CRMA Knowledge 2 — Questions and Answers
Question 1: The COSO ERM 2017 framework organizes its components into how many categories?
- Three
- Four
- Five (Correct answer)
- Six
Correct answer: Five
COSO ERM 2017 organizes its 20 principles into five interrelated components: Governance and Culture, Strategy and Objective-Setting, Performance, Review and Revision, and Information, Communication, and Reporting.
Question 2: Which statement best distinguishes risk appetite from risk tolerance?
- Risk appetite is a precise metric; risk tolerance is a broad philosophy.
- Risk appetite is the broad amount of risk accepted in pursuit of objectives; risk tolerance is the acceptable variation around those objectives. (Correct answer)
- Risk tolerance applies to strategic risks; risk appetite applies only to operational risks.
- Risk appetite and risk tolerance are interchangeable terms in ERM.
Correct answer: Risk appetite is the broad amount of risk accepted in pursuit of objectives; risk tolerance is the acceptable variation around those objectives.
Risk appetite expresses the overall amount of risk an organization is willing to accept, while risk tolerance defines the acceptable deviation from that appetite for specific objectives.
Question 3: ISO 31000:2018 defines risk as:
- The probability of a negative event multiplied by its financial impact.
- The effect of uncertainty on objectives. (Correct answer)
- Any event that could cause a loss greater than the risk threshold.
- The deviation of actual outcomes from expected results.
Correct answer: The effect of uncertainty on objectives.
ISO 31000:2018 defines risk as 'the effect of uncertainty on objectives,' recognizing that effects can be positive or negative.
Question 4: Which body holds primary responsibility for risk oversight in a well-governed organization?
- Chief Risk Officer
- Internal Audit
- Board of Directors (Correct answer)
- External Auditors
Correct answer: Board of Directors
The Board of Directors holds ultimate accountability for risk oversight, setting risk appetite and ensuring management has appropriate ERM processes in place.
Question 5: Inherent risk differs from residual risk in that inherent risk is measured:
- After applying all mitigating controls.
- Before any controls or mitigating actions are applied. (Correct answer)
- Only for financial and compliance risk categories.
- By the Chief Risk Officer rather than management.
Correct answer: Before any controls or mitigating actions are applied.
Inherent risk is the level of risk that exists before any controls are applied, while residual risk is what remains after controls are in place.
Question 6: A 'risk universe' in ERM context refers to:
- The total financial exposure an organization can absorb.
- A comprehensive inventory of all risks that could affect the organization's objectives. (Correct answer)
- The set of risks exceeding the board-approved risk appetite.
- Risks identified only through external environmental scanning.
Correct answer: A comprehensive inventory of all risks that could affect the organization's objectives.
The risk universe is the complete catalogue of potential risks across all categories that could impact an organization's ability to achieve its objectives.
Question 7: Under the COSO ERM framework, 'risk capacity' represents:
- The maximum risk an organization can absorb before threatening its viability. (Correct answer)
- The same concept as risk appetite.
- The number of risk categories the risk management team can monitor.
- The financial reserves set aside for unexpected losses.
Correct answer: The maximum risk an organization can absorb before threatening its viability.
Risk capacity is the maximum amount of risk an entity can bear given its current resources, capabilities, and constraints without jeopardizing its existence.
The COSO ERM 2017 framework organizes its components into how many categories?