CRM CRM Enterprise Risk Management 2 — Questions and Answers
Question 1: The ISO 31000 standard provides guidance on:
- Financial auditing procedures
- Risk management principles and guidelines (Correct answer)
- Environmental compliance requirements
- Human resources management
Correct answer: Risk management principles and guidelines
ISO 31000 is the international standard that provides principles, framework, and a process for managing risk in any organization.
Question 2: In COSO ERM, which component addresses the organization's core values and ethical standards?
- Risk Assessment
- Control Activities
- Internal Environment (Correct answer)
- Information and Communication
Correct answer: Internal Environment
The Internal Environment component of COSO ERM establishes the foundation including culture, values, and ethical standards.
Question 3: What is a Key Risk Indicator (KRI)?
- A measure used to signal increasing risk exposure before a risk event occurs (Correct answer)
- The final risk loss amount
- An insurance policy limit
- A compliance audit score
Correct answer: A measure used to signal increasing risk exposure before a risk event occurs
KRIs are forward-looking metrics that provide early warning signals of increasing risk exposure.
Question 4: Which ERM approach considers both upside opportunities and downside threats?
- Traditional risk management
- Insurance-centric risk management
- Enterprise Risk Management (Correct answer)
- Operational risk management
Correct answer: Enterprise Risk Management
ERM uniquely considers both upside opportunities and downside threats, unlike traditional risk management which focuses mainly on losses.
Question 5: What is the purpose of a risk heat map?
- To display geographic locations of claims
- To visually represent risks by likelihood and impact (Correct answer)
- To track employee performance
- To map insurance coverage areas
Correct answer: To visually represent risks by likelihood and impact
A risk heat map visually plots risks on a matrix of likelihood versus impact to prioritize risk management efforts.
Question 6: In ERM, 'residual risk' is best defined as:
- Risk that cannot be insured
- The risk remaining after risk treatment measures have been applied (Correct answer)
- Historical losses recorded in the risk register
- Risks transferred to third parties
Correct answer: The risk remaining after risk treatment measures have been applied
Residual risk is the level of risk that remains after controls and mitigation measures have been implemented.
The ISO 31000 standard provides guidance on: