CFS Fraud Risk Assessment Frameworks 2 — Questions and Answers
Question 1: In the COSO ERM framework, which component specifically addresses the identification of potential events that could affect an organization's objectives?
- Risk Response
- Event Identification (Correct answer)
- Control Activities
- Objective Setting
Correct answer: Event Identification
Event Identification is the COSO ERM component where management identifies internal and external events that may affect the organization, distinguishing between risks and opportunities.
Question 2: A fraud risk assessment reveals a high-likelihood, low-impact scheme. According to risk management best practices, this risk should primarily be:
- Accepted without controls because the impact is low
- Transferred to an insurer immediately
- Mitigated with cost-effective preventive controls (Correct answer)
- Avoided by discontinuing the related business process
Correct answer: Mitigated with cost-effective preventive controls
High-likelihood risks warrant active mitigation even when impact is low, because frequent occurrences can accumulate into significant aggregate losses.
Question 3: Which fraud risk assessment technique involves comparing an organization's control environment against a defined set of criteria or standards?
- Benchmarking
- Brainstorming
- Delphi technique
- Benchmarking against a control framework (Correct answer)
Correct answer: Benchmarking against a control framework
Benchmarking against a control framework, such as COSO or ISO 31000, measures an organization's controls against established criteria to identify gaps.
Question 4: Under the ACFE's fraud risk management guide, which element is considered the foundation of an effective fraud risk management program?
- Robust data analytics capabilities
- Tone at the top and organizational culture (Correct answer)
- Comprehensive background check procedures
- Automated transaction monitoring systems
Correct answer: Tone at the top and organizational culture
The ACFE emphasizes that tone at the top and an ethical organizational culture are the foundational elements upon which all other fraud risk management efforts depend.
Question 5: When performing a fraud risk assessment, 'fraud schemes' are mapped to 'business processes' in order to:
- Determine the severity of penalties for perpetrators
- Identify which processes are most vulnerable to specific fraud types (Correct answer)
- Satisfy external audit documentation requirements
- Calculate the insurance premium for fraud coverage
Correct answer: Identify which processes are most vulnerable to specific fraud types
Mapping fraud schemes to business processes allows assessors to pinpoint where specific fraud opportunities exist within the organization's operations.
Question 6: A company's fraud risk appetite statement should be developed by:
- The external auditors during the annual audit
- The IT security team based on system vulnerabilities
- The board of directors with input from senior management (Correct answer)
- The internal audit department independently
Correct answer: The board of directors with input from senior management
The board of directors bears ultimate accountability for risk governance and should set the fraud risk appetite with input from senior management.
Question 7: Which of the following best describes a 'residual risk' in the context of fraud risk assessment?
- The risk of fraud that remains after management applies controls (Correct answer)
- The initial fraud risk before any controls are applied
- The risk transferred to a third party through insurance
- The risk identified but deemed immaterial for reporting
Correct answer: The risk of fraud that remains after management applies controls
Residual risk is the exposure that remains after existing controls have been applied to the inherent risk, representing the net fraud exposure.
In the COSO ERM framework, which component specifically addresses the identification of potential events that could affect an organization's objectives?