← All CRA Flashcard Decks

ERM & COSO Framework Flashcards

7 cards from real CRA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 ERM & COSO Framework flashcards as text
  1. Under COSO ERM 2017, which of the five components is most directly concerned with how risk appetite is communicated throughout the organization?

    Answer: Information, Communication, and Reporting

    Information, Communication, and Reporting ensures risk appetite and risk-related data flow across all levels of the organization.

  2. A company sets a risk appetite statement of 'low tolerance for regulatory non-compliance.' Which ERM action best operationalizes this statement?

    Answer: Establishing key risk indicators tied to compliance thresholds with escalation triggers

    KRIs with escalation triggers convert an appetite statement into actionable monitoring and response.

  3. In the COSO Internal Control — Integrated Framework (2013), which principle under the Control Environment component addresses the assignment of authority and responsibility?

    Answer: Principle 3

    Principle 3 states that management establishes structures, reporting lines, and appropriate authorities and responsibilities.

  4. Which ERM concept describes the total risk an entity can bear before it breaches its capital or operational limits?

    Answer: Risk capacity

    Risk capacity is the maximum risk an organization can absorb given its financial and operational resources.

  5. A retail bank's ERM program identifies concentration risk in commercial real estate loans. Under COSO ERM, which risk response category involves selling a portion of the loan portfolio to a third party?

    Answer: Share

    Sharing transfers a portion of the risk (and potential loss) to another party, such as through loan sales or syndications.

  6. The COSO ERM 2017 update placed greater emphasis on which new area compared to the 2004 version?

    Answer: Strategy and performance linkage to risk

    The 2017 update explicitly integrated ERM with strategy-setting and performance management, a link underemphasized in 2004.

  7. Under the COSO ERM framework, 'portfolio view of risk' means that senior management should:

    Answer: Evaluate the aggregate and interdependent risk profile across the enterprise

    A portfolio view aggregates individual risks and considers correlations to understand the organization's total risk exposure.