CRMA Basic 2 — Questions and Answers
Question 1: According to ISO 31000, what is the definition of risk?
- The probability that a negative event will occur
- The effect of uncertainty on objectives (Correct answer)
- A potential financial loss resulting from an adverse event
- The likelihood of a threat exploiting a vulnerability
Correct answer: The effect of uncertainty on objectives
ISO 31000 defines risk as 'the effect of uncertainty on objectives,' encompassing both positive and negative outcomes.
Question 2: Which component of COSO ERM directly addresses the 'tone at the top' of an organization?
- Risk Assessment
- Control Activities
- Governance and Culture (Correct answer)
- Information and Communication
Correct answer: Governance and Culture
The Governance and Culture component of COSO ERM establishes oversight responsibilities and desired behaviors, including tone at the top.
Question 3: What is 'risk appetite' as used in enterprise risk management?
- The maximum loss an organization can absorb before insolvency
- The amount and type of risk an organization is willing to pursue or retain (Correct answer)
- The residual risk remaining after controls are applied
- The likelihood assigned to a risk event during assessment
Correct answer: The amount and type of risk an organization is willing to pursue or retain
Risk appetite is the amount and type of risk an organization is willing to pursue or retain in order to achieve its strategic objectives.
Question 4: In the three lines of defense model, which line is responsible for managing risk on a day-to-day basis?
- Internal audit
- Risk management and compliance functions
- Operational management (Correct answer)
- The board of directors
Correct answer: Operational management
The first line of defense—operational management—owns and manages risk as part of daily business activities.
Question 5: Which type of risk response involves sharing a portion of the risk with a third party, such as an insurer?
- Accept
- Avoid
- Transfer (Correct answer)
- Reduce
Correct answer: Transfer
Risk transfer involves shifting some or all of the financial consequences of a risk to a third party, such as through insurance or outsourcing.
Question 6: A key risk indicator (KRI) differs from a key performance indicator (KPI) primarily because a KRI:
- Measures actual outcomes after they have occurred
- Provides forward-looking signals of increasing risk exposure (Correct answer)
- Is used exclusively by internal auditors
- Focuses only on financial metrics
Correct answer: Provides forward-looking signals of increasing risk exposure
KRIs are leading, predictive metrics that signal rising risk exposure before a risk event materializes, unlike KPIs which measure performance outcomes.
Question 7: Under the CRMA framework, an internal auditor providing risk management assurance should primarily evaluate:
- Whether all identified risks have been eliminated
- The adequacy and effectiveness of the organization's risk management processes (Correct answer)
- The accuracy of financial statements produced by management
- Whether external auditors have reviewed all high-risk areas
Correct answer: The adequacy and effectiveness of the organization's risk management processes
CRMA holders assess whether risk management processes are adequate and effective, not whether every risk has been eliminated.
According to ISO 31000, what is the definition of risk?