CCT Risk Management & Internal Controls 3 — Questions and Answers
Question 1: In an enterprise risk management (ERM) framework, what is the purpose of a risk appetite statement?
- To list every identified risk in the organization
- To define the amount and type of risk the organization is willing to accept (Correct answer)
- To mandate zero tolerance for all compliance risks
- To replace the need for internal controls
Correct answer: To define the amount and type of risk the organization is willing to accept
A risk appetite statement formally articulates how much risk the board and senior management are willing to accept in pursuit of the organization's objectives.
Question 2: Which COSO ERM component focuses on selecting risk responses and deploying control activities to keep risk within appetite?
- Governance and culture
- Strategy and objective-setting
- Performance (Correct answer)
- Review and revision
Correct answer: Performance
The Performance component of COSO ERM encompasses identifying, assessing, prioritizing risks, and implementing responses to manage them within the defined appetite.
Question 3: A compliance officer discovers that the same employee both approves vendor invoices and processes payments. This represents a failure of which control?
- Physical safeguards
- Segregation of duties (Correct answer)
- Information and communication
- Monitoring activities
Correct answer: Segregation of duties
Segregation of duties requires that no single individual controls all stages of a transaction to reduce the opportunity for fraud or error.
Question 4: What is 'key risk indicator' (KRI) primarily used for in compliance programs?
- Measuring the profitability of compliance investments
- Providing early warning signals of increasing risk exposure (Correct answer)
- Documenting past regulatory violations
- Replacing the need for periodic risk assessments
Correct answer: Providing early warning signals of increasing risk exposure
KRIs are metrics that signal when risk levels are trending toward or beyond acceptable thresholds, enabling proactive intervention.
Question 5: Under the COSO Internal Control framework, which component directly addresses management's ongoing monitoring of control effectiveness?
- Control environment
- Risk assessment
- Control activities
- Monitoring activities (Correct answer)
Correct answer: Monitoring activities
The Monitoring Activities component requires ongoing evaluations and separate assessments to verify that internal controls continue to function as intended.
Question 6: A financial institution's compliance department conducts an annual review of its anti-money-laundering controls to verify they meet regulatory standards. This is best described as a:
- Control self-assessment (Correct answer)
- Independent assurance review
- Risk tolerance exercise
- Corrective action plan
Correct answer: Control self-assessment
A control self-assessment (CSA) is a process by which management or staff evaluate the effectiveness of their own internal controls.
Question 7: Which scenario best illustrates 'risk concentration' that a compliance officer should flag?
- A company diversifies its vendor base across 50 suppliers
- A bank has 60% of its loan portfolio concentrated in one industry sector (Correct answer)
- An employee receives mandatory compliance training annually
- A firm maintains duplicate transaction records in two systems
Correct answer: A bank has 60% of its loan portfolio concentrated in one industry sector
Risk concentration occurs when exposure to a single risk factor is high enough that adverse developments in that area could cause significant harm.
In an enterprise risk management (ERM) framework, what is the purpose of a risk appetite statement?