โ† All CFS Flashcard Decks

Fraud Risk Assessment Frameworks Flashcards

7 cards from real CFS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Fraud Risk Assessment Frameworks flashcards as text
  1. In the COSO ERM framework, which component specifically addresses the identification of potential events that could affect an organization's objectives?

    Answer: Event Identification

    Event Identification is the COSO ERM component where management identifies internal and external events that may affect the organization, distinguishing between risks and opportunities.

  2. A fraud risk assessment reveals a high-likelihood, low-impact scheme. According to risk management best practices, this risk should primarily be:

    Answer: Mitigated with cost-effective preventive controls

    High-likelihood risks warrant active mitigation even when impact is low, because frequent occurrences can accumulate into significant aggregate losses.

  3. Which fraud risk assessment technique involves comparing an organization's control environment against a defined set of criteria or standards?

    Answer: Benchmarking against a control framework

    Benchmarking against a control framework, such as COSO or ISO 31000, measures an organization's controls against established criteria to identify gaps.

  4. Under the ACFE's fraud risk management guide, which element is considered the foundation of an effective fraud risk management program?

    Answer: Tone at the top and organizational culture

    The ACFE emphasizes that tone at the top and an ethical organizational culture are the foundational elements upon which all other fraud risk management efforts depend.

  5. When performing a fraud risk assessment, 'fraud schemes' are mapped to 'business processes' in order to:

    Answer: Identify which processes are most vulnerable to specific fraud types

    Mapping fraud schemes to business processes allows assessors to pinpoint where specific fraud opportunities exist within the organization's operations.

  6. A company's fraud risk appetite statement should be developed by:

    Answer: The board of directors with input from senior management

    The board of directors bears ultimate accountability for risk governance and should set the fraud risk appetite with input from senior management.

  7. Which of the following best describes a 'residual risk' in the context of fraud risk assessment?

    Answer: The risk of fraud that remains after management applies controls

    Residual risk is the exposure that remains after existing controls have been applied to the inherent risk, representing the net fraud exposure.