CPHR Risk Assessment and Management 2 — Questions and Answers
Question 1: A company's HR department discovers that a key employee has been sharing confidential compensation data with competitors. Which risk category does this primarily fall under?
- Strategic risk
- Operational risk (Correct answer)
- Compliance risk
- Reputational risk
Correct answer: Operational risk
Unauthorized disclosure of confidential data by an employee is an operational risk, as it stems from internal processes and human behavior failures.
Question 2: When conducting a risk probability assessment, an HR manager rates a risk as 'likely' with 'significant' impact. On a standard 5x5 risk matrix, this would typically fall in which zone?
- Green (low risk)
- Yellow (moderate risk)
- Orange (high risk) (Correct answer)
- Red (critical risk)
Correct answer: Orange (high risk)
A 'likely' probability combined with 'significant' impact typically places a risk in the high (orange) zone on a standard risk matrix, requiring prompt mitigation.
Question 3: Which approach to risk treatment involves an organization choosing not to engage in an activity that creates unacceptable risk exposure?
- Risk mitigation
- Risk transfer
- Risk avoidance (Correct answer)
- Risk acceptance
Correct answer: Risk avoidance
Risk avoidance means deciding not to pursue or continue an activity because its associated risks exceed the organization's tolerance level.
Question 4: An organization implements an employee wellness program to reduce workers' compensation claims. This is an example of which risk management strategy?
- Risk transfer
- Risk avoidance
- Risk reduction (Correct answer)
- Risk retention
Correct answer: Risk reduction
Risk reduction (mitigation) involves taking proactive steps to lower the likelihood or impact of a risk, such as wellness programs that decrease injury-related claims.
Question 5: Under the OSHA General Duty Clause, employers are required to:
- Provide health insurance to all employees
- Maintain a workplace free from recognized serious hazards (Correct answer)
- Conduct annual risk assessments for all job roles
- Report all near-miss incidents to OSHA within 24 hours
Correct answer: Maintain a workplace free from recognized serious hazards
The OSHA General Duty Clause (Section 5(a)(1)) requires employers to furnish a workplace free from recognized hazards likely to cause death or serious physical harm.
Question 6: Which risk management framework, developed by COSO, is most commonly referenced when organizations align enterprise risk management with strategic objectives?
- ISO 31000
- COSO ERM Framework (Correct answer)
- NIST Cybersecurity Framework
- Basel III
Correct answer: COSO ERM Framework
The COSO Enterprise Risk Management (ERM) Framework is widely adopted for integrating risk management with governance, strategy, and performance.
Question 7: A company self-insures for workers' compensation claims up to $250,000 and purchases excess insurance above that amount. This arrangement is an example of:
- Pure risk transfer
- Risk avoidance
- Risk financing through retention with transfer (Correct answer)
- Complete risk elimination
Correct answer: Risk financing through retention with transfer
Retaining risk up to a threshold (self-insurance) while transferring excess exposure to an insurer is a risk financing strategy combining retention and transfer.
A company's HR department discovers that a key employee has been sharing confidential compensation data with competitors.
Which risk category does this primarily fall under?