Corporate Governance Risk Management & Internal Controls 2 — Questions and Answers
Question 1: What is the 'three lines of defense' model in risk management?
- A risk governance structure where business units, risk/compliance functions, and internal audit provide layered oversight (Correct answer)
- A cybersecurity framework using firewalls, encryption, and monitoring
- A board governance model with independent directors, audit committee, and external auditors
- A regulatory model using company filings, SEC review, and judicial enforcement
Correct answer: A risk governance structure where business units, risk/compliance functions, and internal audit provide layered oversight
The three lines model defines business operations (1st line), risk and compliance functions (2nd line), and internal audit (3rd line) as distinct but complementary risk oversight layers.
Question 2: What is a 'key risk indicator' (KRI)?
- A metric that provides an early warning signal about increasing risk exposure (Correct answer)
- A financial ratio used in credit underwriting decisions
- A compliance checklist item required by regulatory bodies
- An internal audit finding that requires remediation within 30 days
Correct answer: A metric that provides an early warning signal about increasing risk exposure
KRIs are forward-looking metrics that signal when risk levels are rising toward thresholds that require management attention or action.
Question 3: What does 'risk appetite' mean in corporate governance?
- The amount and type of risk an organization is willing to accept in pursuit of its objectives (Correct answer)
- The maximum financial loss a company can survive in a crisis scenario
- The risk tolerance set by regulators for a specific industry
- The level of risk reflected in a company's insurance coverage limits
Correct answer: The amount and type of risk an organization is willing to accept in pursuit of its objectives
Risk appetite is the board-established statement of how much risk the organization is willing to take on in pursuit of value creation, guiding management's risk-taking decisions.
Question 4: What is the purpose of an internal audit function?
- To provide independent assurance that internal controls, risk management, and governance processes are effective (Correct answer)
- To prepare the annual financial statements for external review
- To negotiate insurance contracts on behalf of the company
- To conduct criminal investigations into employee fraud
Correct answer: To provide independent assurance that internal controls, risk management, and governance processes are effective
Internal audit provides the board and management with independent, objective assurance and consulting on risk management, control effectiveness, and governance processes.
Question 5: What is a 'whistleblower program' and why is it important to corporate governance?
- A system allowing employees to report misconduct confidentially, helping detect fraud and control failures early (Correct answer)
- A program that pays bonuses to external auditors who find material misstatements
- A regulatory requirement for companies to publicly report all employee complaints
- A software system that monitors employee communications for policy violations
Correct answer: A system allowing employees to report misconduct confidentially, helping detect fraud and control failures early
Whistleblower programs encourage employees and others to report misconduct by providing confidential reporting channels and legal protections against retaliation.
Question 6: What is 'cyber risk governance' in the context of board responsibilities?
- The board's oversight of cybersecurity strategy, incident response preparedness, and disclosure obligations (Correct answer)
- The IT department's management of firewall and intrusion detection systems
- The CFO's reporting of cyber insurance premiums to the audit committee
- The SEC's annual review of company cybersecurity filings
Correct answer: The board's oversight of cybersecurity strategy, incident response preparedness, and disclosure obligations
Boards are expected to oversee cybersecurity risks, ensuring management has adequate resources and strategies and that material incidents are properly disclosed.
What is the 'three lines of defense' model in risk management?