CRA ERM & COSO Framework 3 β Questions and Answers
Question 1: Which COSO ERM component includes the process of prioritizing risks based on their severity relative to risk appetite?
- Governance and Culture
- Strategy and Objective-Setting
- Performance (Correct answer)
- Review and Revision
Correct answer: Performance
The Performance component covers risk identification, assessment, prioritization, and the selection of risk responses.
Question 2: A Chief Risk Officer presents a heat map showing 12 risks mapped by likelihood and impact. Which limitation of heat maps should the board be most aware of?
- Heat maps cannot show more than five risks simultaneously
- They may obscure the aggregate correlation between risks (Correct answer)
- They require quantitative probability distributions for every risk
- They are only valid for financial risks
Correct answer: They may obscure the aggregate correlation between risks
Heat maps display individual risks but do not inherently capture how correlated risks can amplify each other when occurring together.
Question 3: In COSO's three-lines-of-defense model, which line is responsible for providing independent assurance to the board and senior management?
- First line β operational management
- Second line β risk and compliance functions
- Third line β internal audit (Correct answer)
- Fourth line β external auditors
Correct answer: Third line β internal audit
Internal audit (third line) provides independent assurance on the effectiveness of governance, risk management, and internal controls.
Question 4: When applying the COSO ERM framework to a strategic merger decision, risk identification should occur:
- Only after deal closing to avoid biasing negotiations
- During strategy formulation, before the final decision is made (Correct answer)
- Exclusively in the post-merger integration phase
- Solely by the finance team conducting due diligence
Correct answer: During strategy formulation, before the final decision is made
COSO ERM emphasizes integrating risk identification into strategy-setting so that risk informsβrather than followsβmajor decisions.
Question 5: A company's risk register shows an inherent risk rated 'High' with a residual risk rated 'Low.' What does this indicate?
- The controls are ineffective and the risk is unmanaged
- Existing controls are effectively reducing the risk to an acceptable level (Correct answer)
- The risk has been transferred entirely to an insurer
- The inherent and residual ratings should always match
Correct answer: Existing controls are effectively reducing the risk to an acceptable level
The gap between inherent and residual risk reflects the effectiveness of controls in mitigating exposure.
Question 6: Which COSO ERM principle states that organizations should 'identify risk in the context of business context'?
- Principle 6 β Analyzes Business Context
- Principle 8 β Assesses Severity of Risk
- Principle 10 β Identifies Risk (Correct answer)
- Principle 12 β Prioritizes Risks
Correct answer: Principle 10 β Identifies Risk
Principle 10 states that the organization identifies risk and considers how it might affect the achievement of strategy and business objectives.
Question 7: An organization that accepts more risk than its stated appetite to pursue higher returns is exhibiting:
- Risk optimization
- Risk appetite drift (Correct answer)
- Risk transfer
- Risk diversification
Correct answer: Risk appetite drift
Risk appetite drift occurs when actual risk-taking exceeds the formally approved appetite, often without explicit board sanction.
Which COSO ERM component includes the process of prioritizing risks based on their severity relative to risk appetite?