CCM Risk and Internal Controls 3 — Questions and Answers
Question 1: A compliance officer is reviewing an organization's risk register. Which element is LEAST likely to be included in a typical risk register entry?
- Risk owner
- Likelihood rating
- Employee compensation details (Correct answer)
- Mitigation actions
Correct answer: Employee compensation details
A risk register typically includes risk description, likelihood, impact, owner, and mitigation actions — not employee compensation, which is unrelated to risk documentation.
Question 2: Which internal control objective focuses on ensuring that financial and operational reports are accurate and complete?
- Operations
- Reporting (Correct answer)
- Compliance
- Strategic
Correct answer: Reporting
Under the COSO framework, the Reporting objective specifically addresses the reliability and accuracy of both internal and external financial and non-financial reporting.
Question 3: An organization implements a control requiring two separate individuals to authorize any wire transfer over $50,000. This is an example of:
- Segregation of duties
- Dual control (Correct answer)
- Compensating control
- Preventive detective control
Correct answer: Dual control
Dual control requires two or more authorized individuals to be present or to approve a transaction simultaneously, preventing unilateral action on high-risk activities.
Question 4: In the context of risk treatment, 'risk transfer' is best exemplified by:
- Discontinuing a high-risk business line
- Purchasing cybersecurity insurance (Correct answer)
- Implementing stronger access controls
- Accepting residual risk after mitigation
Correct answer: Purchasing cybersecurity insurance
Risk transfer shifts the financial consequences of a risk to a third party, most commonly through insurance policies or contractual arrangements.
Question 5: Which approach to internal control testing examines a sample of transactions from start to finish to verify all controls operated effectively throughout?
- Walkthrough testing
- End-to-end testing (Correct answer)
- Substantive testing
- Regression testing
Correct answer: End-to-end testing
End-to-end testing traces transactions from initiation through completion, verifying that all controls in the process chain functioned as intended.
Question 6: A Compliance officer identifies a 'gap' between the current state of controls and the required regulatory standard. The FIRST step should be to:
- Immediately report to regulators
- Conduct a root cause analysis (Correct answer)
- Suspend the affected business process
- Issue a corrective action plan
Correct answer: Conduct a root cause analysis
Root cause analysis identifies the underlying reason for the control gap, enabling the organization to develop a targeted and effective remediation strategy.
Question 7: Which risk metric measures the maximum potential loss an organization could suffer over a specific time period at a given confidence level?
- Key Risk Indicator (KRI)
- Value at Risk (VaR) (Correct answer)
- Risk Appetite Statement
- Expected Loss (EL)
Correct answer: Value at Risk (VaR)
Value at Risk (VaR) is a statistical measure that quantifies the maximum expected loss over a defined period at a specified confidence level (e.g., 99%).
A compliance officer is reviewing an organization's risk register.
Which element is LEAST likely to be included in a typical risk register entry?