CFE Risk Management & Internal Controls 2 — Questions and Answers
Question 1: Under the COSO ERM framework, which component involves identifying potential events that could affect an organization's ability to achieve its objectives?
- Risk Assessment
- Event Identification (Correct answer)
- Control Activities
- Objective Setting
Correct answer: Event Identification
Event Identification is the COSO ERM component focused on recognizing potential events—both internal and external—that could impact achievement of objectives.
Question 2: A financial examiner discovers that a company's management has the ability to override established internal controls. This situation MOST directly threatens which objective of internal controls?
- Operational efficiency
- Reliability of financial reporting (Correct answer)
- Compliance with laws
- Safeguarding of assets
Correct answer: Reliability of financial reporting
Management override of controls most directly undermines the reliability of financial reporting, as it creates a pathway for intentional misstatement.
Question 3: A residual risk level that exceeds an organization's risk appetite should MOST appropriately trigger which action?
- Documenting the risk in the register only
- Accepting the risk without further action
- Implementing additional controls or revising risk response (Correct answer)
- Transferring responsibility to an external auditor
Correct answer: Implementing additional controls or revising risk response
When residual risk exceeds risk appetite, management must implement additional controls or adjust the risk response strategy to bring exposure within acceptable limits.
Question 4: Which type of insurance mechanism allows an insurer to limit exposure by passing a portion of risk to another insurer?
- Co-insurance
- Reinsurance (Correct answer)
- Self-insurance
- Captive insurance
Correct answer: Reinsurance
Reinsurance is the mechanism by which an insurer transfers a portion of its risk exposure to a reinsurer to limit its own potential losses.
Question 5: During an examination of an insurance company, which internal control is MOST effective at detecting unauthorized changes to policy reserve calculations?
- Segregation of duties between actuaries and IT staff
- Periodic reconciliation of reserve reports to the general ledger (Correct answer)
- Annual external actuarial review
- Management certification of financial statements
Correct answer: Periodic reconciliation of reserve reports to the general ledger
Periodic reconciliation of reserve reports to the general ledger is a detective control that identifies discrepancies between actuarial records and financial records.
Question 6: The 'three lines of defense' model assigns internal audit to which line?
- First line
- Second line
- Third line (Correct answer)
- Fourth line
Correct answer: Third line
Internal audit occupies the third line of defense, providing independent assurance over the effectiveness of risk management and control activities.
Question 7: A key risk indicator (KRI) that shows a metric approaching a threshold level MOST likely serves what purpose for management?
- Documenting past losses for regulatory filing
- Providing an early warning signal for emerging risks (Correct answer)
- Replacing the need for detective controls
- Satisfying external audit requirements
Correct answer: Providing an early warning signal for emerging risks
KRIs provide early warning signals, alerting management when risk exposure is trending toward an unacceptable level before a loss event occurs.
Under the COSO ERM framework, which component involves identifying potential events that could affect an organization's ability to achieve its objectives?