CRA Risk Mitigation Strategies & Controls 3 — Questions and Answers
Question 1: A financial institution segregates duties between employees who authorize payments and those who process them. This primarily mitigates which risk?
- Market risk
- Liquidity risk
- Fraud and operational risk (Correct answer)
- Credit risk
Correct answer: Fraud and operational risk
Segregation of duties reduces the opportunity for a single employee to commit and conceal fraud or errors.
Question 2: Which of the following is an example of a detective control in an enterprise risk management context?
- Firewall blocking unauthorized access
- Mandatory pre-approval for high-value transactions
- Audit log review identifying unusual access patterns (Correct answer)
- Encryption of data at rest
Correct answer: Audit log review identifying unusual access patterns
Reviewing audit logs to find anomalies is a detective control because it identifies risk events after they have occurred.
Question 3: A risk architect recommends replacing a manual approval workflow with an automated system to reduce processing errors. This is best classified as:
- Risk transfer
- Control automation as risk reduction (Correct answer)
- Risk avoidance
- Residual risk acceptance
Correct answer: Control automation as risk reduction
Automating controls reduces the likelihood of human error, directly lowering operational risk exposure.
Question 4: When designing a control environment, which principle ensures that controls address both the likelihood and impact dimensions of risk?
- Defense in depth
- Proportionality (Correct answer)
- Segregation of duties
- Least privilege
Correct answer: Proportionality
Proportionality means control strength and cost should be commensurate with the severity and likelihood of the risk being mitigated.
Question 5: Which type of risk response involves partnering with another organization to share both the potential gain and loss of a risky venture?
- Risk transfer
- Risk sharing (Correct answer)
- Risk reduction
- Risk acceptance
Correct answer: Risk sharing
Risk sharing distributes the risk exposure between parties, with both bearing portions of any resulting losses or gains.
Question 6: A control gap analysis reveals that existing controls only reduce a risk from critical to high. The remaining exposure after controls are applied is called:
- Inherent risk
- Residual risk (Correct answer)
- Controlled risk
- Transferred risk
Correct answer: Residual risk
Residual risk is the level of risk that remains after all mitigation controls have been applied to the inherent risk.
Question 7: Which framework explicitly uses the concept of 'control activities' as one of its five components for managing internal control over financial reporting?
- ISO 31000
- COSO Internal Control Framework (Correct answer)
- NIST RMF
- COBIT 2019
Correct answer: COSO Internal Control Framework
The COSO Internal Control Framework defines five components including Control Activities, which are policies and procedures that help ensure management directives are carried out.
A financial institution segregates duties between employees who authorize payments and those who process them.
This primarily mitigates which risk?