Risk Management Auditing Flashcards
6 cards from real CBA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Risk Management Auditing flashcards as text
An internal auditor at a regional bank is evaluating the institution's operational risk management framework. Which of the following represents the MOST critical component for the auditor to assess to ensure the framework's effectiveness?
Answer: The process for identifying, assessing, monitoring, and reporting operational risks across all business lines.
The core of an effective operational risk management framework is a robust, end-to-end process for proactively managing risk. An auditor must verify that the bank has a systematic way to identify risks, assess their potential impact, monitor them continuously, and report them to relevant stakeholders. While insurance, consultant usage, and historical losses are relevant data points, they are secondary to the fundamental process itself.
In the 'Three Lines of Defense' model for risk management, what is the primary role of the internal audit function?
Answer: To provide independent and objective assurance on the effectiveness of risk management, governance, and internal controls.
The internal audit function serves as the third line of defense, providing independent assurance to the board and senior management that the first and second lines are operating effectively. It does not own or manage risks (first line) or set risk management policies (second line/management), but rather evaluates the entire framework objectively.
A bank's internal audit team is planning an audit of its risk culture. Which of the following audit procedures would provide the MOST insightful evidence regarding the 'tone at the top'?
Answer: Reviewing the minutes of board and senior management risk committee meetings.
Board and senior management meeting minutes provide direct insight into the discussions, priorities, challenges, and decisions made by leadership regarding risk. This is a primary source for assessing the 'tone at the top' and leadership's commitment to a strong risk culture. Other options, while useful for assessing different aspects of risk management or culture, are less direct indicators of leadership's engagement.
During an audit of a bank's enterprise risk management (ERM) framework, an auditor notes that the risk appetite statement is vaguely defined and lacks quantifiable metrics. What is the MOST significant implication of this finding?
Answer: It will be difficult to align strategic decisions with the board's risk tolerance and for audit to assess compliance.
A clear, well-defined risk appetite statement with quantitative and qualitative metrics is crucial for guiding strategic decisions and aligning business activities with the board's approved level of risk tolerance. Without it, management lacks clear boundaries for risk-taking, and internal audit has no objective criteria against which to assess whether business units are operating within acceptable risk levels.
A Certified Bank Auditor is tasked with evaluating the effectiveness of the second line of defense in a large financial institution. Which of the following functions is the auditor MOST likely to be examining?
Answer: The activities of the independent risk management and compliance functions.
The second line of defense is composed of the functions that oversee and challenge the risk-taking activities of the first line. This primarily includes the risk management function, the compliance function, and other control-related functions that report to senior management. Loan origination is a first-line function, internal audit is the third line, and the board is part of the overall governance structure.
Which of the following BEST describes the relationship between inherent risk, control effectiveness, and residual risk from a bank auditor's perspective?
Answer: A high level of inherent risk combined with weak control effectiveness will result in a high level of residual risk.
This question assesses a fundamental risk concept. Inherent risk is the risk present in an activity before any controls are applied. Controls are implemented to mitigate this risk. Residual risk is the level of risk that remains after controls have been implemented. Therefore, if the inherent risk is high and the controls designed to mitigate it are weak or ineffective, the resulting residual risk will also be high. Auditors evaluate this relationship to determine where to focus their testing efforts.