CGAP Risk-Control Frameworks 2 β Questions and Answers
Question 1: In the COSO ERM framework, which component ensures that risk responses are identified and selected to bring residual risk within desired tolerance?
- Risk Assessment
- Risk Response (Correct answer)
- Control Activities
- Event Identification
Correct answer: Risk Response
Risk Response is the COSO ERM component where management selects risk responsesβavoiding, accepting, reducing, or sharing riskβto align residual risk with risk tolerance.
Question 2: A government agency uses a heat map to display risks. What two dimensions are typically plotted on a risk heat map?
- Cost and time
- Likelihood and impact (Correct answer)
- Frequency and velocity
- Detectability and controllability
Correct answer: Likelihood and impact
Risk heat maps plot likelihood (probability) on one axis and impact (consequence) on the other to visually prioritize risks.
Question 3: Which NIST SP 800-39 tier addresses risk at the mission/business process level in a government organization?
- Tier 1 β Organization
- Tier 2 β Mission/Business Process (Correct answer)
- Tier 3 β Information System
- Tier 4 β Operations
Correct answer: Tier 2 β Mission/Business Process
NIST SP 800-39 defines Tier 2 as the mission/business process level, which addresses risk from the perspective of core organizational functions.
Question 4: Under the GAO Green Book (Standards for Internal Control in the Federal Government), which principle requires management to define objectives with sufficient clarity to identify associated risks?
- CC3.01 β Specify Suitable Objectives (Correct answer)
- CC1.01 β Demonstrate Commitment to Integrity
- CC4.01 β Conduct Ongoing Evaluations
- CC2.01 β Use Quality Information
Correct answer: CC3.01 β Specify Suitable Objectives
Green Book principle CC3.01 requires management to specify objectives clearly so that risks to achieving them can be identified and assessed.
Question 5: An auditor discovers that a public sector entity has no documented process for monitoring changes in the external environment that could introduce new risks. Which COSO ERM component is deficient?
- Internal Environment
- Objective Setting
- Risk Identification
- Monitoring (Correct answer)
Correct answer: Monitoring
Monitoring involves reviewing the ERM process over time, including changes in the external environment that could alter the risk profile; its absence indicates a monitoring deficiency.
Question 6: Residual risk differs from inherent risk in that residual risk is measured:
- Before any controls are applied
- After management's risk response and controls are applied (Correct answer)
- Using only quantitative methods
- By external auditors rather than management
Correct answer: After management's risk response and controls are applied
Residual risk is the risk remaining after management has implemented controls and other risk responses, whereas inherent risk exists before any controls.
Question 7: Which key risk indicator (KRI) characteristic makes it most useful for proactive risk management in a government audit context?
- It reports on losses that have already occurred
- It provides a leading signal before a risk event materializes (Correct answer)
- It replaces the need for key performance indicators
- It is derived exclusively from financial data
Correct answer: It provides a leading signal before a risk event materializes
A KRI serves as a leading indicator, warning management that risk levels are changing before an adverse event occurs, enabling proactive action.
In the COSO ERM framework, which component ensures that risk responses are identified and selected to bring residual risk within desired tolerance?