Risk Assessment & Management Flashcards
7 cards from real Certified Internal Auditor practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Assessment & Management flashcards as text
The Three Lines Model assigns primary responsibility for risk management and internal controls to:
Answer: Operational management (first line)
In the Three Lines Model, operational management (first line) owns and manages risks as part of day-to-day activities.
Scenario analysis differs from sensitivity analysis in that scenario analysis:
Answer: Examines the effect of multiple simultaneous variable changes
Scenario analysis evaluates the combined impact of multiple risk factors changing simultaneously, while sensitivity analysis varies one variable at a time.
An auditor is evaluating a risk that has a 10% probability of occurring and would result in a $500,000 loss. The expected value of this risk is:
Answer: $50,000
Expected value = probability × impact = 0.10 × $500,000 = $50,000.
Which of the following is a primary limitation of relying solely on historical data for risk assessment?
Answer: Past events may not reflect future risk exposures accurately
Historical data reflects past conditions; new technologies, markets, or operating environments can produce novel risks not captured in historical records.
A control that reduces the likelihood of a risk event occurring is classified as a:
Answer: Preventive control
Preventive controls are designed to stop risk events from happening, reducing their probability of occurrence.
Which of the following best describes 'inherent risk' in an audit context?
Answer: The gross risk exposure before any controls are applied
Inherent risk is the level of risk that exists in the absence of any management controls or mitigating actions.
A risk culture assessment by internal audit would MOST likely include evaluating:
Answer: Whether employees feel safe reporting risk concerns without retaliation
A healthy risk culture requires psychological safety; auditors assess whether employees can raise concerns freely, which underpins the entire risk management system.