Certified Public Accountant Risk Assessment & Management 4 — Questions and Answers
Question 1: Which of the following best describes 'risk appetite' in the context of enterprise risk management?
- The maximum loss an entity can sustain before becoming insolvent
- The amount of risk an entity is willing to accept in pursuit of its objectives (Correct answer)
- The total value of all risks identified in a risk register
- The level of risk transferred to third parties through insurance
Correct answer: The amount of risk an entity is willing to accept in pursuit of its objectives
Risk appetite is the broad amount of risk an entity is willing to accept in pursuit of value, established by the board and senior management.
Question 2: A control that detects errors after they have already occurred is classified as a:
- Preventive control
- Detective control (Correct answer)
- Corrective control
- Directive control
Correct answer: Detective control
Detective controls are designed to identify errors or irregularities that have already occurred, such as account reconciliations or exception reports.
Question 3: Which scenario best illustrates the risk of 'concentration risk'?
- A manufacturer sources 90% of a critical component from a single supplier (Correct answer)
- A company holds cash in multiple bank accounts
- An investor diversifies across 50 different securities
- An audit firm rotates engagement partners every five years
Correct answer: A manufacturer sources 90% of a critical component from a single supplier
Concentration risk arises when a company is overly dependent on a single source, customer, supplier, or geography, increasing vulnerability to disruption.
Question 4: Under AU-C Section 315, when must an auditor perform risk assessment procedures?
- Only at the completion of the audit
- Throughout the planning phase and early fieldwork (Correct answer)
- Only when fraud indicators are detected
- After internal controls have been tested
Correct answer: Throughout the planning phase and early fieldwork
AU-C 315 requires auditors to perform risk assessment procedures during planning to obtain an understanding of the entity and its environment, including internal controls.
Question 5: A company discovers that its fraud risk assessments did not consider the risk of management override of controls. This represents a gap in which COSO Internal Control component?
- Control Activities
- Risk Assessment (Correct answer)
- Monitoring Activities
- Information and Communication
Correct answer: Risk Assessment
Risk Assessment in the COSO framework requires identifying and analyzing risks to achieving objectives, including the risk of management override and fraud.
Question 6: Which measure best quantifies the potential loss from a risk at a specific confidence level over a defined time horizon?
- Expected loss (EL)
- Value at Risk (VaR) (Correct answer)
- Return on risk-adjusted capital (RAROC)
- Key risk indicator (KRI)
Correct answer: Value at Risk (VaR)
Value at Risk (VaR) quantifies the maximum expected loss over a defined period at a given confidence level (e.g., 95% or 99%).
Question 7: When evaluating the severity of a risk, which two dimensions are typically used?
- Frequency and controllability
- Likelihood and impact (Correct answer)
- Proximity and velocity
- Exposure and tolerance
Correct answer: Likelihood and impact
Risk severity is most commonly assessed using likelihood (probability of occurrence) and impact (magnitude of effect if the risk occurs).
Which of the following best describes 'risk appetite' in the context of enterprise risk management?