be restored after a disruption.
Question 6: The 'three lines of defense' model assigns which primary role to the internal audit function?
- First line — operational risk ownership
- Second line — risk oversight and policy setting
- Third line — independent assurance (Correct answer)
- Fourth line — regulatory examination
Correct answer: Third line — independent assurance
Internal audit serves as the third line of defense by providing independent, objective assurance to senior management and the board on the effectiveness of governance and controls.
Question 7: Which control is designed to limit access to sensitive systems only to personnel who require it for their job functions?
- Compensating control
- Principle of least privilege (Correct answer)
- Detective control
- Dual authorization
Correct answer: Principle of least privilege
The principle of least privilege restricts user access rights to the minimum permissions needed to perform their authorized tasks, reducing the risk of unauthorized actions.
Which risk assessment methodology assigns a numerical score to risks based on probability and impact, allowing for quantitative comparison?