CFE Risk Management & Internal Controls 3 ā Questions and Answers
Question 1: An insurance company fails to update its risk register after entering a new line of business. Which phase of the risk management cycle has been neglected?
- Risk financing
- Risk monitoring and review (Correct answer)
- Risk treatment
- Risk communication
Correct answer: Risk monitoring and review
Risk monitoring and review requires continual updating of risk documentation when business activities change, ensuring the risk profile remains current.
Question 2: Which internal control principle requires that no single employee be able to both initiate and approve a financial transaction?
- Dual control
- Segregation of duties (Correct answer)
- Physical safeguarding
- Authorization hierarchy
Correct answer: Segregation of duties
Segregation of duties divides transaction-processing responsibilities so one person cannot independently complete and conceal an entire transaction.
Question 3: A state insurance regulator uses risk-based examination scheduling to prioritize which companies receive on-site financial examinations FIRST. What is the PRIMARY criterion for this prioritization?
- Companies with the largest premium volume
- Companies exhibiting the greatest risk of insolvency or regulatory concern (Correct answer)
- Companies that have not been examined in the longest period
- Companies operating in multiple states
Correct answer: Companies exhibiting the greatest risk of insolvency or regulatory concern
Risk-based examination scheduling prioritizes companies that pose the greatest risk of financial distress or regulatory non-compliance to protect policyholders.
Question 4: Which risk response strategy involves reducing the likelihood or impact of a risk through implementing controls?
- Risk avoidance
- Risk transfer
- Risk mitigation (Correct answer)
- Risk acceptance
Correct answer: Risk mitigation
Risk mitigation (also called risk reduction) involves implementing controls or taking actions to lower the probability or impact of a risk event.
Question 5: An examiner finds that a company's IT access rights have not been reviewed for two years. This is BEST described as a deficiency in which COSO internal control component?
- Control Environment
- Risk Assessment
- Monitoring Activities (Correct answer)
- Control Activities
Correct answer: Monitoring Activities
Monitoring Activities requires ongoing evaluation of internal controls, including periodic reviews of user access rights, to ensure controls remain effective.
Question 6: Enterprise Risk Management (ERM) differs from traditional risk management PRIMARILY in that ERM:
- Focuses exclusively on insurable risks
- Addresses risks in silos by department
- Takes a holistic, portfolio view of all risks across the organization (Correct answer)
- Eliminates the need for internal audit
Correct answer: Takes a holistic, portfolio view of all risks across the organization
ERM provides a holistic, organization-wide view of all risk categoriesāstrategic, operational, financial, and complianceārather than managing them independently.
Question 7: A financial examiner identifies that an insurance company's board of directors lacks an independent audit committee. This deficiency MOST directly impacts which COSO component?
- Information and Communication
- Control Activities
- Monitoring Activities
- Control Environment (Correct answer)
Correct answer: Control Environment
The Control Environment encompasses governance structures including board oversight; the absence of an independent audit committee weakens the foundation of all other internal controls.
An insurance company fails to update its risk register after entering a new line of business.
Which phase of the risk management cycle has been neglected?