Risk Management & Internal Controls Flashcards
7 cards from real CCT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Management & Internal Controls flashcards as text
Which of the following scenarios exemplifies a 'residual risk' determination?
Answer: Calculating remaining risk exposure after existing controls have been applied
Residual risk is the risk that remains after the organization has implemented its controls and risk responses.
A compliance team discovers that a control designed to prevent unauthorized system access has not been functioning for three months. The compliance officer should first:
Answer: Implement an interim compensating control and escalate to senior management
When a primary control fails, deploying a compensating control immediately limits ongoing exposure while escalation ensures appropriate oversight and remediation.
Under the COSO framework, the 'control environment' component is best described as:
Answer: The foundation of internal control, shaped by management's integrity, ethics, and governance structure
The control environment sets the overall tone of the organization and is the foundation upon which all other components of internal control rest.
Which metric is commonly used in quantitative risk analysis to express the expected financial loss from a specific risk over a one-year period?
Answer: Annual Loss Expectancy (ALE)
Annual Loss Expectancy (ALE) is calculated as Asset Value × Exposure Factor × Annualized Rate of Occurrence and represents the expected yearly financial impact of a risk.
A compliance manager notices that a key internal control is effective but is costing far more to maintain than the risk it mitigates. Which principle should guide the decision?
Answer: The cost of a control should be proportionate to the risk it addresses
The cost-benefit principle holds that the cost of implementing and maintaining a control should not exceed the benefit derived from reduced risk exposure.
Which of the following activities would be performed by the second line of defense in a three-lines model?
Answer: Designing compliance policies, monitoring risk, and providing oversight to the first line
The second line—comprising compliance, risk management, and legal functions—sets policy, monitors first-line adherence, and provides independent oversight without executing operations.
A compliance officer is evaluating whether to escalate a newly identified risk. Which factor most strongly justifies immediate escalation to senior leadership?
Answer: The risk exceeds the organization's defined risk tolerance and lacks compensating controls
Risks that exceed risk tolerance and lack existing controls represent urgent exposures that require senior leadership attention and resource allocation.