โ† All CRA Flashcard Decks

Risk Mitigation Strategies & Controls Flashcards

7 cards from real CRA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Mitigation Strategies & Controls flashcards as text
  1. A financial institution segregates duties between employees who authorize payments and those who process them. This primarily mitigates which risk?

    Answer: Fraud and operational risk

    Segregation of duties reduces the opportunity for a single employee to commit and conceal fraud or errors.

  2. Which of the following is an example of a detective control in an enterprise risk management context?

    Answer: Audit log review identifying unusual access patterns

    Reviewing audit logs to find anomalies is a detective control because it identifies risk events after they have occurred.

  3. A risk architect recommends replacing a manual approval workflow with an automated system to reduce processing errors. This is best classified as:

    Answer: Control automation as risk reduction

    Automating controls reduces the likelihood of human error, directly lowering operational risk exposure.

  4. When designing a control environment, which principle ensures that controls address both the likelihood and impact dimensions of risk?

    Answer: Proportionality

    Proportionality means control strength and cost should be commensurate with the severity and likelihood of the risk being mitigated.

  5. Which type of risk response involves partnering with another organization to share both the potential gain and loss of a risky venture?

    Answer: Risk sharing

    Risk sharing distributes the risk exposure between parties, with both bearing portions of any resulting losses or gains.

  6. A control gap analysis reveals that existing controls only reduce a risk from critical to high. The remaining exposure after controls are applied is called:

    Answer: Residual risk

    Residual risk is the level of risk that remains after all mitigation controls have been applied to the inherent risk.

  7. Which framework explicitly uses the concept of 'control activities' as one of its five components for managing internal control over financial reporting?

    Answer: COSO Internal Control Framework

    The COSO Internal Control Framework defines five components including Control Activities, which are policies and procedures that help ensure management directives are carried out.