Risk Management & Assessment Flashcards
9 cards from real CRM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 9 Risk Management & Assessment flashcards as text
What is the first step in the risk management process?
Answer: Identify potential risks.
The first step in the risk management process is to identify potential risks. This involves systematically determining what events or circumstances could negatively impact an organization's objectives. Without first identifying these risks, it is impossible to effectively evaluate, treat, or monitor them, making this a foundational and critical initial step.
Which of the following is a qualitative risk assessment method?
Answer: Risk matrix scoring
A risk matrix is a qualitative risk assessment method that plots risks based on their likelihood and impact, often using descriptive scales like 'low,' 'medium,' or 'high.' This approach allows for a quick visual prioritization of risks without requiring extensive quantitative data or complex statistical analysis. It provides a clear, high-level overview of an organization's risk landscape.
In risk terminology, what does 'inherent risk' refer to?
Answer: Risk before controls are in place
In risk terminology, 'inherent risk' refers to the level of risk that exists before any internal controls or other mitigating factors have been implemented. It represents the raw, unmitigated risk exposure an organization faces from a particular activity or threat. Understanding inherent risk is crucial for designing and implementing appropriate control measures.
Which strategy is used when an organization decides not to engage in a high-risk activity?
Answer: Risk avoidance
Risk avoidance is a strategy where an organization decides not to engage in an activity or project that carries a high level of unacceptable risk. By eliminating the source of the risk entirely, the organization prevents the potential negative consequences from occurring. This differs from other strategies like reduction or transfer, which involve managing existing risks.
What is the primary benefit of conducting a risk assessment?
Answer: To identify and prioritize risks
The primary benefit of conducting a risk assessment is to identify and prioritize risks. This systematic process helps organizations discover potential threats and opportunities, evaluate their likelihood and impact, and then rank them based on their significance. This enables effective resource allocation, focusing attention on the most critical areas to protect organizational objectives.
Which of the following is a risk transfer technique?
Answer: Insurance policy
Risk transfer is a strategy where the financial consequences of a potential risk are shifted to a third party. An insurance policy is a classic example of this technique, as the insurer agrees to compensate the policyholder for specified losses in exchange for premiums. This allows the organization to mitigate its direct financial exposure to certain risks.
Residual risk is defined as:
Answer: Risk remaining after controls
Residual risk is defined as the amount of risk that remains after an organization has implemented risk mitigation strategies and controls. It is the risk that management has either accepted, transferred, or reduced to an acceptable level, but which has not been entirely eliminated. Organizations must continuously monitor and manage these remaining risks.
Which document outlines an organization's approach to managing risk?
Answer: Risk management policy
A risk management policy is a formal document that outlines an organization's overall philosophy, objectives, and approach to managing risk. It establishes the framework, roles, responsibilities, and processes for identifying, assessing, treating, monitoring, and communicating risks across the organization. This policy provides the guiding principles for all risk-related activities.
Why is ongoing risk monitoring important?
Answer: To ensure risk controls stay effective
Ongoing risk monitoring is important because risks and their associated controls are not static; they can change over time due to internal or external factors. Regular monitoring ensures that implemented risk controls remain effective, identifies new or emerging risks, and verifies that the risk management process is functioning as intended. This continuous oversight helps maintain an appropriate risk posture.