Risk Management & Internal Controls Flashcards
7 cards from real CFE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Management & Internal Controls flashcards as text
An insurance company fails to update its risk register after entering a new line of business. Which phase of the risk management cycle has been neglected?
Answer: Risk monitoring and review
Risk monitoring and review requires continual updating of risk documentation when business activities change, ensuring the risk profile remains current.
Which internal control principle requires that no single employee be able to both initiate and approve a financial transaction?
Answer: Segregation of duties
Segregation of duties divides transaction-processing responsibilities so one person cannot independently complete and conceal an entire transaction.
A state insurance regulator uses risk-based examination scheduling to prioritize which companies receive on-site financial examinations FIRST. What is the PRIMARY criterion for this prioritization?
Answer: Companies exhibiting the greatest risk of insolvency or regulatory concern
Risk-based examination scheduling prioritizes companies that pose the greatest risk of financial distress or regulatory non-compliance to protect policyholders.
Which risk response strategy involves reducing the likelihood or impact of a risk through implementing controls?
Answer: Risk mitigation
Risk mitigation (also called risk reduction) involves implementing controls or taking actions to lower the probability or impact of a risk event.
An examiner finds that a company's IT access rights have not been reviewed for two years. This is BEST described as a deficiency in which COSO internal control component?
Answer: Monitoring Activities
Monitoring Activities requires ongoing evaluation of internal controls, including periodic reviews of user access rights, to ensure controls remain effective.
Enterprise Risk Management (ERM) differs from traditional risk management PRIMARILY in that ERM:
Answer: Takes a holistic, portfolio view of all risks across the organization
ERM provides a holistic, organization-wide view of all risk categories—strategic, operational, financial, and compliance—rather than managing them independently.
A financial examiner identifies that an insurance company's board of directors lacks an independent audit committee. This deficiency MOST directly impacts which COSO component?
Answer: Control Environment
The Control Environment encompasses governance structures including board oversight; the absence of an independent audit committee weakens the foundation of all other internal controls.