CRM Risk Assessment & Mitigation 3 — Questions and Answers
Question 1: Which risk indicator would MOST likely trigger a records manager to conduct an unscheduled risk reassessment?
- A scheduled audit cycle completion
- A major merger, acquisition, or organizational restructuring (Correct answer)
- Annual renewal of a records management software license
- Completion of staff onboarding training
Correct answer: A major merger, acquisition, or organizational restructuring
Major organizational changes such as mergers or restructuring significantly alter the records risk landscape and warrant an immediate reassessment.
Question 2: A risk heat map is used in records management primarily to:
- Track individual employee compliance
- Visually prioritize risks by likelihood and impact (Correct answer)
- Calculate the cost of records storage
- Document chain-of-custody procedures
Correct answer: Visually prioritize risks by likelihood and impact
A risk heat map plots risks on a grid of probability versus impact, enabling managers to visually identify and prioritize the most critical risks.
Question 3: Which of the following is an example of risk transfer in a records management context?
- Shredding outdated documents to prevent unauthorized access
- Purchasing cyber liability insurance to cover a data breach (Correct answer)
- Encrypting confidential records at rest
- Training staff on records handling procedures
Correct answer: Purchasing cyber liability insurance to cover a data breach
Risk transfer shifts the financial consequences of a risk to a third party, such as an insurer, rather than eliminating the risk itself.
Question 4: A records manager is evaluating the risk of a legacy records system becoming unsupported. This is classified as which type of risk?
- Technological obsolescence risk (Correct answer)
- Compliance risk
- Reputational risk
- Personnel risk
Correct answer: Technological obsolescence risk
Technological obsolescence risk occurs when systems or media formats become outdated, threatening the accessibility and integrity of records over time.
Question 5: When a risk assessment reveals a low-probability, low-impact risk, the MOST appropriate response is typically to:
- Implement costly controls immediately
- Accept the risk and monitor it periodically (Correct answer)
- Transfer the risk to a vendor immediately
- Escalate it to senior leadership for immediate action
Correct answer: Accept the risk and monitor it periodically
Low-probability, low-impact risks are generally accepted and placed on a watch list for periodic monitoring rather than requiring costly immediate action.
Question 6: Which standard provides the most comprehensive international guidance on risk management that records managers should align with?
- ISO 9001
- ISO 31000 (Correct answer)
- NFPA 232
- DoD 5015.02
Correct answer: ISO 31000
ISO 31000 provides principles and guidelines for risk management applicable across all sectors and is widely used to structure records risk programs.
Question 7: A records manager discovers employees are storing records on personal cloud accounts. Which risk does this PRIMARILY represent?
- Data sovereignty and security risk (Correct answer)
- Physical disaster risk
- Retention schedule non-compliance only
- Redundancy risk
Correct answer: Data sovereignty and security risk
Personal cloud storage creates data sovereignty and security risks because organizational records are outside IT governance, encryption controls, and jurisdictional oversight.
Which risk indicator would MOST likely trigger a records manager to conduct an unscheduled risk reassessment?