โ† All CCT Flashcard Decks

Risk Management & Internal Controls Flashcards

7 cards from real CCT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Management & Internal Controls flashcards as text
  1. In an enterprise risk management (ERM) framework, what is the purpose of a risk appetite statement?

    Answer: To define the amount and type of risk the organization is willing to accept

    A risk appetite statement formally articulates how much risk the board and senior management are willing to accept in pursuit of the organization's objectives.

  2. Which COSO ERM component focuses on selecting risk responses and deploying control activities to keep risk within appetite?

    Answer: Performance

    The Performance component of COSO ERM encompasses identifying, assessing, prioritizing risks, and implementing responses to manage them within the defined appetite.

  3. A compliance officer discovers that the same employee both approves vendor invoices and processes payments. This represents a failure of which control?

    Answer: Segregation of duties

    Segregation of duties requires that no single individual controls all stages of a transaction to reduce the opportunity for fraud or error.

  4. What is 'key risk indicator' (KRI) primarily used for in compliance programs?

    Answer: Providing early warning signals of increasing risk exposure

    KRIs are metrics that signal when risk levels are trending toward or beyond acceptable thresholds, enabling proactive intervention.

  5. Under the COSO Internal Control framework, which component directly addresses management's ongoing monitoring of control effectiveness?

    Answer: Monitoring activities

    The Monitoring Activities component requires ongoing evaluations and separate assessments to verify that internal controls continue to function as intended.

  6. A financial institution's compliance department conducts an annual review of its anti-money-laundering controls to verify they meet regulatory standards. This is best described as a:

    Answer: Control self-assessment

    A control self-assessment (CSA) is a process by which management or staff evaluate the effectiveness of their own internal controls.

  7. Which scenario best illustrates 'risk concentration' that a compliance officer should flag?

    Answer: A bank has 60% of its loan portfolio concentrated in one industry sector

    Risk concentration occurs when exposure to a single risk factor is high enough that adverse developments in that area could cause significant harm.

Risk Management & Internal Controls Flashcards โ€” CCT Study Cards with Answers