CPS Risk Management & Mitigation 3 — Questions and Answers
Question 1: Which of the following best describes 'inherent risk' in process management?
- Risk after all controls have been applied
- The gross risk level before any controls or mitigations are in place (Correct answer)
- Risk introduced by outsourcing a process step
- Risk associated only with financial reporting
Correct answer: The gross risk level before any controls or mitigations are in place
Inherent risk is the raw level of risk present in a process or activity before any controls, safeguards, or mitigation actions are applied.
Question 2: When conducting a Failure Mode and Effects Analysis (FMEA), what does the 'detection' rating measure?
- How often the failure occurs
- How severe the failure impact is on the customer
- The ability of current controls to detect the failure before it reaches the customer (Correct answer)
- The cost of correcting the failure
Correct answer: The ability of current controls to detect the failure before it reaches the customer
In FMEA, the detection rating evaluates how effectively existing controls can identify a failure mode before it escapes the process and affects the customer.
Question 3: A company implements redundant systems to ensure a backup activates if the primary process fails. This risk strategy is best described as:
- Risk avoidance
- Risk transfer
- Risk mitigation through redundancy (Correct answer)
- Passive risk acceptance
Correct answer: Risk mitigation through redundancy
Adding redundant systems reduces the impact of a failure by providing a backup, which is a form of risk mitigation focused on reducing impact severity.
Question 4: What is the primary objective of a 'business continuity plan' (BCP) in process risk management?
- To maximize profit during stable operations
- To ensure critical processes can continue or recover quickly after a disruptive event (Correct answer)
- To train employees on regulatory compliance
- To reduce operational costs in peak periods
Correct answer: To ensure critical processes can continue or recover quickly after a disruptive event
A BCP defines strategies and procedures to maintain or rapidly restore critical business functions when disruptions such as disasters or system failures occur.
Question 5: Which risk escalation trigger is most appropriate for a process manager to use?
- Escalate every risk regardless of severity
- Escalate only when a risk exceeds predefined thresholds of impact or probability (Correct answer)
- Never escalate; all risks should be resolved at the process level
- Escalate only financial risks to the CFO
Correct answer: Escalate only when a risk exceeds predefined thresholds of impact or probability
Effective escalation protocols define clear thresholds so that risks exceeding acceptable limits are raised to higher management for decision-making.
Question 6: In process risk analysis, 'sensitivity analysis' is used to:
- Determine which variables have the greatest influence on the risk outcome (Correct answer)
- Identify all stakeholders affected by a risk event
- Calculate the total cost of risk mitigation
- Map dependencies between process steps
Correct answer: Determine which variables have the greatest influence on the risk outcome
Sensitivity analysis tests how changes in individual input variables affect the overall risk outcome, helping prioritize which factors to control most tightly.
Question 7: A risk response plan that includes specific pre-planned actions to be triggered only if a defined risk event occurs is called a:
- Contingency plan (Correct answer)
- Risk avoidance strategy
- Risk register entry
- Corrective action report
Correct answer: Contingency plan
A contingency plan is a set of pre-approved actions that are activated when a risk event materializes, reducing response time and uncertainty.
Which of the following best describes 'inherent risk' in process management?