Certified Public Accountant Risk Assessment & Management 2 — Questions and Answers
Question 1: Which component of the COSO ERM framework addresses how an entity identifies potential events that may affect the entity?
- Risk Response
- Event Identification (Correct answer)
- Objective Setting
- Internal Environment
Correct answer: Event Identification
Event Identification is the COSO ERM component focused on recognizing internal and external events that could affect achievement of objectives.
Question 2: A company's board of directors reviews management's risk appetite annually. This activity primarily demonstrates which risk governance principle?
- Risk tolerance monitoring
- Board oversight of risk management (Correct answer)
- Operational risk mitigation
- Regulatory compliance assurance
Correct answer: Board oversight of risk management
Board oversight of risk management is demonstrated when the board reviews and approves the risk appetite set by management.
Question 3: In a risk matrix, a risk scored as high likelihood but low impact would most appropriately be handled by:
- Immediate escalation to senior management
- Transfer to a third-party insurer
- Monitor and control with standard procedures (Correct answer)
- Terminate the activity causing the risk
Correct answer: Monitor and control with standard procedures
Risks with high likelihood but low impact are best managed through ongoing monitoring and standard control procedures rather than escalation or transfer.
Question 4: Which type of audit risk arises from the possibility that a material misstatement will not be detected by the auditor's procedures?
- Inherent risk
- Control risk
- Detection risk (Correct answer)
- Business risk
Correct answer: Detection risk
Detection risk is the risk that the auditor's substantive procedures will fail to detect a material misstatement that exists in an account balance or disclosure.
Question 5: An entity accepts certain risks because the cost of mitigation exceeds the expected loss. This is an example of which risk response strategy?
- Risk avoidance
- Risk acceptance (Correct answer)
- Risk reduction
- Risk sharing
Correct answer: Risk acceptance
Risk acceptance occurs when management decides to accept a risk because the cost or difficulty of responding exceeds the potential benefit.
Question 6: Residual risk is best defined as:
- The risk remaining after management applies risk responses (Correct answer)
- The initial risk before any controls are in place
- The portion of risk transferred to a third party
- The risk associated with material misstatements in financial statements
Correct answer: The risk remaining after management applies risk responses
Residual risk is the risk that remains after management has implemented risk responses and internal controls.
Question 7: Which risk assessment technique involves assigning numerical probabilities to possible outcomes to calculate expected value?
- Benchmarking
- Scenario analysis
- Probabilistic modeling (Correct answer)
- Control self-assessment
Correct answer: Probabilistic modeling
Probabilistic modeling uses statistical techniques to assign probabilities to outcomes and compute expected values for risk analysis.
Which component of the COSO ERM framework addresses how an entity identifies potential events that may affect the entity?