CRA - Certified Risk Architect Strategic Risk and Governance Questions and Answers 1 — Questions and Answers
Question 1: Which of the following represents the most fundamental governance role of an organization's board of directors with respect to strategic risk?
- Reviewing and approving the mitigation plan for each individual high-priority risk.
- Defining and formally approving the organization's overall risk appetite statement. (Correct answer)
- Conducting the day-to-day monitoring of key risk indicators (KRIs).
- Directly managing the internal audit function to ensure its independence.
Correct answer: Defining and formally approving the organization's overall risk appetite statement.
The board's primary governance role is to set the overall strategic direction and boundaries for risk-taking. Formally defining and approving the risk appetite statement is the key mechanism for this, as it establishes the amount and type of risk the organization is willing to accept in pursuit of its objectives. The other options are either too tactical (A), a management responsibility (C), or an oversight function rather than direct management (D).
Question 2: A global logistics company is developing its five-year strategic plan. To effectively integrate risk management into this process, what should be the risk architect's primary focus?
- Compiling a comprehensive register of all known operational risks.
- Ensuring the new strategy complies with all international shipping regulations.
- Facilitating an analysis of the risks and opportunities inherent in each proposed strategic alternative. (Correct answer)
- Purchasing insurance policies to cover potential disruptions identified in the plan.
Correct answer: Facilitating an analysis of the risks and opportunities inherent in each proposed strategic alternative.
Integrating risk into strategic planning is about using risk analysis to inform the choice of strategy itself, not just protecting the chosen strategy. The risk architect's key role is to help leadership understand the risk-reward trade-offs of different paths, thereby enabling a more resilient and informed strategic decision. The other options are important risk management activities but are either too narrow (B, D) or focused on existing, non-strategic risks (A).
Question 3: Which of the following is the most defining characteristic of a strategic risk?
- It arises from failures in day-to-day internal processes, people, or systems.
- It can be fully mitigated through the implementation of robust internal controls.
- It has the potential to significantly impact an organization's ability to achieve its long-term objectives. (Correct answer)
- It is typically associated with financial losses due to short-term market volatility.
Correct answer: It has the potential to significantly impact an organization's ability to achieve its long-term objectives.
Strategic risks are fundamentally linked to the long-term goals and direction of the business. They are risks that could derail the entire strategy, such as major shifts in technology, competition, or customer demand. In contrast, operational risks arise from internal process failures (A), and market risks are related to financial market fluctuations (D). While controls can help manage strategic risks, they often cannot be fully mitigated (B).
Question 4: A new CEO wants to improve the company's risk governance and observes that while policies and procedures exist, employees often seem disengaged or fearful of reporting potential issues. Which action would be most effective in fostering a stronger risk culture?
- Implementing a new, advanced GRC (Governance, Risk, and Compliance) software platform.
- Hiring a third-party firm to conduct all future risk assessments.
- Consistently demonstrating and communicating a commitment to ethical behavior and open dialogue about risk, starting with the board and senior leadership. (Correct answer)
- Creating a system of financial penalties for any employee associated with a control failure.
Correct answer: Consistently demonstrating and communicating a commitment to ethical behavior and open dialogue about risk, starting with the board and senior leadership.
A strong risk culture is built on trust and is driven from the top down. This concept, known as "tone at the top," is the most critical element. When senior leaders consistently model desired behaviors, prioritize ethical decisions, and encourage open communication about risk without a culture of blame, it signals to the entire organization that risk management is a shared value. Technology (A) is a tool, outsourcing (B) can reduce internal ownership, and punitive measures (D) often discourage reporting.
Question 5: In the 'Three Lines Model' of risk governance, which group is considered the first line, responsible for owning and managing risks as a direct part of their daily responsibilities?
- The board of directors' audit and risk committees.
- Operational management and front-line staff who execute business activities. (Correct answer)
- The internal audit function.
- The enterprise risk management, compliance, and legal functions.
Correct answer: Operational management and front-line staff who execute business activities.
The first line consists of the business units and operational managers who are directly involved in delivering products or services. They own the risks associated with their activities and are responsible for implementing and maintaining controls as part of their day-to-day work. The risk and compliance functions are the second line (oversight), internal audit is the third line (independent assurance), and the board provides ultimate oversight.
Question 6: A company's board has approved a risk appetite statement indicating a 'high' appetite for risks related to new product innovation. However, for a specific product launch, the project team is instructed that the budget cannot exceed the initial forecast by more than 5%. This specific 5% limit is best described as an example of:
- Risk Capacity
- Inherent Risk
- Risk Tolerance (Correct answer)
- Strategic Risk
Correct answer: Risk Tolerance
Risk appetite is the broad, high-level amount of risk an organization is willing to take to achieve its objectives (e.g., 'high' appetite for innovation). Risk tolerance is the specific, acceptable level of deviation or variance from objectives related to that appetite, often expressed in measurable terms (e.g., a budget overrun not to exceed 5%). It is the tactical application of the strategic risk appetite.
Which of the following represents the most fundamental governance role of an organization's board of directors with respect to strategic risk?