CCM Risk Management and Compliance 3 — Questions and Answers
Question 1: A residual risk is best defined as the risk that remains after:
- Initial identification of all risks
- Risk transfer to a third party
- Application of controls and mitigation measures (Correct answer)
- Approval by senior management
Correct answer: Application of controls and mitigation measures
Residual risk is the level of risk remaining after controls and mitigation strategies have been applied to the inherent risk.
Question 2: Which international standard provides a framework specifically for anti-bribery management systems?
- ISO 9001
- ISO 31000
- ISO 37001 (Correct answer)
- ISO 27001
Correct answer: ISO 37001
ISO 37001 specifies requirements for establishing, implementing, and maintaining an anti-bribery management system.
Question 3: A 'whistle-blower' policy in a compliance program is designed primarily to:
- Discourage employees from reporting concerns to regulators
- Provide a safe channel for employees to report suspected violations without retaliation (Correct answer)
- Replace the need for an internal audit function
- Limit company liability by documenting complaints
Correct answer: Provide a safe channel for employees to report suspected violations without retaliation
Whistle-blower policies create protected reporting channels, encouraging employees to surface misconduct without fear of retaliation.
Question 4: In contract risk management, a 'limitation of liability' clause is designed to:
- Remove all liability from the seller regardless of fault
- Cap the maximum financial exposure either party bears under the contract (Correct answer)
- Transfer liability to the buyer unconditionally
- Void the contract in the event of a dispute
Correct answer: Cap the maximum financial exposure either party bears under the contract
A limitation of liability clause sets a ceiling on damages recoverable under the contract, protecting parties from open-ended financial exposure.
Question 5: Regulatory compliance risk refers to the risk that an organization will suffer penalties due to:
- Failing to meet market demand
- Competitors introducing superior products
- Violating laws, regulations, or industry codes (Correct answer)
- Foreign currency exchange fluctuations
Correct answer: Violating laws, regulations, or industry codes
Regulatory compliance risk arises when an organization fails to adhere to applicable laws, regulations, or standards, leading to fines, sanctions, or reputational damage.
Question 6: A company uses Key Risk Indicators (KRIs) to:
- Measure past losses after they have occurred
- Provide early warning signals that risk levels may be changing (Correct answer)
- Replace the need for internal controls
- Approve risk appetite thresholds
Correct answer: Provide early warning signals that risk levels may be changing
KRIs are forward-looking metrics that signal when risks are trending toward or beyond acceptable thresholds, enabling proactive management.
Question 7: Under US export control regulations (EAR/ITAR), 'deemed exports' refer to:
- Goods shipped to allied nations
- Technology disclosed to foreign nationals within the United States (Correct answer)
- Products re-exported through a third country
- Items on the Commerce Control List shipped to Canada
Correct answer: Technology disclosed to foreign nationals within the United States
A deemed export occurs when controlled technology or software is released to a foreign national in the US, which is treated as an export to their home country.
A residual risk is best defined as the risk that remains after: