Certification in Risk Management Assurance (CRMA) — Questions and Answers
Question 1: Which stakeholder group typically provides the most valuable input during the risk identification phase of engagement planning?
- External auditors and regulatory examiners
- IT department personnel and data analysts
- Human resources specialists and training coordinators
- Senior management and business process owners (Correct answer)
Correct answer: Senior management and business process owners
Process owners and senior management have the deepest operational knowledge of risks within their specific areas.
Question 2: What is the primary purpose of an assurance map in a coordinated assurance framework?
- To document the budget allocated to each line of defense activity
- To visually display which assurance providers cover which risks and identify gaps or overlaps (Correct answer)
- To rank individual auditors by their level of professional certification
- To replace the internal audit's annual risk assessment process
Correct answer: To visually display which assurance providers cover which risks and identify gaps or overlaps
An assurance map displays risk coverage across all providers, revealing gaps where risks are unassured and overlaps where effort is duplicated.
Question 3: In sensitivity analysis, the purpose of changing one variable at a time while holding others constant is to:
- Determine which individual risk variable has the greatest influence on the outcome (Correct answer)
- Comply with regulatory reporting requirements
- Calculate the net present value of risk mitigation investments
- Test whether controls are operating effectively
Correct answer: Determine which individual risk variable has the greatest influence on the outcome
Sensitivity analysis isolates the effect of each variable to identify which risks drive the most uncertainty in the overall outcome.
Question 4: When a company separates the Risk Committee from the Audit Committee, what is the primary governance benefit?
- It ensures the CFO chairs both committees independently
- It transfers risk ownership from management to the board
- It allows deeper focus on risk strategy versus financial reporting oversight (Correct answer)
- It reduces the total number of board meetings required
Correct answer: It allows deeper focus on risk strategy versus financial reporting oversight
Separating the committees allows each to specialize — the Risk Committee focuses on strategic and operational risk while the Audit Committee focuses on financial reporting and controls.
Question 5: Which scenario represents a risk culture 'red flag' related to the 'accountability' dimension?
- The risk function reports directly to the CFO rather than the CRO
- The audit committee meets four times per year
- Risk appetite is reviewed annually rather than semi-annually
- Significant risk events consistently result in no personal consequences for responsible individuals (Correct answer)
Correct answer: Significant risk events consistently result in no personal consequences for responsible individuals
Absence of consequences following risk events signals that accountability is not enforced, which erodes the cultural expectation that risk ownership matters.
Question 6: A bow-tie analysis in risk management visually connects:
- Causes of a risk event on the left to consequences on the right, with controls at the center. (Correct answer)
- The three lines of defense to specific risk categories.
- Strategic objectives to operational KPIs.
- Risk appetite to residual risk exposure.
Correct answer: Causes of a risk event on the left to consequences on the right, with controls at the center.
A bow-tie diagram places the risk event at the center, shows threat causes on the left with preventive controls, and consequences on the right with recovery controls.
Question 7: When internal audit provides consulting services related to risk management, the chief audit executive must ensure that:
- Objectivity is safeguarded and management retains risk ownership (Correct answer)
- Risk consulting replaces the need for assurance engagements
- The internal audit activity assumes ownership of risk management outcomes
- External consultants co-sign all risk management reports
Correct answer: Objectivity is safeguarded and management retains risk ownership
During risk management consulting, internal audit must safeguard its objectivity and ensure management—not internal audit—retains ownership of risk decisions.
Question 8: What is 'risk appetite' as used in enterprise risk management?
- The likelihood assigned to a risk event during assessment
- The residual risk remaining after controls are applied
- The maximum loss an organization can absorb before insolvency
- The amount and type of risk an organization is willing to pursue or retain (Correct answer)
Correct answer: The amount and type of risk an organization is willing to pursue or retain
Risk appetite is the amount and type of risk an organization is willing to pursue or retain in order to achieve its strategic objectives.
Question 9: A CRMA professional discovers that risk reports consistently exclude certain categories of risk. This MOST likely indicates:
- Compliance with regulatory requirements to limit disclosure
- An efficient reporting process that focuses on material risks only
- Evidence that excluded risk categories have been fully mitigated
- A potential gap in risk identification or a cultural reluctance to report certain risks (Correct answer)
Correct answer: A potential gap in risk identification or a cultural reluctance to report certain risks
Systematic exclusion of risk categories may signal blind spots in the risk identification process or a cultural environment where certain risks are discouraged from being raised.
Question 10: The CRMA credential signals that the holder is competent to:
- Manage the enterprise risk management function as a second-line owner
- Set organizational risk appetite and approve risk tolerance thresholds
- Perform external audits of risk management frameworks on behalf of regulators
- Provide assurance, insight, and recommendations on risk management processes (Correct answer)
Correct answer: Provide assurance, insight, and recommendations on risk management processes
The CRMA certification demonstrates competency in evaluating risk management processes and providing risk-focused assurance, insight, and recommendations as part of the internal audit role.
Question 11: Which communication channel is MOST appropriate for immediate notification of a risk event that could materially impact the organization?
- Publishing a notice in the employee newsletter
- Inclusion in the next scheduled quarterly risk report
- Annual risk assessment update shared with the audit committee
- Direct escalation through defined rapid-alert channels to senior leadership (Correct answer)
Correct answer: Direct escalation through defined rapid-alert channels to senior leadership
Material risk events require immediate escalation through rapid-alert channels so senior leaders can authorize timely response actions to limit impact.
Question 12: Internal audit is reviewing risk management effectiveness. Management claims all key risks are within appetite. The BEST audit approach is to:
- Independently verify that risk exposure measurements align with stated appetite thresholds (Correct answer)
- Limit scope to controls testing and exclude risk appetite assessment
- Accept management's assertion and document it as audit evidence
- Escalate to the board without further testing since management may be biased
Correct answer: Independently verify that risk exposure measurements align with stated appetite thresholds
Effective assurance requires independent corroboration of management's risk assessments against documented appetite thresholds rather than reliance on assertion alone.
Question 13: Which element makes risk communication most actionable for the recipient?
- Comparison to prior-year risk ratings without forward-looking guidance
- Clear recommended actions or decisions required, with owners and deadlines (Correct answer)
- Detailed statistical methodology used to calculate risk scores
- Extensive background on the theoretical risk management framework
Correct answer: Clear recommended actions or decisions required, with owners and deadlines
Actionable risk communication specifies what needs to be done, who is responsible, and by when, enabling recipients to respond effectively rather than simply be informed.
Question 14: A consulting engagement letter or planning document should contain:
- Only the deliverables and timelines, omitting scope limitations
- The auditor's personal opinion on current control effectiveness
- Objectives, scope, respective responsibilities, and agreed deliverables (Correct answer)
- A guarantee of improved outcomes following the engagement
Correct answer: Objectives, scope, respective responsibilities, and agreed deliverables
The engagement letter should capture all key parameters so both parties understand objectives, scope, roles, and expected outputs before work begins.
Question 15: A risk owner fails to respond to repeated requests for risk status updates. The MOST appropriate escalation step is to:
- Remove the risk from active monitoring until the owner responds
- File a formal regulatory complaint against the risk owner
- Assign a risk rating of 'unknown' and continue without further follow-up
- Escalate the non-response to the risk owner's supervisor or governance committee (Correct answer)
Correct answer: Escalate the non-response to the risk owner's supervisor or governance committee
Escalating unresponsive risk ownership to appropriate governance levels ensures accountability is maintained and risks do not go unmonitored due to individual inaction.
Question 16: Which scenario BEST demonstrates 'tone in the middle' as a risk culture concern?
- The board approves an overly aggressive risk appetite
- A branch manager dismisses staff concerns about control weaknesses as 'not worth escalating' (Correct answer)
- The chief audit executive fails to report to the audit committee
- A risk officer bypasses the CFO in reporting to the board
Correct answer: A branch manager dismisses staff concerns about control weaknesses as 'not worth escalating'
Tone in the middle refers to management behavior that either reinforces or undermines executive risk messaging; a manager suppressing escalations is a direct example.
Question 17: Which governance body holds ultimate accountability for ensuring an effective enterprise risk management framework exists?
- Chief Risk Officer
- Board of Directors (Correct answer)
- Internal Audit Committee
- Risk Management Committee
Correct answer: Board of Directors
The board of directors bears ultimate accountability for the organization's risk governance framework.
Question 18: Which indicator is most suggestive of a strong risk culture within an organization?
- The board delegates all risk oversight decisions to the Chief Risk Officer.
- Risk management responsibilities are concentrated in a dedicated ERM department.
- Management openly discusses failures and near-misses without blame, encouraging early escalation. (Correct answer)
- Employees report risk events only after losses exceed a defined threshold.
Correct answer: Management openly discusses failures and near-misses without blame, encouraging early escalation.
A strong risk culture is characterized by psychological safety — people escalate concerns early and learn from near-misses rather than hiding problems to avoid blame.
Question 19: A key risk indicator (KRI) differs from a key performance indicator (KPI) primarily because a KRI:
- Is used exclusively by internal auditors
- Provides forward-looking signals of increasing risk exposure (Correct answer)
- Measures actual outcomes after they have occurred
- Focuses only on financial metrics
Correct answer: Provides forward-looking signals of increasing risk exposure
KRIs are leading, predictive metrics that signal rising risk exposure before a risk event materializes, unlike KPIs which measure performance outcomes.
Question 20: Which risk culture indicator would be MOST relevant when evaluating an organization undergoing rapid expansion?
- Whether the IT department has scaled server infrastructure
- Whether risk onboarding processes are embedded in new-hire integration programs (Correct answer)
- Whether the board has approved an updated risk appetite statement
- Whether the CFO has signed off on the new budget
Correct answer: Whether risk onboarding processes are embedded in new-hire integration programs
During rapid expansion, new employees are culture-forming; integrating risk culture into onboarding is the primary mechanism for scaling risk awareness.
Question 21: Which document most formally defines the scope, responsibilities, and interaction protocols among all assurance providers in an organization?
- The external auditor's engagement letter
- A combined assurance charter or memorandum of understanding (Correct answer)
- The annual internal audit plan
- The organization's code of ethics
Correct answer: A combined assurance charter or memorandum of understanding
A combined assurance charter or MOU formally establishes how each provider coordinates, reducing confusion and duplication.
Question 22: Under the COSO ERM 2017 'Performance' component, which activity involves identifying the severity of risks relative to risk appetite?
- Risk governance
- Risk prioritization (Correct answer)
- Risk communication
- Risk financing
Correct answer: Risk prioritization
Risk prioritization within the Performance component involves assessing the severity of identified risks and ranking them relative to the organization's risk appetite.
Question 23: In the context of ERM and CRMA, which statement about risk appetite and organizational culture is MOST accurate?
- A strong risk appetite statement automatically creates a risk-aware culture.
- Culture is separate from risk management and should not be assessed by internal audit.
- Organizational culture can cause actual risk-taking to diverge from the formally stated appetite, making culture a key audit consideration. (Correct answer)
- If the CEO supports the risk appetite statement, culture is aligned by definition.
Correct answer: Organizational culture can cause actual risk-taking to diverge from the formally stated appetite, making culture a key audit consideration.
An organization's culture — including incentives, leadership behaviors, and informal norms — can override formal risk appetite statements, making cultural assessment essential for audit.
Question 24: What is 'residual risk'?
- The portion of a risk transferred to an insurer
- The total of all risks across the enterprise risk register
- The risk remaining after management has applied controls and risk responses (Correct answer)
- The risk identified but not yet assigned to a risk owner
Correct answer: The risk remaining after management has applied controls and risk responses
Residual risk is the risk that remains after management has implemented controls and other responses to reduce the inherent risk.
Question 25: A 'black swan' event in risk management refers to:
- A strategic risk identified through SWOT analysis
- A high-frequency, low-severity operational risk
- A risk fully covered by the organization's insurance program
- A rare, unpredictable event with extreme consequences that is rationalized in hindsight (Correct answer)
Correct answer: A rare, unpredictable event with extreme consequences that is rationalized in hindsight
Black swan events are highly improbable, high-impact events that are virtually impossible to predict but seem obvious after they occur.
Question 26: Which statement accurately describes internal audit's appropriate role in an organization's ERM process?
- Internal audit should serve as the primary decision-maker in risk response selection.
- Internal audit should provide objective assurance on the effectiveness of ERM but not own or manage risks. (Correct answer)
- Internal audit should own and manage key enterprise risks to demonstrate its strategic value.
- Internal audit should set the organization's risk appetite on behalf of the board.
Correct answer: Internal audit should provide objective assurance on the effectiveness of ERM but not own or manage risks.
The IIA's guidance is clear that internal audit's role in ERM is to provide objective assurance; taking ownership of risks or making risk decisions impairs auditor independence.
Question 27: A risk-based engagement plan should be formally updated when:
- External auditors complete their annual financial audit
- The internal audit department receives additional budget
- Senior management schedules an all-hands training event
- A significant change in the organization's risk profile occurs (Correct answer)
Correct answer: A significant change in the organization's risk profile occurs
Material changes to the risk environment require corresponding updates to the engagement plan to keep it relevant.
Question 28: A financial institution states it has a 'low appetite for liquidity risk.' Which control environment would be MOST consistent with this appetite?
- Liquidity risk managed at the discretion of individual business unit treasurers.
- Annual review of liquid asset buffers by the CFO.
- Daily liquidity coverage ratio monitoring with automatic escalation triggers. (Correct answer)
- Monthly liquidity stress tests with results shared quarterly with the board.
Correct answer: Daily liquidity coverage ratio monitoring with automatic escalation triggers.
Daily monitoring with automatic escalation reflects the high vigilance and tight controls consistent with a low appetite for liquidity risk.
Question 29: Which stakeholder is ultimately accountable for establishing and maintaining an effective organizational assurance framework?
- The Chief Audit Executive
- The board of directors (Correct answer)
- The external audit partner
- The Chief Risk Officer
Correct answer: The board of directors
Ultimate accountability for governance — including the assurance framework — rests with the board as the highest governing body.
Question 30: Effective board-level risk reporting should primarily enable the board to:
- Replace management's risk assessment with the board's own independent assessment
- Eliminate the need for a separate Risk Committee
- Exercise informed oversight by understanding the organization's key risk exposures relative to appetite (Correct answer)
- Approve every individual risk response action taken by management
Correct answer: Exercise informed oversight by understanding the organization's key risk exposures relative to appetite
Board risk reporting is designed to support oversight and judgment — not operational management — by presenting material risks in context of the approved appetite.
Question 31: How does risk tolerance differ from risk appetite?
- Risk tolerance refers to acceptable variation around specific objectives; risk appetite is the broader strategic risk level (Correct answer)
- Risk tolerance is set by regulators; risk appetite is set by management
- Risk tolerance is always quantitative; risk appetite is always qualitative
- Risk tolerance applies only to financial risks; risk appetite applies to all risks
Correct answer: Risk tolerance refers to acceptable variation around specific objectives; risk appetite is the broader strategic risk level
Risk tolerance is the acceptable variation in outcomes related to specific risk exposures, while risk appetite represents the overall strategic posture toward risk.
Question 32: A risk appetite statement is most effective when it:
- Uses only qualitative language to preserve flexibility
- Links specific risk exposures to measurable thresholds tied to strategic objectives (Correct answer)
- Focuses solely on downside financial risks
- Is drafted by the risk function and approved once at the enterprise level
Correct answer: Links specific risk exposures to measurable thresholds tied to strategic objectives
An effective risk appetite statement connects risk categories to measurable limits and ties them directly to the organization's strategic goals.
Question 33: A risk escalation procedure primarily serves which governance purpose?
- It ensures significant risks are communicated upward to appropriate decision-makers in a timely manner (Correct answer)
- It allows management to avoid reporting risks to the board
- It documents all historical risk events for audit trail purposes
- It transfers risk ownership from the first line to the second line automatically
Correct answer: It ensures significant risks are communicated upward to appropriate decision-makers in a timely manner
Escalation procedures ensure that risks exceeding defined thresholds reach the appropriate governance level before they become crises.
Question 34: An organization in a heavily regulated industry wants to set risk appetite for compliance risk. Which approach is MOST appropriate?
- Set zero tolerance for material compliance breaches and define narrow tolerances for minor procedural deviations. (Correct answer)
- Allow business units to set their own compliance risk appetite independently.
- Set compliance risk appetite equal to the industry average for violations.
- Avoid quantifying compliance risk appetite since regulatory requirements already define limits.
Correct answer: Set zero tolerance for material compliance breaches and define narrow tolerances for minor procedural deviations.
Zero tolerance for material breaches paired with defined narrow tolerances for minor deviations provides a practical and defensible compliance risk appetite framework.
Question 35: How should the emergence of new or rapidly evolving risks influence an organization's risk response strategies?
- Risk responses should be dynamically reassessed and updated to address new exposures (Correct answer)
- Only the board, not management, should update responses to emerging risks
- Existing responses should remain unchanged to maintain control consistency
- Emerging risks require immediate risk avoidance as the default response
Correct answer: Risk responses should be dynamically reassessed and updated to address new exposures
Risk responses must be periodically reviewed and updated to remain effective as the risk landscape evolves; static responses may become inadequate over time.
Question 36: ISO 31000:2018 defines risk as:
- The effect of uncertainty on objectives. (Correct answer)
- The probability of a negative event multiplied by its financial impact.
- The deviation of actual outcomes from expected results.
- Any event that could cause a loss greater than the risk threshold.
Correct answer: The effect of uncertainty on objectives.
ISO 31000:2018 defines risk as 'the effect of uncertainty on objectives,' recognizing that effects can be positive or negative.
Question 37: How does risk capacity differ from risk appetite in the context of CRMA assessments?
- Risk capacity refers to operational risks only, while risk appetite covers all risk categories.
- Risk capacity is subjective, while risk appetite is objectively measurable.
- Risk capacity is set by regulators, while risk appetite is set by management.
- Risk capacity is the maximum risk an organization can absorb without threatening viability; risk appetite is the amount it chooses to accept. (Correct answer)
Correct answer: Risk capacity is the maximum risk an organization can absorb without threatening viability; risk appetite is the amount it chooses to accept.
Risk capacity defines the absolute outer limit of risk an organization can survive, while risk appetite is the strategic choice of how much risk to actually take on within that limit.
Question 38: Which metric is MOST useful when quantitatively assessing risk culture strength across business units?
- Number of employees per manager
- Near-miss reporting rates compared across units (Correct answer)
- Total revenue generated per unit
- Percentage of budget spent on compliance
Correct answer: Near-miss reporting rates compared across units
Near-miss reporting rates reveal willingness to surface risk events, a direct behavioral indicator of risk culture strength.
Question 39: When internal audit lacks specialized expertise to assess a high-risk technical area, the CAE should:
- Skip the area and formally note it as out of scope for the current audit cycle
- Assign the engagement to junior staff for on-the-job professional development
- Engage subject-matter experts or co-source the engagement to ensure competent coverage (Correct answer)
- Request that management assume full responsibility for conducting the self-assessment
Correct answer: Engage subject-matter experts or co-source the engagement to ensure competent coverage
IIA Standards require that engagements be performed with due professional care, which includes obtaining specialized competency when the internal team lacks it.
Question 40: Which principle should guide the CRMA professional when tailoring risk communication for different audiences?
- Use identical technical language across all audiences for consistency
- Always provide the most detailed version to every stakeholder
- Focus exclusively on financial metrics regardless of audience function
- Adapt content depth and terminology to the audience's role and expertise (Correct answer)
Correct answer: Adapt content depth and terminology to the audience's role and expertise
Effective risk communication requires matching the level of detail, terminology, and focus to what each audience needs to make informed decisions.
Question 41: Which of the following is a limitation of expressing risk appetite solely in qualitative terms?
- Qualitative statements cannot be applied to strategic risks.
- They cannot be easily translated into actionable thresholds, making consistent application difficult. (Correct answer)
- They are not accepted by external regulators or rating agencies.
- Qualitative statements are too technical for board members to understand.
Correct answer: They cannot be easily translated into actionable thresholds, making consistent application difficult.
Purely qualitative appetite statements are inherently subjective, making it difficult to consistently determine when a risk level exceeds the stated appetite in practice.
Question 42: Which of the following is the LEAST appropriate consulting role for internal audit to assume?
- Selecting and recommending the organization's external audit firm (Correct answer)
- Providing fraud awareness training to business unit employees
- Reviewing draft policies before their formal implementation
- Facilitating a board self-assessment process
Correct answer: Selecting and recommending the organization's external audit firm
Selecting the external auditor is a governance decision reserved for the audit committee, not an appropriate internal audit consulting function.
Question 43: In the three-lines-of-defense model, internal audit occupies the third line primarily because it:
- Manages day-to-day operational risks directly
- Sets risk policy and risk appetite for the organization
- Coordinates risk oversight with external regulators
- Provides independent assurance to senior management and the board (Correct answer)
Correct answer: Provides independent assurance to senior management and the board
The third line (internal audit) provides independent, objective assurance over the effectiveness of risk management and controls operated by the first and second lines.
Question 44: A risk heat map uses color coding to convey risk severity. Which combination correctly represents standard heat map conventions?
- Green=high risk, Red=low risk, Yellow=moderate risk
- Red=high risk, Yellow=moderate risk, Green=low risk (Correct answer)
- Blue=high risk, Orange=moderate risk, White=low risk
- Purple=high risk, Green=moderate risk, Red=low risk
Correct answer: Red=high risk, Yellow=moderate risk, Green=low risk
Standard risk heat maps use red for high risk, yellow/amber for moderate risk, and green for low risk to enable quick visual assessment.
Question 45: Which of the following is a key characteristic that distinguishes a CRMA holder's role from a traditional internal auditor in relation to risk?
- CRMA holders are authorized to approve risk management policies on behalf of management
- CRMA holders replace the external auditor for risk-related financial assertions
- CRMA holders possess specialized competency to evaluate and provide assurance on risk management processes (Correct answer)
- CRMA holders are exempt from independence requirements when advising on risk
Correct answer: CRMA holders possess specialized competency to evaluate and provide assurance on risk management processes
The CRMA credential signifies specialized competency in evaluating risk management effectiveness and providing assurance—it does not transfer management's risk ownership or waive independence standards.
Question 46: In the Three Lines of Defense model, which group is primarily responsible for owning and managing risks on a day-to-day basis?
- Business unit management (Correct answer)
- Internal audit
- Risk and compliance functions
- The board of directors
Correct answer: Business unit management
Business unit management (the first line) owns and manages risks as part of their operational responsibilities.
Question 47: A board revises its risk appetite to be more conservative following a major industry loss event at a competitor. What should internal audit do FIRST?
- Wait until year-end to incorporate the revised appetite into the audit universe.
- Assess whether existing business activities and controls are still aligned with the revised appetite. (Correct answer)
- Immediately issue findings for any current activities that exceeded the old appetite.
- Update the audit plan's risk ratings to reflect the competitor's loss event.
Correct answer: Assess whether existing business activities and controls are still aligned with the revised appetite.
When risk appetite changes, internal audit should promptly evaluate whether current operations and controls remain aligned with the updated boundaries.
Question 48: A business unit manager asks internal audit to help design a new vendor onboarding process. This is best classified as:
- An assurance engagement
- An internal investigation
- A compliance review
- A consulting engagement (Correct answer)
Correct answer: A consulting engagement
Designing processes is an advisory activity where internal audit serves the client's needs, making it a consulting engagement.
Question 49: Which of the following is the PRIMARY benefit of standardizing risk communication templates across business units?
- Enabling consistent comparison and aggregation of risk information across the enterprise (Correct answer)
- Eliminating the need for qualitative risk narratives
- Assigning risk ownership to a single central team
- Reducing the frequency of required risk reporting
Correct answer: Enabling consistent comparison and aggregation of risk information across the enterprise
Standardized templates allow risk information from different business units to be compared, aggregated, and rolled up into enterprise-level views without manual reconciliation.
Question 50: ISO 31000:2018 identifies which of the following as the first step in the risk management process?
- Risk assessment
- Communication and consultation
- Risk treatment
- Scope, context, and criteria establishment (Correct answer)
Correct answer: Scope, context, and criteria establishment
Establishing the scope, context, and criteria is the first step in the ISO 31000 risk management process, providing the basis for all subsequent steps.
Question 51: Resource constraints require the CAE to reduce planned engagements. The BEST approach is to:
- Defer lower-risk engagements while maintaining focus on the highest-risk areas (Correct answer)
- Outsource the entire audit plan to an external accounting firm
- Reduce engagements proportionally and equally across all risk levels
- Cancel all engagements until additional budget is approved
Correct answer: Defer lower-risk engagements while maintaining focus on the highest-risk areas
Risk-based prioritization ensures that when resources are constrained, audit effort remains concentrated on the highest-risk areas.
Question 52: When internal audit's annual assurance work reveals the ERM framework is fundamentally inadequate, the MOST appropriate reporting action is to:
- Issue a qualified opinion and limit distribution to the CAE
- Consult with external auditors before issuing any opinion
- Withhold the opinion until management has an opportunity to rebuild the framework
- Issue an adverse opinion and communicate it directly to the board and audit committee (Correct answer)
Correct answer: Issue an adverse opinion and communicate it directly to the board and audit committee
A fundamentally inadequate ERM framework warrants an adverse opinion that must be communicated directly to the board and audit committee as the highest governance body.
Question 53: Which action should a CRMA practitioner recommend when an audit reveals that risk culture varies significantly between business units within the same organization?
- Apply a single enterprise-wide policy mandate immediately
- Suspend the units with weak risk culture until improvement is demonstrated
- Replace unit-level leadership uniformly
- Identify the root causes of divergence and recommend targeted interventions tailored to each unit's cultural drivers (Correct answer)
Correct answer: Identify the root causes of divergence and recommend targeted interventions tailored to each unit's cultural drivers
Cultural divergence requires root-cause analysis because the drivers differ by unit; tailored interventions are more effective than uniform mandates.
Question 54: When the audit committee asks internal audit to provide assurance over the organization's ERM program's coverage of emerging risks, what should the internal auditor assess?
- Whether all risks in the register are rated as high to demonstrate thorough risk identification
- Whether management has already mitigated all emerging risks before the audit begins
- Whether the risk identification process includes structured mechanisms for capturing emerging risks and whether the risk register is updated as new risks are identified (Correct answer)
- Whether emerging risks are limited to technology-related topics only
Correct answer: Whether the risk identification process includes structured mechanisms for capturing emerging risks and whether the risk register is updated as new risks are identified
Assurance over emerging risk coverage evaluates whether the organization's risk identification process is designed to capture new and evolving risks systematically.
Question 55: Which scenario represents a 'risk appetite gap'?
- Management takes significantly more risk than the board-approved appetite allows. (Correct answer)
- Two business units have slightly different interpretations of 'moderate' risk.
- The risk appetite statement is written at a high level of abstraction.
- The board sets a moderate appetite, and business units take moderate risks.
Correct answer: Management takes significantly more risk than the board-approved appetite allows.
A risk appetite gap occurs when actual risk-taking behavior materially exceeds or falls short of the board-approved risk appetite.
Question 56: In risk analysis, 'velocity' refers to:
- The rate at which new risks are identified
- The speed at which a risk mitigation plan is implemented
- The pace of residual risk reduction over time
- How quickly a risk event could impact the organization once triggered (Correct answer)
Correct answer: How quickly a risk event could impact the organization once triggered
Velocity (or speed of onset) measures how quickly a risk materializes and affects the organization after it is triggered.
Question 57: When internal audit coordinates with external auditors on ERM-related work, the primary goal is to:
- Transfer responsibility for ERM assurance to the external auditors.
- Align coverage to address the most significant risks without unnecessary duplication. (Correct answer)
- Ensure the external auditors accept internal audit's ERM conclusions without re-testing.
- Reduce the external audit fee by sharing workpapers.
Correct answer: Align coverage to address the most significant risks without unnecessary duplication.
Coordination between internal and external audit aims to maximize coverage of significant risks efficiently, avoiding gaps or redundant testing that wastes both organizations' resources.
Question 58: When assessing risk appetite for a new business venture, management should FIRST:
- Hire external consultants to assess the market risk.
- Seek regulatory pre-approval before evaluating risk appetite fit.
- Determine whether the venture's risk profile falls within the board-approved risk appetite. (Correct answer)
- Conduct a detailed financial modeling exercise.
Correct answer: Determine whether the venture's risk profile falls within the board-approved risk appetite.
Before allocating resources to any new venture, management should confirm the associated risks fit within the board's sanctioned risk appetite.
Question 59: According to ISO 31000, what is the definition of risk?
- The effect of uncertainty on objectives (Correct answer)
- The likelihood of a threat exploiting a vulnerability
- A potential financial loss resulting from an adverse event
- The probability that a negative event will occur
Correct answer: The effect of uncertainty on objectives
ISO 31000 defines risk as 'the effect of uncertainty on objectives,' encompassing both positive and negative outcomes.
Question 60: An internal auditor who previously managed the accounts payable department is asked to consult on AP process improvements. The auditor should:
- Decline permanently because prior management involvement creates an irrecoverable disqualification
- Accept freely since consulting requires a lower standard of independence than assurance
- Disclose the prior management role, assess objectivity impairment, and disclose if proceeding despite impairment (Correct answer)
- Obtain written approval from the external auditors before accepting the consulting request
Correct answer: Disclose the prior management role, assess objectivity impairment, and disclose if proceeding despite impairment
Prior management roles create objectivity risk; disclosure is required, and the auditor must assess and disclose whether they can proceed objectively.
Question 61: A Risk Management Committee Charter should explicitly address all of the following EXCEPT:
- Individual salary levels for risk management staff (Correct answer)
- Membership composition and quorum requirements
- Frequency and format of reporting to the board
- The committee's authority and scope of oversight
Correct answer: Individual salary levels for risk management staff
Committee charters define governance structure, authority, and reporting obligations — compensation matters are typically governed by the Compensation Committee, not a Risk Committee charter.
Question 62: In the Institute of Internal Auditors' Three Lines Model (2020), what is the primary role of the second line?
- Supporting management's risk and control responsibilities through expertise and oversight (Correct answer)
- Providing independent assurance to the board
- Setting the organization's overall risk strategy
- Owning and managing risks within business operations
Correct answer: Supporting management's risk and control responsibilities through expertise and oversight
The second line provides expertise, support, and monitoring to assist first-line management in managing risk and controls effectively.
Question 63: Which of the following best describes 'risk culture' within an organization?
- The documented risk appetite statement approved by the board
- The number of risk management certifications held by employees
- The formal risk register maintained by the risk department
- The shared values, beliefs, and behaviors related to risk awareness and management (Correct answer)
Correct answer: The shared values, beliefs, and behaviors related to risk awareness and management
Risk culture encompasses the shared values, norms, and behaviors that influence how employees at all levels identify, understand, and respond to risk.
Question 64: When the board requests a risk culture assessment, which source of evidence should the internal auditor prioritize LAST?
- Whistleblower and hotline trend data
- Employee behavioral observation data
- Control failure and near-miss incident patterns
- Management's self-assessment of risk culture (Correct answer)
Correct answer: Management's self-assessment of risk culture
Management self-assessments are subject to self-serving bias and should be corroborated with objective behavioral and incident data before being relied upon.
Question 65: Which COSO ERM component is MOST directly evaluated when internal audit assesses whether the organization has correctly identified its key risks?
- Monitoring Activities
- Control Activities
- Event Identification (Correct answer)
- Information and Communication
Correct answer: Event Identification
Event Identification within COSO ERM addresses the process of recognizing potential events that could affect the achievement of objectives, which aligns directly with risk identification assessment.
Question 66: Which of the following must be communicated even if a consulting engagement scope does not include it?
- All operational observations regardless of their materiality or significance
- Benchmark comparisons with relevant industry peers discovered during research
- Minor process inefficiencies observed incidentally during fieldwork
- Significant governance, risk, or control issues identified during the engagement (Correct answer)
Correct answer: Significant governance, risk, or control issues identified during the engagement
Significant issues must be communicated regardless of consulting scope limitations — scope does not excuse non-disclosure of material findings.
Question 67: Which of the following best illustrates a 'strategic risk'?
- A power outage that temporarily shuts down a manufacturing plant
- A slip-and-fall injury sustained by a customer on company premises
- A disruptive new technology that renders the company's core product obsolete (Correct answer)
- A payroll processing error that results in employee overpayments
Correct answer: A disruptive new technology that renders the company's core product obsolete
Strategic risks threaten an organization's ability to achieve its long-term objectives; disruptive technology is a classic example that can undermine an entire business model.
Question 68: The IIA Standards require that internal auditors assess organizational culture as part of their work because:
- Culture shapes the control environment and influences the likelihood of control effectiveness (Correct answer)
- Culture determines the external audit fee
- Culture scores are used to benchmark compensation levels
- Cultural assessments are required by all financial regulators
Correct answer: Culture shapes the control environment and influences the likelihood of control effectiveness
The IIA recognizes that culture is a foundational component of the control environment and directly affects whether controls operate as intended.
Question 69: Which of the following is the MOST important characteristic of a well-designed risk identification process?
- It focuses solely on financial and operational risks
- It is conducted exclusively by the internal audit function
- It is periodic, structured, and involves stakeholders across all levels of the organization (Correct answer)
- It is completed before the annual budgeting process begins
Correct answer: It is periodic, structured, and involves stakeholders across all levels of the organization
Effective risk identification is ongoing, structured, and inclusive—drawing on input from diverse stakeholders to ensure comprehensive coverage.
Question 70: When multiple consulting projects compete for limited internal audit resources, the CAE should prioritize based on:
- The potential to convert consulting findings into future assurance engagements
- The chronological order in which requests were received by the audit team
- The seniority of the manager submitting each consultation request
- Risk significance and alignment with organizational strategic priorities (Correct answer)
Correct answer: Risk significance and alignment with organizational strategic priorities
Resource allocation for consulting should reflect risk significance and strategic organizational value, applying the same risk-based approach used in audit planning.
Question 71: An organization has experienced repeated control failures despite strong risk policies. The CRMA practitioner should first investigate:
- Whether risk training is delivered by external vendors
- Whether cultural norms in specific departments normalize bypassing controls (Correct answer)
- Whether the risk policies are too detailed and complex
- Whether the board receives weekly risk reports
Correct answer: Whether cultural norms in specific departments normalize bypassing controls
Repeated failures despite strong policies suggest a cultural enforcement gap where local norms override formal controls in practice.
Question 72: When an organization adopts a new enterprise risk framework, how should the coordinated assurance plan be updated?
- No update is needed if the existing assurance plan was approved within the last 12 months
- Only the compliance function's testing scope needs to change
- External auditors should take full responsibility for updating the plan
- The assurance map and coverage assignments should be realigned to reflect the new risk taxonomy and updated risk priorities (Correct answer)
Correct answer: The assurance map and coverage assignments should be realigned to reflect the new risk taxonomy and updated risk priorities
A new risk framework changes how risks are categorized and prioritized, requiring the assurance map to be realigned so coverage remains relevant.
Question 73: A CRMA professional conducting an ERM assurance engagement should evaluate whether management has:
- Achieved zero residual risk across all key operational processes.
- Replaced all qualitative risk assessments with quantitative models.
- Eliminated all risks rated 'high' on the risk heat map.
- Designed and implemented risk responses proportionate to the identified risk ratings. (Correct answer)
Correct answer: Designed and implemented risk responses proportionate to the identified risk ratings.
ERM assurance focuses on whether risk responses are proportionate and effective — not on eliminating all risk, which would be neither possible nor desirable.
Question 74: A significant gap in ERM coverage is identified by internal audit. Who should receive this finding FIRST?
- Management, so they have an opportunity to remediate before board communication (Correct answer)
- External auditors so they can include it in their report
- The board audit committee directly, bypassing management
- Regulatory bodies because it represents a compliance breach
Correct answer: Management, so they have an opportunity to remediate before board communication
Standard practice requires informing management first so they can respond; internal audit escalates to the board if management does not act adequately.
Question 75: Which principle belongs to the 'Governance & Culture' component of COSO ERM 2017?
- Assesses severity of risk
- Defines desired culture (Correct answer)
- Develops portfolio view
- Identifies risk
Correct answer: Defines desired culture
Defining desired culture is one of the five principles within the Governance & Culture component, reflecting the board and management's tone at the top.
Question 76: The concept of 'risk aggregation' in response planning is BEST described as:
- Assessing how multiple individual risks combine to affect overall organizational risk exposure (Correct answer)
- Combining individual risk responses into a single control framework
- Grouping risks by category so one response can address all risks in the group
- Averaging the impact scores of all identified risks to determine a response priority
Correct answer: Assessing how multiple individual risks combine to affect overall organizational risk exposure
Risk aggregation involves understanding how multiple individual risks interact and combine, potentially creating a total exposure greater than the sum of individual risks.
Question 77: An internal auditor is reviewing a manufacturing company's risk appetite for workplace safety. Which finding would indicate the stated appetite is NOT effectively operationalized?
- Safety training is conducted annually for all employees.
- A safety officer reports to the VP of Operations.
- Incident rates are tracked monthly but never compared to appetite thresholds. (Correct answer)
- The safety risk appetite statement was approved by the CEO.
Correct answer: Incident rates are tracked monthly but never compared to appetite thresholds.
Tracking incident rates without comparing them to appetite thresholds means data exists but is not being used to manage risk within stated boundaries.
Question 78: An internal auditor notices that a business unit consistently operates at the upper boundary of its approved risk tolerance. What is the MOST important concern to raise?
- The business unit is technically within limits, so no action is needed.
- Consistently operating near the boundary suggests the unit may breach tolerance during adverse conditions, warranting proactive management attention. (Correct answer)
- The tolerance level should be raised to match the unit's actual behavior.
- The risk appetite statement needs to be rewritten to be less restrictive.
Correct answer: Consistently operating near the boundary suggests the unit may breach tolerance during adverse conditions, warranting proactive management attention.
Operating consistently at the boundary of tolerance leaves no buffer; any adverse event could push actual risk above approved limits, which is a material concern for management.
Question 79: When should an organization's risk appetite statement be formally reviewed?
- Every five years as part of the strategic planning cycle.
- At least annually and whenever there is a material change in strategy, environment, or key risks. (Correct answer)
- Only when a significant risk event occurs within the organization.
- Whenever internal audit recommends a change.
Correct answer: At least annually and whenever there is a material change in strategy, environment, or key risks.
Risk appetite should be reviewed at least annually and triggered by material changes in strategy or risk environment to remain relevant and aligned.
Question 80: In the context of risk communication, what does 'risk appetite statement' primarily serve to communicate?
- The compensation structure for risk management professionals
- The specific controls implemented to manage each identified risk
- The historical frequency of risk events over the past fiscal year
- The types and amounts of risk the organization is willing to accept in pursuing objectives (Correct answer)
Correct answer: The types and amounts of risk the organization is willing to accept in pursuing objectives
A risk appetite statement communicates the boundaries within which the organization is prepared to operate, guiding decision-making across all levels.
Question 81: When implementing an ERM framework, which step should occur BEFORE selecting risk treatment options?
- Drafting the risk appetite statement
- Establishing risk reporting templates
- Conducting a risk assessment (Correct answer)
- Defining key risk indicators
Correct answer: Conducting a risk assessment
Risk assessment — including identification, analysis, and evaluation — must precede treatment decisions so that responses are matched to actual risk exposures.
Question 82: Which of the following is a key limitation of using only historical data for risk identification?
- Historical data is too expensive to collect
- It overstates the likelihood of low-probability risks
- It cannot be used in quantitative risk models
- It may not capture emerging or novel risks with no prior occurrence (Correct answer)
Correct answer: It may not capture emerging or novel risks with no prior occurrence
Historical data reflects past events and may miss entirely new risk categories, disruptive technologies, or unprecedented scenarios.
Question 83: The primary purpose of documenting work papers in a consulting engagement is to:
- Support the engagement's conclusions and facilitate quality assurance review (Correct answer)
- Share detailed findings directly with external auditors automatically
- Create admissible evidence for potential future litigation
- Satisfy regulatory filing requirements for consulting activities
Correct answer: Support the engagement's conclusions and facilitate quality assurance review
Work papers support consulting conclusions and enable supervisory review of the work performed, paralleling assurance documentation requirements.
Question 84: An accountability framework for risk management is most effective when it links:
- Board risk oversight responsibilities to external auditor compensation
- Risk ownership and risk outcomes to individual and organizational performance evaluation processes (Correct answer)
- Risk events exclusively to legal penalties for responsible employees
- Risk appetite limits to specific financial investment thresholds only
Correct answer: Risk ownership and risk outcomes to individual and organizational performance evaluation processes
Linking risk ownership and outcomes to performance evaluation creates genuine accountability and motivates appropriate risk behavior throughout the organization.
Question 85: In coordinating with external auditors on a Sarbanes-Oxley Section 404 engagement, internal audit's primary contribution is typically to:
- Approve the external audit firm's independence disclosure to the SEC
- Replace management's ICFR assessment with an internal audit assessment
- Perform controls testing that external auditors can leverage, reducing total audit cost and effort (Correct answer)
- Issue the external auditor's opinion on internal control over financial reporting
Correct answer: Perform controls testing that external auditors can leverage, reducing total audit cost and effort
Internal audit performs controls testing that external auditors can rely on under PCAOB standards, enabling more efficient SOX 404 audits overall.
Question 86: When coordinating with external auditors, internal audit's PRIMARY objective is to:
- Adopt the same audit methodology to ensure consistent findings
- Minimize duplication of effort and maximize total assurance coverage (Correct answer)
- Transfer all financial audit work to external auditors
- Present a unified report to management under a single signature
Correct answer: Minimize duplication of effort and maximize total assurance coverage
Effective coordination reduces duplication, optimizes resource use, and ensures combined assurance covers all significant risk areas without gaps.
Question 87: An organization's legal team identifies a new regulation taking effect in 90 days. This is an example of which type of risk identification source?
- Internal operational data
- Employee survey feedback
- External environmental scanning (Correct answer)
- Internal audit finding
Correct answer: External environmental scanning
Monitoring regulatory changes in the external environment is a classic form of environmental scanning used to identify emerging compliance risks.
Question 88: What is the most appropriate reporting line for a Chief Risk Officer (CRO) to maintain risk governance independence?
- Chief Compliance Officer
- Chief Financial Officer
- Chief Operating Officer
- Chief Executive Officer or Board Risk Committee (Correct answer)
Correct answer: Chief Executive Officer or Board Risk Committee
The CRO should report to the CEO or directly to the Board Risk Committee to maintain sufficient independence and authority.
Question 89: A technology company faces the risk that a competitor could launch a superior product within 12 months. Which risk category does this most likely represent?
- Operational risk
- Compliance risk
- Strategic risk (Correct answer)
- Financial risk
Correct answer: Strategic risk
Competitive threats that affect an organization's strategic position and market share are classified as strategic risks.
Question 90: Risk velocity in enterprise risk management refers to:
- The speed at which a risk event could impact the organization after occurring (Correct answer)
- The rate at which new risks are added to the risk register
- The dollar magnitude of a risk if it materializes
- The frequency of risk committee meetings
Correct answer: The speed at which a risk event could impact the organization after occurring
Risk velocity measures how quickly a risk could affect the organization once it is triggered, influencing the time available to respond.
Question 91: According to CRMA principles, who holds primary responsibility for selecting and implementing risk responses?
- Management (Correct answer)
- The board of directors
- The external auditor
- The Chief Audit Executive (CAE)
Correct answer: Management
Management holds primary responsibility for identifying, selecting, and implementing risk responses as part of its ownership of the risk management process; internal audit provides assurance over that process.
Question 92: In the context of CRMA practice, 'culture audit' differs from a standard compliance audit primarily because it:
- Requires board pre-approval for every finding communicated
- Focuses on financial statement accuracy
- Assesses informal behaviors, norms, and values rather than adherence to documented policies and procedures (Correct answer)
- Is conducted exclusively by external auditors
Correct answer: Assesses informal behaviors, norms, and values rather than adherence to documented policies and procedures
A culture audit examines the unwritten rules, actual behaviors, and shared values that drive decisions, whereas compliance audits verify adherence to formal requirements.
Question 93: When using scenario analysis for risk identification, the primary benefit is:
- Exploring plausible future states to uncover risks that may not be apparent in current operations (Correct answer)
- Automating the risk register update process
- Reducing the time needed to document risks
- Eliminating the need for quantitative risk models
Correct answer: Exploring plausible future states to uncover risks that may not be apparent in current operations
Scenario analysis helps organizations anticipate risks by examining hypothetical but plausible future situations.
Question 94: Which risk treatment option is most appropriate when a risk's likelihood and impact are both very low?
- Immediately escalate to senior management
- Avoid the risk by discontinuing the activity
- Transfer the risk to an insurer
- Accept the risk without additional controls (Correct answer)
Correct answer: Accept the risk without additional controls
When both likelihood and impact are low, accepting the risk (retaining it without additional controls) is typically the most cost-effective response.
Question 95: A well-designed assurance coordination framework should address which of the following elements?
- Only financial and compliance risks to limit scope and cost
- The specific audit software tools each provider must use
- Individual performance metrics for each auditor across all lines
- Roles, responsibilities, communication protocols, reliance criteria, and reporting mechanisms across all providers (Correct answer)
Correct answer: Roles, responsibilities, communication protocols, reliance criteria, and reporting mechanisms across all providers
An effective framework defines how providers interact, who covers what, how findings are shared, and how results are reported to governance.
Question 96: In an ERM context, internal audit's most appropriate consulting role includes:
- Taking ownership of the risk register and maintaining it on an ongoing basis
- Replacing the risk management function during organizational restructuring transitions
- Setting the organization's risk appetite on behalf of the board and senior management
- Facilitating risk identification workshops and providing ERM education to management (Correct answer)
Correct answer: Facilitating risk identification workshops and providing ERM education to management
Internal audit can facilitate and educate on ERM without owning the process, preserving its independence and ability to provide future assurance on ERM effectiveness.
Question 97: When should internal audit rely on the work of other assurance providers rather than performing independent testing?
- Never, because independence requires all evidence to be self-gathered
- When the other provider's competence, objectivity, and due professional care can be assessed and confirmed (Correct answer)
- Always, to maximize resource efficiency
- Only when the external auditor has previously reviewed and approved the work
Correct answer: When the other provider's competence, objectivity, and due professional care can be assessed and confirmed
IIA standards allow reliance on other assurance providers when internal audit has assessed and is satisfied with their competence, objectivity, and application of due professional care.
Question 98: Which internal audit activity provides the STRONGEST evidence of tone at the top regarding risk culture?
- Reviewing the wording of the company's published risk appetite statement
- Observing whether executives attend and actively engage in risk committee meetings (Correct answer)
- Analyzing the risk section of the annual report
- Counting the number of risk training hours completed by executives
Correct answer: Observing whether executives attend and actively engage in risk committee meetings
Direct behavioral observation of executive engagement in risk governance provides stronger evidence than documents or reported metrics alone.
Question 99: A risk scenario that has a low likelihood but very high potential impact is most appropriately managed by:
- Accepting it since the chance of occurrence is low
- Ignoring it because the probability is negligible
- Treating it with contingency or continuity plans due to its severity (Correct answer)
- Reporting it as a current loss in the financial statements
Correct answer: Treating it with contingency or continuity plans due to its severity
High-impact, low-likelihood risks (often called 'tail risks') warrant contingency planning and business continuity measures to limit consequences if they do occur.
Question 100: Internal audit should decline a consulting engagement when:
- The subject matter is somewhat unfamiliar to the current audit team
- The engagement cannot be completed within the current fiscal year
- Accepting the work would require internal audit to assume management responsibility for decisions (Correct answer)
- The request originates from the CEO rather than the audit committee
Correct answer: Accepting the work would require internal audit to assume management responsibility for decisions
Accepting management responsibility crosses the line from consulting into managing operations, which violates internal audit independence principles.
Question 101: How does risk-based engagement planning BEST integrate with an organization's Enterprise Risk Management (ERM) framework?
- ERM and internal audit planning operate as completely independent, unconnected functions
- Internal audit uses ERM risk data to inform engagement prioritization while maintaining independent judgment (Correct answer)
- ERM eliminates the need for a separate internal audit planning process
- Internal audit solely validates ERM outputs and does not conduct independent assessment
Correct answer: Internal audit uses ERM risk data to inform engagement prioritization while maintaining independent judgment
Internal audit leverages ERM risk information as a valuable input to planning while preserving its own independent risk assessment.
Question 102: When building a risk-based engagement plan, which method BEST prioritizes auditable entities?
- Alphabetical ordering of business units
- Random sampling across all departments
- Selection based solely on management requests
- Risk ranking by inherent risk and control effectiveness (Correct answer)
Correct answer: Risk ranking by inherent risk and control effectiveness
Risk-based planning prioritizes entities by weighing inherent risk against the strength of existing controls.
Question 103: Which cultural attribute, when present, is MOST predictive of effective risk escalation in an organization?
- Mandatory ethics training completed annually
- A formalized escalation policy in the employee handbook
- Presence of a dedicated chief risk officer
- Psychological safety to speak up without fear of retaliation (Correct answer)
Correct answer: Psychological safety to speak up without fear of retaliation
Psychological safety—the belief that one can raise concerns without punishment—is the primary behavioral enabler of timely risk escalation.
Question 104: A CAE is asked to join a project steering committee as a non-voting advisor. This arrangement:
- Is acceptable if the CAE maintains objectivity and discloses the advisory role for future work (Correct answer)
- Automatically converts all future audits of the project into consulting engagements
- Requires prior approval from external regulators before participation
- Is always prohibited under IIA Standards regardless of voting status
Correct answer: Is acceptable if the CAE maintains objectivity and discloses the advisory role for future work
Non-voting advisory participation is permissible when the CAE maintains objectivity and discloses the involvement before any future assurance work on the project.
Question 105: Which risk identification technique is MOST useful for uncovering risks associated with a specific business process through systematic 'what if' questioning?
- Internal audit sampling
- Balanced scorecard review
- Key risk indicator (KRI) monitoring
- Hazard and Operability Study (HAZOP) (Correct answer)
Correct answer: Hazard and Operability Study (HAZOP)
HAZOP uses structured 'what if' guide words to systematically probe each part of a process for potential deviations and their risk consequences.
Question 106: When risk information is communicated upward through the organization, which phenomenon represents a significant threat to accuracy?
- Use of technical jargon in executive summaries
- Delayed reporting due to data collection cycles
- Over-documentation of minor operational risks
- Information filtering where bad news is softened at each management layer (Correct answer)
Correct answer: Information filtering where bad news is softened at each management layer
Upward communication filtering occurs when managers suppress or soften negative information, causing senior leaders to receive an inaccurate, overly optimistic picture of risk.
Question 107: Under the Basel II/III operational risk framework, the Advanced Measurement Approach (AMA) required banks to use:
- A standardized percentage of gross income
- A regulatory-set fixed capital charge
- External loss data only
- Their own internal models validated by regulators (Correct answer)
Correct answer: Their own internal models validated by regulators
The AMA allowed banks to use their own quantitative models for operational risk capital calculation, subject to regulatory approval and validation.
Question 108: When communicating risk information verbally to an executive, which practice MOST undermines effectiveness?
- Using technical risk jargon without confirming the executive's familiarity with terms (Correct answer)
- Connecting risk information to the executive's specific area of responsibility
- Summarizing key points before diving into supporting detail
- Asking whether the executive has questions after presenting the information
Correct answer: Using technical risk jargon without confirming the executive's familiarity with terms
Using technical jargon with audiences who may not share the same terminology creates confusion and reduces the likelihood that the risk message will be understood and acted upon.
Question 109: Which of the following is an example of a 'leading' risk indicator?
- Percentage of staff who have not completed mandatory compliance training (Correct answer)
- Total financial losses from operational failures in the prior year
- Number of audit findings closed in the current period
- Number of fraud incidents reported last quarter
Correct answer: Percentage of staff who have not completed mandatory compliance training
A leading indicator is a forward-looking metric—such as incomplete training rates—that signals potential future risk events before they occur.
Question 110: Key Risk Indicators (KRIs) are best described as:
- Financial ratios used exclusively by the CFO to monitor liquidity risk.
- Metrics that measure losses after a risk event has occurred.
- Audit findings documented in the internal audit report.
- Forward-looking metrics that signal increasing risk exposure before losses materialize. (Correct answer)
Correct answer: Forward-looking metrics that signal increasing risk exposure before losses materialize.
KRIs are leading indicators designed to provide early warning of rising risk levels, enabling proactive management before a risk event causes harm.
Question 111: An organization rewards employees who exceed revenue targets regardless of the risk methods used. What risk culture problem does this indicate?
- Incentive structures that undermine risk-aware behavior (Correct answer)
- Insufficient risk training programs
- Poor risk appetite documentation
- Inadequate segregation of duties
Correct answer: Incentive structures that undermine risk-aware behavior
When incentive systems reward results without regard to risk behavior, they send cultural signals that undermine the organization's stated risk values.
Question 112: Which of the following BEST illustrates a qualitative risk appetite statement?
- We will not pursue business opportunities that conflict with our ethical values. (Correct answer)
- We will not accept losses exceeding $5 million in any single quarter.
- We maintain a maximum debt-to-equity ratio of 2:1.
- We target a minimum credit rating of BBB from all rating agencies.
Correct answer: We will not pursue business opportunities that conflict with our ethical values.
Qualitative statements describe risk appetite in non-numeric, principle-based terms, such as ethical standards, rather than specific measurable thresholds.
Question 113: In risk-based engagement planning, 'audit coverage' is BEST measured by:
- Ratio of internal audit staff headcount to total organization headcount
- Proportion of identified high-risk areas included in the audit plan relative to total risks cataloged (Correct answer)
- Total audit hours consumed per business unit over the plan year
- Percentage of completed audit findings that management resolved within 90 days
Correct answer: Proportion of identified high-risk areas included in the audit plan relative to total risks cataloged
Meaningful audit coverage ensures the plan systematically addresses high-risk areas rather than simply maximizing activity volume.
Question 114: When communicating about risk culture, which indicator BEST reflects a healthy risk communication environment?
- Risk discussions are confined to the risk management department
- Staff at all levels feel safe reporting concerns and near-misses without fear of retaliation (Correct answer)
- Risk information flows exclusively from senior management downward
- Employees rarely raise risk concerns because controls are believed to be sufficient
Correct answer: Staff at all levels feel safe reporting concerns and near-misses without fear of retaliation
A healthy risk culture is characterized by psychological safety, where employees at all levels willingly surface concerns and near-misses without fear of negative consequences.
Question 115: Cross-functional risk governance committees are most valuable when:
- The board wants to reduce the total number of risk management staff
- Internal audit needs to expand its scope beyond financial controls
- A single department wants to own all enterprise risks independently
- Risks span multiple business units and require coordinated management across organizational silos (Correct answer)
Correct answer: Risks span multiple business units and require coordinated management across organizational silos
Cross-functional committees are designed to manage interconnected risks that no single unit can address in isolation.
Question 116: An organization faces increasing risk from ransomware attacks. In assessing this risk under ERM, what is the MOST critical factor to evaluate in the organization's resilience?
- The age of the organization's antivirus software license
- The number of cybersecurity training sessions completed by employees in the last year
- The adequacy of tested data backup and recovery capabilities, including recovery time objectives aligned with business continuity requirements (Correct answer)
- Whether the organization has cyber insurance without testing recovery processes
Correct answer: The adequacy of tested data backup and recovery capabilities, including recovery time objectives aligned with business continuity requirements
Ransomware resilience depends fundamentally on the ability to restore operations quickly from clean backups, making recovery testing the most critical assurance area.
Question 117: Coverage duplication occurs when multiple assurance providers independently test the same control without coordination. What is the MOST significant risk of this situation?
- Inflated assurance budgets that benefit shareholders
- Excessive assurance coverage that improves risk detection accuracy
- External auditors losing access to internal audit workpapers
- Wasted resources and increased burden on control owners without proportional risk reduction (Correct answer)
Correct answer: Wasted resources and increased burden on control owners without proportional risk reduction
Duplicated coverage wastes limited assurance resources and strains control owners through repeated testing of the same area.
Question 118: Risk-adjusted performance management in risk governance is designed to:
- Replace traditional financial reporting with risk-based metrics
- Penalize business units that report risk events
- Ensure that performance metrics account for the level of risk taken to achieve results (Correct answer)
- Allow management to bypass risk limits during high-growth periods
Correct answer: Ensure that performance metrics account for the level of risk taken to achieve results
Risk-adjusted performance management prevents rewarding returns that were achieved by taking excessive or unauthorized risks.
Question 119: The COSO ERM 2017 framework is organized around how many interrelated components?
- Nine
- Seven
- Three
- Five (Correct answer)
Correct answer: Five
COSO ERM 2017 contains five interrelated components: Governance & Culture, Strategy & Objective-Setting, Performance, Review & Revision, and Information, Communication & Reporting.
Question 120: A risk maturity model typically measures an organization's ERM capabilities across how many levels?
- Three
- Seven
- Five (Correct answer)
- Four
Correct answer: Five
Most risk maturity models (such as RIMS Risk Maturity Model) use five levels ranging from ad hoc/initial to optimized/advanced.
Question 121: A retail bank's risk appetite states it accepts 'moderate credit risk.' A loan officer approves a portfolio of subprime loans representing 40% of the loan book. Internal audit should PRIMARILY evaluate whether:
- The subprime borrowers were notified of their loan terms.
- The loans were documented in accordance with underwriting policy.
- The subprime concentration aligns with what the board intended by 'moderate credit risk.' (Correct answer)
- The loan officer had the proper authority to approve each loan.
Correct answer: The subprime concentration aligns with what the board intended by 'moderate credit risk.'
The key audit question is whether the actual risk taken — a heavy subprime concentration — is consistent with what the board defined as 'moderate' credit risk appetite.
Question 122: Under the Three Lines of Defense model, the second line's primary governance role is to:
- Oversee, challenge, and support first-line risk management activities (Correct answer)
- Approve the annual risk appetite statement
- Execute transactions and control day-to-day operations
- Provide independent assurance to the board on risk management effectiveness
Correct answer: Oversee, challenge, and support first-line risk management activities
The second line (risk and compliance functions) oversees, challenges, and supports the first line rather than owning operational risk directly.
Question 123: Which of the following BEST describes the role of a risk communication plan within an organization's broader risk management framework?
- It assigns financial budgets for risk mitigation activities
- It replaces the enterprise risk register with a simplified summary document
- It defines how, when, and to whom risk information will be delivered across the organization (Correct answer)
- It documents past risk events and lessons learned exclusively
Correct answer: It defines how, when, and to whom risk information will be delivered across the organization
A risk communication plan ensures that the right risk information reaches the right people at the right time through appropriate channels, supporting informed decision-making.
Question 124: Which risk response approach is MOST appropriate for a low-likelihood, low-impact risk?
- Risk reduction through multiple controls
- Risk transfer
- Risk acceptance (Correct answer)
- Risk avoidance
Correct answer: Risk acceptance
Low-likelihood, low-impact risks typically fall within risk tolerance, making acceptance the most cost-effective and practical response.
Question 125: In the three lines of defense model, which line is responsible for managing risk on a day-to-day basis?
- The board of directors
- Risk management and compliance functions
- Internal audit
- Operational management (Correct answer)
Correct answer: Operational management
The first line of defense—operational management—owns and manages risk as part of daily business activities.
Certification in Risk Management Assurance (CRMA)
The CRMA exam, administered by The Institute of Internal Auditors (IIA), validates a professional's ability to provide assurance on the entire risk management process, from risk identification and assessment to risk response and reporting.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds