Certified Risk Manager (CRM) Exam — Questions and Answers
Question 1: What is a risk report primarily used for?
- To assign job duties.
- To track sales goals.
- To present risk status and actions to management. (Correct answer)
- To review entertainment expenses.
Correct answer: To present risk status and actions to management.
A risk report serves as a formal document to inform management and other key stakeholders about the current state of identified risks, their potential impact, and the effectiveness of implemented controls. It outlines ongoing risk management activities, highlights emerging risks, and often proposes further actions. This enables informed strategic decisions regarding risk.
Question 2: What is a 'deductible' in an insurance policy?
- The policy cancellation fee
- The annual premium for the policy
- The maximum amount the insurer will pay per claim
- The amount the insured must pay before insurance coverage applies (Correct answer)
Correct answer: The amount the insured must pay before insurance coverage applies
A deductible is the portion of a loss that the insured must pay out-of-pocket before the insurance policy begins paying.
Question 3: Why is ongoing risk monitoring important?
- To reduce reporting requirements
- To ensure risk controls stay effective (Correct answer)
- To delay mitigation strategies
- To increase inherent risks
Correct answer: To ensure risk controls stay effective
Ongoing risk monitoring is important because risks and their associated controls are not static; they can change over time due to internal or external factors. Regular monitoring ensures that implemented risk controls remain effective, identifies new or emerging risks, and verifies that the risk management process is functioning as intended. This continuous oversight helps maintain an appropriate risk posture.
Question 4: What is the primary goal of a crisis communication plan?
- To ensure timely, accurate, and consistent information reaches all stakeholders (Correct answer)
- To assign social media accounts to marketing personnel during emergencies
- To restrict all external communications until the crisis is fully resolved
- To document all internal communications for legal discovery purposes
Correct answer: To ensure timely, accurate, and consistent information reaches all stakeholders
A crisis communication plan ensures that accurate, consistent messages are delivered to all stakeholders—employees, customers, media, and regulators—in a timely manner.
Question 5: What is a 'captive insurance company'?
- An insurer specializing in high-risk industries
- A reinsurer that takes on catastrophic risks
- A government-sponsored insurance pool
- A company formed by an organization to insure its own risks (Correct answer)
Correct answer: A company formed by an organization to insure its own risks
A captive is an insurance subsidiary created and owned by an organization to provide coverage for its parent company's risks.
Question 6: Under the Incident Command System (ICS), what is the purpose of the 'unified command' structure?
- To place one organization in sole command of all crisis response activities
- To transfer incident command to federal authorities automatically
- To eliminate the need for a designated incident commander
- To allow multiple agencies or organizations to jointly manage an incident while maintaining individual accountability (Correct answer)
Correct answer: To allow multiple agencies or organizations to jointly manage an incident while maintaining individual accountability
Unified command allows multiple organizations with different jurisdictions or functional responsibilities to coordinate and share command of a complex incident without losing individual accountability.
Question 7: What type of control is a company policy that limits access to data?
- Administrative control. (Correct answer)
- Physical control.
- Informal control.
- Technical control.
Correct answer: Administrative control.
An administrative control is a policy, procedure, or guideline established by management to govern behavior and manage risk. A company policy limiting data access falls under this category as it defines rules and responsibilities for information security. It's not a technical solution (like software) or a physical barrier (like a lock).
Question 8: Which source is typically used to identify risks?
- Stakeholder feedback.
- Market advertisements.
- Past project records. (Correct answer)
- Personal opinions.
Correct answer: Past project records.
Past project records, including lessons learned, incident reports, and historical data, are invaluable sources for identifying potential risks. By reviewing previous experiences, organizations can anticipate similar challenges, understand common pitfalls, and leverage insights to proactively identify and mitigate risks in current or future endeavors. This historical perspective provides empirical evidence for risk identification.
Question 9: What does 'loss frequency' refer to in insurance and risk management?
- The severity of individual losses
- The number of insurance policies held
- The total annual premium paid
- How often losses occur within a given period (Correct answer)
Correct answer: How often losses occur within a given period
Loss frequency measures how often loss events occur, which helps predict future losses and set appropriate premiums.
Question 10: What distinguishes 'operational risk' from financial risk in enterprise risk management?
- Operational risk only affects manufacturing companies
- Operational risk only involves employee actions
- Operational risk is always insurable
- Operational risk arises from failures in internal processes, people, systems, or external events (Correct answer)
Correct answer: Operational risk arises from failures in internal processes, people, systems, or external events
Operational risk encompasses losses from failed internal processes, human error, systems failures, or external events, distinct from market or credit risk.
Question 11: What is the first step in the risk management process?
- Identify potential risks. (Correct answer)
- Monitor and review controls.
- Implement control measures.
- Evaluate the risks.
Correct answer: Identify potential risks.
The first step in the risk management process is to identify potential risks. This involves systematically determining what events or circumstances could negatively impact an organization's objectives. Without first identifying these risks, it is impossible to effectively evaluate, treat, or monitor them, making this a foundational and critical initial step.
Question 12: What ethical standard governs continuing education requirements practice?
- Ethical standards are optional for certified professionals
- Ethics only apply in academic settings
- Ethics are personal opinions, not professional requirements
- Adherence to the profession's code of ethics and applicable laws and regulations (Correct answer)
Correct answer: Adherence to the profession's code of ethics and applicable laws and regulations
Professional ethics codes and applicable laws provide the framework for ethical practice in every professional field.
Question 13: How should professionals apply industry best practices in daily practice?
- Follow standards only for complex tasks
- Only when being evaluated
- Apply principles selectively based on convenience
- Consistently integrate best practices into every aspect of professional work (Correct answer)
Correct answer: Consistently integrate best practices into every aspect of professional work
Consistent application of professional standards ensures quality outcomes and builds professional credibility.
Question 14: What is the goal of risk control?
- To eliminate business objectives.
- To create risks for competitors.
- To reduce the frequency or severity of risks. (Correct answer)
- To avoid stakeholder engagement.
Correct answer: To reduce the frequency or severity of risks.
The primary goal of risk control is to implement measures that either prevent risks from occurring (reducing frequency) or lessen their negative impact if they do materialize (reducing severity). This proactive approach aims to protect an organization's assets, operations, and objectives from potential harm. Effective risk control helps maintain business continuity and minimize losses.
Question 15: How should professionals apply assessment and evaluation in daily practice?
- Apply principles selectively based on convenience
- Follow standards only for complex tasks
- Consistently integrate best practices into every aspect of professional work (Correct answer)
- Only when being evaluated
Correct answer: Consistently integrate best practices into every aspect of professional work
Consistent application of professional standards ensures quality outcomes and builds professional credibility.
Question 16: What is the foundational principle of applied methods and techniques in the Certified Relationship Manager field?
- Avoiding all challenging situations
- Maintaining competence, integrity, and service to stakeholders (Correct answer)
- Maximizing personal advancement
- Following the easiest path available
Correct answer: Maintaining competence, integrity, and service to stakeholders
The foundational principles of applied methods and techniques in Certified Relationship Manager center on maintaining competence, integrity, and quality service.
Question 17: Which of the following best describes risk identification?
- Evaluating how likely a risk is to occur.
- Calculating financial impact of a hazard.
- Documenting controls currently in place.
- Determining potential events that may impact objectives. (Correct answer)
Correct answer: Determining potential events that may impact objectives.
Risk identification best describes the process of determining potential events or circumstances that may impact an organization's objectives. It involves systematically discovering, recognizing, and describing these potential events, whether positive or negative. This foundational step lays the groundwork for all subsequent risk analysis and treatment activities.
Question 18: How should challenges in core concepts and principles be addressed?
- Avoid challenges and stick to familiar tasks
- Delegate all challenges to supervisors
- Ignore challenges until they resolve themselves
- Apply systematic problem-solving, seek expert guidance when needed, and document decisions (Correct answer)
Correct answer: Apply systematic problem-solving, seek expert guidance when needed, and document decisions
Systematic problem-solving combined with appropriate consultation and documentation ensures challenges are addressed effectively.
Question 19: Which type of business continuity test involves stopping production systems and redirecting all operations to the recovery environment?
- Full interruption test (Correct answer)
- Tabletop exercise
- Parallel test
- Structured walk-through
Correct answer: Full interruption test
A full interruption test (or cutover test) shuts down the primary systems and requires the organization to fully operate from the recovery environment, providing the most realistic validation.
Question 20: In risk evaluation, what does 'likelihood' refer to?
- The severity of a risk's impact.
- The probability that a risk event will occur. (Correct answer)
- The risk owner's preferences.
- How much a risk will cost.
Correct answer: The probability that a risk event will occur.
In risk evaluation, 'likelihood' refers to the probability or frequency with which a specific risk event is expected to occur. It assesses how often a threat might materialize, often expressed qualitatively (e.g., rare, likely) or quantitatively (e.g., a percentage). Understanding likelihood is crucial for assessing the overall significance of a risk.
Question 21: What ethical standard governs core concepts and principles practice?
- Ethical standards are optional for certified professionals
- Adherence to the profession's code of ethics and applicable laws and regulations (Correct answer)
- Ethics are personal opinions, not professional requirements
- Ethics only apply in academic settings
Correct answer: Adherence to the profession's code of ethics and applicable laws and regulations
Professional ethics codes and applicable laws provide the framework for ethical practice in every professional field.
Question 22: How can risk be reduced through training programs?
- By minimizing team size.
- By outsourcing risk decisions.
- By ensuring employees are prepared to prevent risks. (Correct answer)
- By replacing risk analysis with instinct.
Correct answer: By ensuring employees are prepared to prevent risks.
Training programs enhance employees' knowledge, skills, and awareness regarding potential risks and appropriate preventative measures. Well-trained staff are better equipped to identify hazards, follow safety protocols, and respond effectively to emerging threats, thereby directly reducing the likelihood and impact of risk events. This proactive approach empowers individuals to contribute to risk reduction.
Question 23: Which of the following is an example of a physical control?
- Project budgeting guideline.
- Employee code of conduct.
- Financial audit policy.
- Security camera installation. (Correct answer)
Correct answer: Security camera installation.
A physical control is a tangible measure designed to prevent or deter unauthorized access, damage, or theft of assets. Installing security cameras directly fits this definition by providing surveillance and acting as a visible deterrent. It physically protects an environment or asset, unlike policies or guidelines which are administrative.
Question 24: What quality assurance measure supports assessment and evaluation?
- Quality checks are unnecessary for experienced professionals
- Annual review is sufficient
- Quality only matters for new practitioners
- Regular self-assessment, peer review, and adherence to established standards (Correct answer)
Correct answer: Regular self-assessment, peer review, and adherence to established standards
Ongoing quality assurance through self-assessment, peer review, and standards adherence ensures continuous improvement.
Question 25: What is the primary purpose of risk financing?
- To fund losses that occur and restore the organization to its pre-loss financial position (Correct answer)
- To eliminate all organizational risks
- To purchase reinsurance for catastrophic events
- To invest surplus premiums in equity markets
Correct answer: To fund losses that occur and restore the organization to its pre-loss financial position
Risk financing ensures funds are available to pay for losses, allowing the organization to restore itself financially after a risk event.
Question 26: How should core concepts and principles knowledge be maintained and updated?
- Knowledge updates are only needed every five years
- Learning stops after certification
- Through continuous professional development, current literature review, and professional networking (Correct answer)
- Initial training provides lifelong competence
Correct answer: Through continuous professional development, current literature review, and professional networking
Professional competence requires ongoing development through education, literature review, and engagement with the professional community.
Question 27: What does 'risk mitigation' typically involve?
- Ignoring the risk.
- Reducing the impact of a risk event. (Correct answer)
- Escalating the risk.
- Reassigning project leaders.
Correct answer: Reducing the impact of a risk event.
Risk mitigation involves taking actions to lessen the potential negative consequences or likelihood of an identified risk. While it can also aim to reduce the probability, its core focus is often on minimizing the damage or disruption if the risk materializes. This makes the risk more manageable and less costly to the organization.
Question 28: What is the primary benefit of conducting a risk assessment?
- To eliminate all risks
- To comply with all regulations
- To identify and prioritize risks (Correct answer)
- To reduce operational costs
Correct answer: To identify and prioritize risks
The primary benefit of conducting a risk assessment is to identify and prioritize risks. This systematic process helps organizations discover potential threats and opportunities, evaluate their likelihood and impact, and then rank them based on their significance. This enables effective resource allocation, focusing attention on the most critical areas to protect organizational objectives.
Question 29: In risk terminology, what does 'inherent risk' refer to?
- Risk before controls are in place (Correct answer)
- Risk left after implementing controls
- Risks accepted by management
- The most critical identified risk
Correct answer: Risk before controls are in place
In risk terminology, 'inherent risk' refers to the level of risk that exists before any internal controls or other mitigating factors have been implemented. It represents the raw, unmitigated risk exposure an organization faces from a particular activity or threat. Understanding inherent risk is crucial for designing and implementing appropriate control measures.
Question 30: Large deductible programs in risk financing primarily benefit organizations by:
- Allowing cash flow advantages by retaining smaller losses internally (Correct answer)
- Transferring all risk to third parties
- Eliminating all insurance costs
- Reducing regulatory compliance requirements
Correct answer: Allowing cash flow advantages by retaining smaller losses internally
Large deductible programs allow organizations to retain and internally fund smaller losses while gaining premium savings and cash flow benefits.
Question 31: What is a 'self-insured retention' (SIR) in a commercial liability policy?
- The maximum premium the insured will pay
- The policy's automatic renewal provision
- The amount an insured pays per claim before the insurer responds (Correct answer)
- A reserve fund maintained by the insurer
Correct answer: The amount an insured pays per claim before the insurer responds
An SIR is the amount the insured must pay for each claim before the insurance company begins contributing to the loss.
Question 32: How does redundancy help in risk mitigation?
- It eliminates the need for training.
- It increases costs with no benefits.
- It ensures operations continue if the primary system fails. (Correct answer)
- It confuses the workflow.
Correct answer: It ensures operations continue if the primary system fails.
Redundancy is a risk mitigation strategy that involves duplicating critical components or systems. Its purpose is to provide a backup or alternative pathway, ensuring that if one part fails, the system or operation can continue without interruption. This significantly enhances resilience and reduces the impact of single points of failure.
Question 33: Which document outlines an organization's approach to managing risk?
- Operational handbook
- Risk register
- Code of ethics
- Risk management policy (Correct answer)
Correct answer: Risk management policy
A risk management policy is a formal document that outlines an organization's overall philosophy, objectives, and approach to managing risk. It establishes the framework, roles, responsibilities, and processes for identifying, assessing, treating, monitoring, and communicating risks across the organization. This policy provides the guiding principles for all risk-related activities.
Question 34: Workers' compensation insurance provides coverage for:
- Customer injuries on business premises
- Property damage caused by employees
- Employee injuries or illnesses arising from employment (Correct answer)
- Director and officer liability
Correct answer: Employee injuries or illnesses arising from employment
Workers' compensation covers medical expenses and lost wages for employees injured or made ill in the course of their employment.
Question 35: What is the primary goal of risk evaluation?
- To create contingency plans.
- To assign risk owners.
- To eliminate all risks.
- To prioritize risks based on impact and likelihood. (Correct answer)
Correct answer: To prioritize risks based on impact and likelihood.
The primary goal of risk evaluation is to prioritize risks based on their potential impact and likelihood of occurrence. This assessment allows organizations to determine the significance of identified risks, enabling them to allocate resources effectively to the most critical areas. It informs decision-making regarding which risks require immediate attention and treatment.
Question 36: Which liability coverage protects a business against claims arising from its products after they leave the premises?
- Premises liability
- Professional liability
- Products liability (Correct answer)
- Employer liability
Correct answer: Products liability
Products liability coverage protects manufacturers and sellers against claims arising from harm caused by their products.
Question 37: How should challenges in assessment and evaluation be addressed?
- Avoid challenges and stick to familiar tasks
- Ignore challenges until they resolve themselves
- Apply systematic problem-solving, seek expert guidance when needed, and document decisions (Correct answer)
- Delegate all challenges to supervisors
Correct answer: Apply systematic problem-solving, seek expert guidance when needed, and document decisions
Systematic problem-solving combined with appropriate consultation and documentation ensures challenges are addressed effectively.
Question 38: What is a risk register used for?
- To manage human resources.
- To record financial statements.
- To track and document identified risks. (Correct answer)
- To maintain equipment logs.
Correct answer: To track and document identified risks.
A risk register is a central repository used to systematically track and document all identified risks within an organization or project. It typically includes details such as risk descriptions, likelihood, impact, mitigation strategies, owners, and current status. This tool provides a comprehensive overview of the risk landscape, enabling effective management and communication.
Question 39: How should applied methods and techniques knowledge be maintained and updated?
- Learning stops after certification
- Knowledge updates are only needed every five years
- Through continuous professional development, current literature review, and professional networking (Correct answer)
- Initial training provides lifelong competence
Correct answer: Through continuous professional development, current literature review, and professional networking
Professional competence requires ongoing development through education, literature review, and engagement with the professional community.
Question 40: Which strategy is used when an organization decides not to engage in a high-risk activity?
- Risk transfer
- Risk acceptance
- Risk avoidance (Correct answer)
- Risk reduction
Correct answer: Risk avoidance
Risk avoidance is a strategy where an organization decides not to engage in an activity or project that carries a high level of unacceptable risk. By eliminating the source of the risk entirely, the organization prevents the potential negative consequences from occurring. This differs from other strategies like reduction or transfer, which involve managing existing risks.
Question 41: What does 'subrogation' mean in insurance?
- The insured's right to cancel a policy
- The insurer's right to pursue a third party that caused an insurance loss (Correct answer)
- The process of filing a claim
- A premium discount for good loss history
Correct answer: The insurer's right to pursue a third party that caused an insurance loss
Subrogation allows an insurer who has paid a claim to pursue recovery from the responsible third party.
Question 42: How should professional standards and ethics knowledge be maintained and updated?
- Through continuous professional development, current literature review, and professional networking (Correct answer)
- Initial training provides lifelong competence
- Knowledge updates are only needed every five years
- Learning stops after certification
Correct answer: Through continuous professional development, current literature review, and professional networking
Professional competence requires ongoing development through education, literature review, and engagement with the professional community.
Question 43: Which of the following best describes 'risk tolerance' in ERM?
- The minimum risk required for operations
- The risk transfer mechanism
- The ability to withstand catastrophic losses
- The acceptable variation around risk appetite defining boundaries of risk-taking (Correct answer)
Correct answer: The acceptable variation around risk appetite defining boundaries of risk-taking
Risk tolerance is the acceptable variation around risk appetite, defining the boundaries of acceptable risk-taking.
Question 44: Why is testing controls important in risk mitigation?
- To eliminate all risks.
- To validate the effectiveness of risk controls. (Correct answer)
- To delay audits.
- To reduce employee morale.
Correct answer: To validate the effectiveness of risk controls.
Testing controls is essential to ensure they are functioning as intended and are effective in mitigating identified risks. Regular testing helps identify weaknesses, gaps, or malfunctions in controls before a risk event occurs. This validation process allows for necessary adjustments and improvements, strengthening the overall risk management framework.
Question 45: Which of the following best describes a proactive risk control?
- Issuing a public apology.
- Filing an insurance claim.
- Installing fire alarms in advance. (Correct answer)
- Responding after a breach.
Correct answer: Installing fire alarms in advance.
A proactive risk control is implemented before a risk event occurs, aiming to prevent it or reduce its potential impact. Installing fire alarms is a classic example, as it's done in anticipation of a fire to provide early warning and facilitate a response. This contrasts with reactive measures taken after an incident has already occurred.
Question 46: What is a 'low likelihood, high impact' risk typically considered?
- A minor concern.
- A trivial issue.
- A strategic risk. (Correct answer)
- A residual hazard.
Correct answer: A strategic risk.
A 'low likelihood, high impact' risk is typically considered a strategic risk. While these events may not happen often, their occurrence could have severe, far-reaching consequences for an organization's long-term goals, reputation, or even survival. Such risks require careful planning and contingency strategies despite their low probability.
Question 47: What is the primary purpose of a tabletop exercise in crisis management?
- To physically test backup generators and utility systems
- To rehearse actual evacuation procedures with all staff
- To simulate a crisis scenario through facilitated discussion without real system disruption (Correct answer)
- To validate data backup and restoration procedures in a live environment
Correct answer: To simulate a crisis scenario through facilitated discussion without real system disruption
A tabletop exercise is a discussion-based simulation where key personnel walk through a crisis scenario to identify gaps in plans without disrupting actual operations.
Question 48: What is the foundational principle of assessment and evaluation in the Certified Relationship Manager field?
- Maximizing personal advancement
- Following the easiest path available
- Maintaining competence, integrity, and service to stakeholders (Correct answer)
- Avoiding all challenging situations
Correct answer: Maintaining competence, integrity, and service to stakeholders
The foundational principles of assessment and evaluation in Certified Relationship Manager center on maintaining competence, integrity, and quality service.
Question 49: Which technique is commonly used during the risk identification phase?
- Critical path analysis.
- Brainstorming. (Correct answer)
- Benchmarking.
- Control charting.
Correct answer: Brainstorming.
Brainstorming is a commonly used and highly effective technique during the risk identification phase. It involves a group of stakeholders collaboratively generating a comprehensive list of potential risks, encouraging creative thinking and diverse perspectives. This method helps uncover a wide range of threats and opportunities that might impact objectives.
Question 50: What does 'control environment' refer to in risk mitigation?
- Market competition level.
- Physical building conditions.
- Only the IT infrastructure.
- Organizational culture and structure. (Correct answer)
Correct answer: Organizational culture and structure.
The 'control environment' refers to the overall attitude, awareness, and actions of management and the board of directors regarding internal controls and their importance. It encompasses the ethical values, competence, organizational structure, and assignment of authority and responsibility within an entity. Essentially, it sets the tone at the top for risk management.
Certified Risk Manager (CRM) Exam
The CRM program consists of five courses and exams, each focusing on a specific aspect of risk management. The overall certification requires passing all five.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds