CGAP Risk-Control Frameworks 4 — Questions and Answers
Question 1: A government auditor evaluates a department's risk register and finds risks listed without assigned owners. What critical risk management element is missing?
- Risk identification
- Risk ownership and accountability (Correct answer)
- Risk quantification
- Risk appetite statement
Correct answer: Risk ownership and accountability
Every identified risk should have a designated owner responsible for monitoring and managing it; without ownership, risk responses may go unimplemented.
Question 2: Under the GAO Green Book, which internal control component encompasses the entity's commitment to competence and the human capital practices that support the workforce?
- Control Activities
- Risk Assessment
- Control Environment (Correct answer)
- Monitoring
Correct answer: Control Environment
The Control Environment includes management's commitment to attracting, developing, and retaining competent individuals, which is foundational to all other internal control components.
Question 3: Which quantitative risk analysis technique uses probability distributions and thousands of simulations to model the range of possible risk outcomes?
- Failure Mode and Effects Analysis (FMEA)
- Monte Carlo simulation (Correct answer)
- Delphi technique
- Fishbone diagram analysis
Correct answer: Monte Carlo simulation
Monte Carlo simulation runs thousands of scenarios using probability distributions for uncertain variables to produce a range of possible outcomes and their likelihoods.
Question 4: In ERM, 'risk aggregation' refers to:
- Eliminating duplicate risks from the risk register
- Combining individual risks to understand their cumulative effect on objectives (Correct answer)
- Assigning all risks to a single risk owner
- Reporting only the highest-rated risks to leadership
Correct answer: Combining individual risks to understand their cumulative effect on objectives
Risk aggregation combines individual risks across the organization to assess their combined or portfolio-level effect on strategic objectives.
Question 5: A state auditor reviewing procurement controls notes that purchase orders are approved by the same individual who receives goods. Which control principle is violated?
- Dual authorization
- Separation of duties (Correct answer)
- Management override prevention
- Physical safeguarding
Correct answer: Separation of duties
Separation of duties requires that incompatible functions—such as authorization and custody—be performed by different individuals to prevent and detect errors and fraud.
Question 6: Which risk framework element defines the boundaries within which an organization is willing to operate, expressed as quantitative or qualitative limits?
- Risk appetite
- Risk tolerance (Correct answer)
- Risk capacity
- Risk velocity
Correct answer: Risk tolerance
Risk tolerance specifies the acceptable level of variation from risk appetite through specific thresholds or limits that guide day-to-day decision-making.
Question 7: When the GAO Green Book refers to 'complementary user entity controls,' it means controls that:
- Are performed exclusively by the service organization
- Must be implemented by the user entity to complete the service organization's control objectives (Correct answer)
- Replace the need for the service auditor's report
- Apply only to cybersecurity risks
Correct answer: Must be implemented by the user entity to complete the service organization's control objectives
Complementary user entity controls are controls that the service organization assumes the user entity will implement in order for the combined controls to achieve their objectives.
A government auditor evaluates a department's risk register and finds risks listed without assigned owners.
What critical risk management element is missing?