CRMA Internal Audit's Assurance Role 3 — Questions and Answers
Question 1: Which COSO ERM component is MOST directly evaluated when internal audit assesses whether the organization has correctly identified its key risks?
- Control Activities
- Event Identification (Correct answer)
- Information and Communication
- Monitoring Activities
Correct answer: Event Identification
Event Identification within COSO ERM addresses the process of recognizing potential events that could affect the achievement of objectives, which aligns directly with risk identification assessment.
Question 2: An organization's risk appetite statement is vague and unmeasurable. Internal audit's BEST course of action is to:
- Rewrite the risk appetite statement on management's behalf
- Report it as a significant deficiency and recommend management develop measurable thresholds (Correct answer)
- Ignore it since risk appetite is outside audit's mandate
- Use external benchmarks to substitute for the missing thresholds
Correct answer: Report it as a significant deficiency and recommend management develop measurable thresholds
A vague risk appetite statement is a control deficiency that should be reported with a recommendation for management to develop measurable criteria; internal audit should not own that task.
Question 3: When communicating ERM assurance results to the board, internal audit should PRIMARILY:
- Present detailed findings on every individual risk reviewed
- Provide an overall opinion on the adequacy and effectiveness of ERM processes (Correct answer)
- Recommend specific risk mitigation strategies for each finding
- Disclose all consulting work performed during the same period
Correct answer: Provide an overall opinion on the adequacy and effectiveness of ERM processes
Board-level communication should convey a synthesized opinion on ERM effectiveness rather than granular transaction-level findings.
Question 4: Internal audit discovers that a critical risk has been accepted by management at a level exceeding board-approved risk appetite. The CORRECT action is to:
- Allow management to justify the exception and close the finding
- Escalate to the board or audit committee because this exceeds delegated authority (Correct answer)
- Reclassify the risk as within appetite to avoid escalation
- Report it in the next quarterly cycle to avoid disrupting operations
Correct answer: Escalate to the board or audit committee because this exceeds delegated authority
When risk acceptance exceeds board-approved appetite, the matter must be escalated to the board because management lacks authority to approve exceptions above that level.
Question 5: How does internal audit's assurance role differ from the risk management function's role?
- Internal audit designs risk responses while risk management monitors them
- Internal audit owns the risk register; risk management provides assurance over it
- Internal audit independently evaluates risk management; the risk management function operates and maintains ERM processes (Correct answer)
- Both functions share equal responsibility for ERM effectiveness
Correct answer: Internal audit independently evaluates risk management; the risk management function operates and maintains ERM processes
The risk management function (second line) operates and maintains ERM processes, while internal audit (third line) independently evaluates whether those processes are adequate and effective.
Question 6: An internal audit opinion that ERM is 'generally effective with minor exceptions' MOST appropriately means:
- All risks are within appetite and no action is required
- The overall framework is sound but specific gaps exist that management should address (Correct answer)
- External auditors have concurred with internal audit's assessment
- The organization has no material risk exposures
Correct answer: The overall framework is sound but specific gaps exist that management should address
'Generally effective with minor exceptions' indicates the ERM framework is fundamentally sound while acknowledging specific areas requiring management attention and remediation.
Question 7: Which factor is MOST critical when determining the frequency of internal audit's ERM assurance activities?
- The external auditor's audit cycle
- The rate of change in the organization's risk environment (Correct answer)
- The number of staff available in the internal audit department
- The frequency of audit committee meetings
Correct answer: The rate of change in the organization's risk environment
A rapidly changing risk environment necessitates more frequent ERM assurance to ensure the framework remains aligned with current threats and organizational objectives.
Which COSO ERM component is MOST directly evaluated when internal audit assesses whether the organization has correctly identified its key risks?