CRMA Basic 3 — Questions and Answers
Question 1: Which risk treatment option is most appropriate when a risk's likelihood and impact are both very low?
- Avoid the risk by discontinuing the activity
- Transfer the risk to an insurer
- Accept the risk without additional controls (Correct answer)
- Immediately escalate to senior management
Correct answer: Accept the risk without additional controls
When both likelihood and impact are low, accepting the risk (retaining it without additional controls) is typically the most cost-effective response.
Question 2: What does 'inherent risk' represent in a risk assessment?
- The risk remaining after management controls are applied
- The risk that exists before any mitigating controls are considered (Correct answer)
- The risk associated with the internal audit function itself
- The risk transferred to a third party through contracts
Correct answer: The risk that exists before any mitigating controls are considered
Inherent risk is the level of risk that exists before any controls or mitigating actions are in place.
Question 3: In a risk heat map, what do the axes typically represent?
- Cost of control and control effectiveness
- Likelihood of occurrence and impact if it occurs (Correct answer)
- Risk owner and risk category
- Detection time and recovery cost
Correct answer: Likelihood of occurrence and impact if it occurs
A risk heat map plots risks on a two-dimensional grid using likelihood (probability) on one axis and impact (consequence) on the other.
Question 4: Which of the following best describes 'risk culture' within an organization?
- The documented risk appetite statement approved by the board
- The shared values, beliefs, and behaviors related to risk awareness and management (Correct answer)
- The formal risk register maintained by the risk department
- The number of risk management certifications held by employees
Correct answer: The shared values, beliefs, and behaviors related to risk awareness and management
Risk culture encompasses the shared values, norms, and behaviors that influence how employees at all levels identify, understand, and respond to risk.
Question 5: The COSO Internal Control – Integrated Framework identifies how many components of internal control?
- Three
- Four
- Five (Correct answer)
- Seven
Correct answer: Five
COSO's Internal Control – Integrated Framework consists of five components: Control Environment, Risk Assessment, Control Activities, Information & Communication, and Monitoring.
Question 6: When internal audit provides consulting services related to risk management, the chief audit executive must ensure that:
- The internal audit activity assumes ownership of risk management outcomes
- Objectivity is safeguarded and management retains risk ownership (Correct answer)
- Risk consulting replaces the need for assurance engagements
- External consultants co-sign all risk management reports
Correct answer: Objectivity is safeguarded and management retains risk ownership
During risk management consulting, internal audit must safeguard its objectivity and ensure management—not internal audit—retains ownership of risk decisions.
Question 7: Which of the following is an example of a control that addresses the 'detection' rather than the 'prevention' of risk?
- Segregation of duties in payment processing
- Mandatory pre-approval for vendor contracts
- Reconciliation of bank statements to the general ledger (Correct answer)
- Physical locks on server room doors
Correct answer: Reconciliation of bank statements to the general ledger
Bank reconciliations detect discrepancies after transactions occur, making them detective controls rather than preventive ones.
Which risk treatment option is most appropriate when a risk's likelihood and impact are both very low?