CORES Risk Control Strategies & Mitigation Planning 4 — Questions and Answers
Question 1: An organization maps its controls to specific risks in a Risk and Control Self-Assessment (RCSA). What is the PRIMARY purpose of this mapping?
- To satisfy external auditors with documentation
- To identify control gaps and ensure every significant risk has adequate coverage (Correct answer)
- To rank risks by financial impact for the CFO
- To automate control testing across all business units
Correct answer: To identify control gaps and ensure every significant risk has adequate coverage
Control mapping in an RCSA reveals where risks lack adequate coverage, enabling targeted remediation of control gaps.
Question 2: Which mitigation approach is MOST appropriate for an operational risk that is high in likelihood but low in impact?
- Risk avoidance by exiting the business line
- Frequent monitoring and process-level preventive controls (Correct answer)
- Full insurance coverage to transfer financial exposure
- Board-level formal acceptance without controls
Correct answer: Frequent monitoring and process-level preventive controls
High-likelihood, low-impact risks are best managed through process controls and monitoring to reduce frequency and operational disruption.
Question 3: In a risk control matrix, 'control effectiveness rating' refers to:
- The financial cost of implementing the control
- The degree to which a control reduces the likelihood or impact of a risk (Correct answer)
- The number of employees trained on the control
- The frequency at which the control is tested by internal audit
Correct answer: The degree to which a control reduces the likelihood or impact of a risk
Control effectiveness measures how well a control actually reduces risk likelihood or impact, which is the core metric in a risk control matrix.
Question 4: Third-party risk management is an extension of operational risk control because:
- Vendors are legally responsible for all risks they introduce
- Outsourced activities retain the firm's operational risk exposure even when performed externally (Correct answer)
- Third-party contracts eliminate the need for internal controls
- Regulatory bodies manage third-party risks on behalf of financial institutions
Correct answer: Outsourced activities retain the firm's operational risk exposure even when performed externally
Outsourcing transfers activities but not accountability; the firm retains operational risk exposure and must maintain oversight and controls.
Question 5: A 'compensating control' is BEST defined as:
- A control that pays employees for reporting risk events
- An alternative control that mitigates risk when a primary control cannot be implemented (Correct answer)
- A control that compensates for insurance coverage gaps
- A secondary approval layer added to all financial transactions
Correct answer: An alternative control that mitigates risk when a primary control cannot be implemented
Compensating controls are substitutes deployed when the ideal primary control is not feasible, providing an alternative risk mitigation mechanism.
Question 6: Which metric is MOST useful for evaluating whether a risk mitigation plan is achieving its intended outcome over time?
- Number of controls documented in the risk register
- Trend analysis of Key Risk Indicators before and after control implementation (Correct answer)
- Total budget allocated to the risk management department
- Number of risk events reported by employees
Correct answer: Trend analysis of Key Risk Indicators before and after control implementation
Tracking KRI trends before and after control implementation provides direct evidence of whether mitigation efforts are reducing risk levels.
Question 7: Under the COSO ERM framework, which component directly addresses the design and deployment of risk responses, including mitigation strategies?
- Risk Appetite and Strategy
- Risk Response (Correct answer)
- Control Activities
- Event Identification
Correct answer: Risk Response
The 'Risk Response' component of COSO ERM is where organizations select and implement strategies such as avoidance, reduction, transfer, or acceptance.
An organization maps its controls to specific risks in a Risk and Control Self-Assessment (RCSA).
What is the PRIMARY purpose of this mapping?