CED Risk Assessment & Management 2 — Questions and Answers
Question 1: A nonprofit executive director discovers that a key grant funder represents 60% of the organization's annual budget. Which risk management strategy is most appropriate?
- Accept the risk and continue current operations
- Transfer the risk by purchasing insurance
- Mitigate the risk by actively diversifying funding sources (Correct answer)
- Avoid the risk by returning the grant funds
Correct answer: Mitigate the risk by actively diversifying funding sources
Diversifying funding sources reduces concentration risk and decreases dependency on any single funder.
Question 2: What is the primary purpose of a SWOT analysis in the context of organizational risk management?
- To calculate the financial cost of each identified risk
- To identify internal and external factors that may affect organizational objectives (Correct answer)
- To assign probability scores to potential risk events
- To create a legal framework for liability protection
Correct answer: To identify internal and external factors that may affect organizational objectives
SWOT analysis identifies Strengths, Weaknesses, Opportunities, and Threats to inform strategic and risk planning.
Question 3: An organization's risk register should be reviewed and updated at minimum:
- Every five years during strategic planning cycles
- Only after a risk event has occurred
- Annually, or whenever significant organizational changes occur (Correct answer)
- Whenever the board requests a review
Correct answer: Annually, or whenever significant organizational changes occur
Risk registers should be reviewed at least annually and after significant changes to keep risk information current and actionable.
Question 4: Which of the following best describes residual risk?
- Risk that has been fully eliminated through controls
- The risk remaining after mitigation measures have been applied (Correct answer)
- Risk transferred entirely to an insurance provider
- Newly identified risks not yet in the risk register
Correct answer: The risk remaining after mitigation measures have been applied
Residual risk is the level of risk that remains after controls, mitigation strategies, or other risk responses have been implemented.
Question 5: A CED is preparing for a potential cyberattack on the organization's donor database. Which response plan element is MOST critical to establish in advance?
- A list of preferred cybersecurity vendors for future procurement
- Clear roles, communication protocols, and a data recovery procedure (Correct answer)
- An annual cybersecurity budget projection
- A policy prohibiting staff from accessing donor records remotely
Correct answer: Clear roles, communication protocols, and a data recovery procedure
Effective incident response requires pre-defined roles, communication chains, and recovery steps to minimize damage and restore operations quickly.
Question 6: When evaluating a new program expansion, an executive director should conduct a risk assessment PRIMARILY to:
- Justify the expansion budget to the board of directors
- Identify potential barriers and plan mitigation before launch (Correct answer)
- Satisfy regulatory reporting requirements
- Determine the marketing strategy for the new program
Correct answer: Identify potential barriers and plan mitigation before launch
Risk assessment before a program launch allows leaders to anticipate problems and build mitigation strategies into the implementation plan.
Question 7: Which type of risk is associated with an organization failing to comply with state nonprofit reporting requirements?
- Strategic risk
- Reputational risk
- Compliance risk (Correct answer)
- Operational risk
Correct answer: Compliance risk
Compliance risk arises from failing to adhere to applicable laws, regulations, or reporting requirements.
A nonprofit executive director discovers that a key grant funder represents 60% of the organization's annual budget.
Which risk management strategy is most appropriate?