โ† All Certified Internal Auditor Flashcard Decks

Risk Assessment & Management Flashcards

7 cards from real Certified Internal Auditor practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Assessment & Management flashcards as text
  1. Which risk assessment technique uses a structured group process to elicit expert opinions anonymously across multiple rounds?

    Answer: Delphi technique

    The Delphi technique gathers anonymous expert input through iterative questionnaire rounds until consensus is reached.

  2. Residual risk is best defined as the risk that remains after:

    Answer: Management implements controls

    Residual risk is the exposure that remains after management has applied controls to address inherent risk.

  3. An organization's risk appetite differs from its risk tolerance in that risk appetite represents:

    Answer: The broad level of risk an entity is willing to accept in pursuit of objectives

    Risk appetite is the overall amount of risk an entity is willing to accept, while risk tolerance is the acceptable deviation around specific objectives.

  4. When using a heat map to present risk assessment results, the axes typically represent:

    Answer: Likelihood and impact

    Heat maps plot risks on a two-dimensional grid of likelihood (probability) versus impact (consequence) to prioritize audit attention.

  5. Which of the following is an example of a risk response strategy known as 'risk sharing'?

    Answer: Purchasing insurance for property damage

    Insurance transfers a portion of financial risk to a third party, which is the essence of the risk sharing (transfer) response.

  6. Key Risk Indicators (KRIs) are most useful to internal auditors because they:

    Answer: Signal emerging risk before it materializes into loss

    KRIs are forward-looking metrics that alert management and auditors to increasing risk exposure before a loss event occurs.

  7. During a risk assessment, the internal auditor discovers that a control is effective but the underlying risk is very low. The auditor should conclude that:

    Answer: The cost-benefit of the control should be evaluated by management

    When a control's cost may exceed the benefit given a low-risk environment, it is the auditor's role to recommend that management evaluate the cost-effectiveness, not to unilaterally remove controls.