CGAP Risk-Control Frameworks 5 — Questions and Answers
Question 1: Which COSO ERM 2017 component includes 'Performance' as a key area where risk is identified, assessed, and prioritized in relation to risk appetite?
- Strategy and Objective-Setting
- Performance (Correct answer)
- Review and Revision
- Governance and Culture
Correct answer: Performance
In COSO ERM 2017, the Performance component is where risks are identified, assessed, prioritized, and responded to in relation to the entity's risk appetite.
Question 2: A government auditor assesses control effectiveness by reviewing whether controls operate consistently over time. This type of evaluation is best described as:
- Design effectiveness testing
- Operating effectiveness testing (Correct answer)
- Walkthrough testing
- Substantive testing
Correct answer: Operating effectiveness testing
Operating effectiveness testing determines whether a control has functioned consistently as designed throughout the period under review, not just whether the design is sound.
Question 3: In risk management, 'risk velocity' refers to:
- The financial magnitude of a risk event
- The speed at which a risk can impact the organization once triggered (Correct answer)
- The frequency with which a risk event occurs
- The number of risks identified per audit cycle
Correct answer: The speed at which a risk can impact the organization once triggered
Risk velocity measures how quickly a risk could impact the organization after it materializes, influencing how much response time management has.
Question 4: Under FISMA, federal agencies must implement an information security program that includes which of the following risk management activities?
- Annual external financial audits of all IT systems
- Categorization, selection, implementation, and assessment of security controls using NIST guidelines (Correct answer)
- Mandatory adoption of ISO 27001 certification
- Outsourcing all cybersecurity functions to OMB
Correct answer: Categorization, selection, implementation, and assessment of security controls using NIST guidelines
FISMA requires agencies to categorize information and systems, select and implement appropriate NIST-based security controls, and regularly assess their effectiveness.
Question 5: A control that prevents a risk event from occurring is classified as:
- Detective
- Corrective
- Preventive (Correct answer)
- Compensating
Correct answer: Preventive
Preventive controls are designed to deter or prevent error, fraud, or other undesirable events before they occur.
Question 6: In a three lines of defense model, which line is responsible for designing and operating risk management and internal control frameworks?
- First line – operational management
- Second line – risk and compliance functions (Correct answer)
- Third line – internal audit
- Fourth line – external audit
Correct answer: Second line – risk and compliance functions
The second line of defense comprises risk management and compliance functions that design frameworks, set policies, and monitor the first line's risk and control activities.
Question 7: When auditing a government entity's ERM program, which finding would MOST indicate a mature, integrated risk management culture?
- Risk assessments are performed annually by the internal audit department only
- Risk information is embedded in strategic planning, budgeting, and performance reporting processes (Correct answer)
- The risk register is maintained solely in spreadsheet format by one risk officer
- Risk appetite is defined verbally by the CFO without board documentation
Correct answer: Risk information is embedded in strategic planning, budgeting, and performance reporting processes
A mature ERM culture integrates risk information across strategic planning, budgeting, and performance management rather than treating it as a separate compliance exercise.
Which COSO ERM 2017 component includes 'Performance' as a key area where risk is identified, assessed, and prioritized in relation to risk appetite?