CPL CPL Risk Management & Compliance 2 — Questions and Answers
Question 1: When a program manager implements a workaround, it is a response to:
- A risk that has been accepted with a passive strategy
- An issue that was not anticipated and has no prior contingency plan (Correct answer)
- A risk that has been transferred to a third party
- A risk that has been fully mitigated in advance
Correct answer: An issue that was not anticipated and has no prior contingency plan
A workaround is an unplanned response to an issue or risk event that occurs without a prepared contingency, requiring an immediate improvised solution.
Question 2: In the context of program compliance, which of the following BEST describes due diligence?
- A legal requirement to report financial discrepancies to regulators
- A thorough investigation and verification process to ensure regulatory and policy adherence (Correct answer)
- The process of auditing vendor contracts for compliance gaps
- A risk escalation protocol used when thresholds are exceeded
Correct answer: A thorough investigation and verification process to ensure regulatory and policy adherence
Due diligence is a comprehensive review process that verifies a program meets all applicable legal, regulatory, and organizational compliance requirements.
Question 3: A risk that is identified as having high probability but low impact should MOST likely be handled by:
- Escalating to the program sponsor immediately
- Accepting the risk with active monitoring (Correct answer)
- Transferring the risk to an insurance provider
- Avoiding the risk by changing the program approach
Correct answer: Accepting the risk with active monitoring
High-probability, low-impact risks are typically accepted with active monitoring, as the cost of avoidance or transfer often outweighs the relatively minor impact.
Question 4: Which qualitative risk analysis tool uses expert opinion gathered through multiple anonymous rounds to build consensus on risk rankings?
- Probability and Impact Matrix
- Delphi technique (Correct answer)
- Monte Carlo simulation
- SWOT analysis
Correct answer: Delphi technique
The Delphi technique gathers anonymous expert input over multiple rounds, using feedback between rounds to converge on a consensus risk assessment.
Question 5: A secondary risk in program management is BEST defined as:
- A risk that is lower in priority than primary risks
- A new risk created directly by implementing a risk response (Correct answer)
- A risk that has been deferred to a later phase of the program
- A risk owned by a component project rather than the program level
Correct answer: A new risk created directly by implementing a risk response
Secondary risks arise as a direct consequence of a risk response action, meaning the solution to one risk introduces a new risk that must also be managed.
Question 6: Which program governance mechanism is responsible for reviewing and approving risk responses that exceed the program manager's authority or risk threshold?
- The change control board
- The program management office (PMO)
- The program governance board (Correct answer)
- The program sponsor
Correct answer: The program governance board
The program governance board provides oversight and approves decisions that exceed the program manager's delegated authority, including high-impact risk responses.
When a program manager implements a workaround, it is a response to: