CRA ERM & COSO Framework 2 — Questions and Answers
Question 1: Under COSO ERM 2017, which of the five components is most directly concerned with how risk appetite is communicated throughout the organization?
- Risk Assessment
- Governance and Culture
- Review and Revision
- Information, Communication, and Reporting (Correct answer)
Correct answer: Information, Communication, and Reporting
Information, Communication, and Reporting ensures risk appetite and risk-related data flow across all levels of the organization.
Question 2: A company sets a risk appetite statement of 'low tolerance for regulatory non-compliance.' Which ERM action best operationalizes this statement?
- Eliminating all business activities that involve regulation
- Establishing key risk indicators tied to compliance thresholds with escalation triggers (Correct answer)
- Transferring all compliance risk to a third party
- Documenting the appetite statement in the annual report only
Correct answer: Establishing key risk indicators tied to compliance thresholds with escalation triggers
KRIs with escalation triggers convert an appetite statement into actionable monitoring and response.
Question 3: In the COSO Internal Control — Integrated Framework (2013), which principle under the Control Environment component addresses the assignment of authority and responsibility?
- Principle 2
- Principle 3 (Correct answer)
- Principle 4
- Principle 5
Correct answer: Principle 3
Principle 3 states that management establishes structures, reporting lines, and appropriate authorities and responsibilities.
Question 4: Which ERM concept describes the total risk an entity can bear before it breaches its capital or operational limits?
- Risk appetite
- Risk capacity (Correct answer)
- Risk tolerance
- Residual risk
Correct answer: Risk capacity
Risk capacity is the maximum risk an organization can absorb given its financial and operational resources.
Question 5: A retail bank's ERM program identifies concentration risk in commercial real estate loans. Under COSO ERM, which risk response category involves selling a portion of the loan portfolio to a third party?
- Accept
- Avoid
- Share (Correct answer)
- Reduce
Correct answer: Share
Sharing transfers a portion of the risk (and potential loss) to another party, such as through loan sales or syndications.
Question 6: The COSO ERM 2017 update placed greater emphasis on which new area compared to the 2004 version?
- Internal control over financial reporting
- Strategy and performance linkage to risk (Correct answer)
- Fraud risk management
- IT general controls
Correct answer: Strategy and performance linkage to risk
The 2017 update explicitly integrated ERM with strategy-setting and performance management, a link underemphasized in 2004.
Question 7: Under the COSO ERM framework, 'portfolio view of risk' means that senior management should:
- Assess each risk in isolation for precise measurement
- Evaluate the aggregate and interdependent risk profile across the enterprise (Correct answer)
- Assign each risk to a single business unit owner
- Report only the top five risks to the board
Correct answer: Evaluate the aggregate and interdependent risk profile across the enterprise
A portfolio view aggregates individual risks and considers correlations to understand the organization's total risk exposure.
Under COSO ERM 2017, which of the five components is most directly concerned with how risk appetite is communicated throughout the organization?