CIG Risk Management & Compliance 2 — Questions and Answers
Question 1: Which risk assessment methodology assigns numerical probabilities to potential outcomes to quantify the expected impact of a risk event?
- Qualitative risk analysis
- Quantitative risk analysis (Correct answer)
- Risk tolerance benchmarking
- Residual risk mapping
Correct answer: Quantitative risk analysis
Quantitative risk analysis uses numerical values and statistical techniques to calculate the probability and monetary impact of risk events.
Question 2: An inspector general discovers that a program office bypassed required internal controls citing a time-sensitive emergency. What is the FIRST step the IG should take?
- Immediately report the violation to Congress
- Verify whether an emergency waiver process exists and was followed (Correct answer)
- Suspend the program pending a full audit
- Issue a subpoena for all related records
Correct answer: Verify whether an emergency waiver process exists and was followed
Before concluding a violation occurred, the IG should determine whether an authorized emergency exception or waiver process exists and whether it was properly invoked.
Question 3: Under OMB Circular A-123, what is the primary purpose of management's assessment of internal control?
- To replace the annual independent audit
- To provide reasonable assurance that federal programs achieve objectives and safeguard assets (Correct answer)
- To certify zero risk across all programs
- To satisfy congressional earmark requirements
Correct answer: To provide reasonable assurance that federal programs achieve objectives and safeguard assets
OMB Circular A-123 requires agencies to assess internal controls to provide reasonable assurance over operations, reporting, and compliance objectives.
Question 4: Which term describes the risk that remains after management implements controls to mitigate an identified risk?
- Inherent risk
- Control risk
- Residual risk (Correct answer)
- Detection risk
Correct answer: Residual risk
Residual risk is the exposure that persists after mitigating controls are applied, distinguishing it from inherent risk (pre-control exposure).
Question 5: A compliance program is considered effective when it does which of the following?
- Eliminates all instances of non-compliance
- Detects, prevents, and corrects violations while promoting an ethical culture (Correct answer)
- Ensures every employee passes an annual ethics test
- Transfers all compliance risk to external auditors
Correct answer: Detects, prevents, and corrects violations while promoting an ethical culture
An effective compliance program combines preventive, detective, and corrective elements within a culture of integrity—not a guarantee of zero violations.
Question 6: In the COSO Internal Control—Integrated Framework, which component addresses the organization's values, ethics, and commitment to competence?
- Risk Assessment
- Control Activities
- Control Environment (Correct answer)
- Monitoring Activities
Correct answer: Control Environment
The Control Environment is the foundation of the COSO framework, encompassing tone at the top, integrity, ethical values, and management's commitment to competence.
Question 7: When risk appetite and risk tolerance are used together, what is the key distinction between them?
- Risk appetite is quantitative; risk tolerance is qualitative
- Risk appetite is the broad level of risk an entity accepts; risk tolerance is the acceptable variance around specific objectives (Correct answer)
- Risk tolerance is set by the board; risk appetite is set by management
- They are interchangeable terms for the same concept
Correct answer: Risk appetite is the broad level of risk an entity accepts; risk tolerance is the acceptable variance around specific objectives
Risk appetite defines the overall willingness to accept risk, while risk tolerance establishes the acceptable deviation from specific performance targets.
Which risk assessment methodology assigns numerical probabilities to potential outcomes to quantify the expected impact of a risk event?