Risk Management & Internal Controls Flashcards
7 cards from real CFE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Management & Internal Controls flashcards as text
Under the NAIC Financial Condition Examiners Handbook, which examination approach emphasizes evaluating management's risk oversight processes rather than testing all individual transactions?
Answer: Risk-focused examination approach
The risk-focused examination approach directs examiner resources toward assessing how well management identifies and controls risks rather than exhaustively testing individual transactions.
Which of the following BEST describes the concept of 'control risk' in an examination context?
Answer: The risk that the entity's internal controls will fail to prevent or detect a material misstatement
Control risk is the risk that an entity's internal controls will not prevent, detect, or correct a material misstatement on a timely basis.
A 'stress test' performed on an insurance company's investment portfolio MOST directly assesses:
Answer: How the portfolio's value and liquidity would be affected under adverse market scenarios
Stress testing evaluates how a portfolio performs under hypothetical adverse conditions—such as market crashes or interest rate spikes—to identify potential vulnerabilities.
An insurer's risk appetite statement specifies a maximum tolerable combined ratio of 105%. If the current combined ratio is 108%, management's MOST appropriate response under ERM principles is to:
Answer: Escalate to the board and implement corrective actions to reduce the ratio
Exceeding a stated risk appetite threshold requires escalation to governance and implementation of corrective actions to bring performance back within acceptable bounds.
Which internal control activity BEST ensures that journal entries recorded in the general ledger are authorized and accurate?
Answer: Requiring supervisory approval of all manual journal entries with supporting documentation
Requiring supervisory approval with supporting documentation for manual journal entries is a preventive authorization control that deters and detects unauthorized or erroneous entries.
The process by which an organization systematically evaluates its risk exposures and selects the optimal mix of risk retention, avoidance, reduction, and transfer is called:
Answer: Risk treatment
Risk treatment is the process of selecting and implementing measures—such as avoidance, reduction, transfer, or acceptance—to manage identified risk exposures.
A financial examiner notes that an insurer's internal audit function reports directly to the CFO rather than to the board audit committee. The MAIN concern with this reporting structure is:
Answer: The CFO may restrict audit scope, impairing internal audit independence
When internal audit reports to management rather than to the board, the CFO can limit audit scope or suppress findings, compromising the independence that makes internal audit effective.