CCT Risk Management & Internal Controls 5 — Questions and Answers
Question 1: Which of the following scenarios exemplifies a 'residual risk' determination?
- Estimating potential losses before any controls exist
- Calculating remaining risk exposure after existing controls have been applied (Correct answer)
- Mapping all risks to a regulatory requirement
- Identifying new risks through a brainstorming workshop
Correct answer: Calculating remaining risk exposure after existing controls have been applied
Residual risk is the risk that remains after the organization has implemented its controls and risk responses.
Question 2: A compliance team discovers that a control designed to prevent unauthorized system access has not been functioning for three months. The compliance officer should first:
- Document the failure and include it in next year's risk assessment
- Implement an interim compensating control and escalate to senior management (Correct answer)
- Remove the control from the risk register as ineffective
- Notify regulators before conducting an internal investigation
Correct answer: Implement an interim compensating control and escalate to senior management
When a primary control fails, deploying a compensating control immediately limits ongoing exposure while escalation ensures appropriate oversight and remediation.
Question 3: Under the COSO framework, the 'control environment' component is best described as:
- The set of automated system checks that prevent unauthorized transactions
- The foundation of internal control, shaped by management's integrity, ethics, and governance structure (Correct answer)
- The process for identifying and assessing financial statement risks
- The procedures used to reconcile accounts at period end
Correct answer: The foundation of internal control, shaped by management's integrity, ethics, and governance structure
The control environment sets the overall tone of the organization and is the foundation upon which all other components of internal control rest.
Question 4: Which metric is commonly used in quantitative risk analysis to express the expected financial loss from a specific risk over a one-year period?
- Risk Tolerance Level (RTL)
- Annual Loss Expectancy (ALE) (Correct answer)
- Net Present Value of Risk (NPVR)
- Residual Risk Quotient (RRQ)
Correct answer: Annual Loss Expectancy (ALE)
Annual Loss Expectancy (ALE) is calculated as Asset Value × Exposure Factor × Annualized Rate of Occurrence and represents the expected yearly financial impact of a risk.
Question 5: A compliance manager notices that a key internal control is effective but is costing far more to maintain than the risk it mitigates. Which principle should guide the decision?
- Controls must be maintained regardless of cost once implemented
- The cost of a control should be proportionate to the risk it addresses (Correct answer)
- All controls should be replaced with insurance coverage
- Only regulators can authorize the removal of an internal control
Correct answer: The cost of a control should be proportionate to the risk it addresses
The cost-benefit principle holds that the cost of implementing and maintaining a control should not exceed the benefit derived from reduced risk exposure.
Question 6: Which of the following activities would be performed by the second line of defense in a three-lines model?
- Processing customer transactions on a daily basis
- Designing compliance policies, monitoring risk, and providing oversight to the first line (Correct answer)
- Conducting independent audits and reporting to the audit committee
- Approving individual customer credit applications
Correct answer: Designing compliance policies, monitoring risk, and providing oversight to the first line
The second line—comprising compliance, risk management, and legal functions—sets policy, monitors first-line adherence, and provides independent oversight without executing operations.
Question 7: A compliance officer is evaluating whether to escalate a newly identified risk. Which factor most strongly justifies immediate escalation to senior leadership?
- The risk was identified during a routine self-assessment with no control gaps noted
- The risk exceeds the organization's defined risk tolerance and lacks compensating controls (Correct answer)
- The risk is documented in the register and has a control in the testing queue
- The risk is classified as low impact with high likelihood of occurrence
Correct answer: The risk exceeds the organization's defined risk tolerance and lacks compensating controls
Risks that exceed risk tolerance and lack existing controls represent urgent exposures that require senior leadership attention and resource allocation.
Which of the following scenarios exemplifies a 'residual risk' determination?