CRMA Risk Identification and Analysis 3 — Questions and Answers
Question 1: Which qualitative risk analysis tool uses predefined scales for both likelihood and impact to rank risks for prioritization?
- Decision tree analysis
- Risk probability and impact matrix (Correct answer)
- Sensitivity analysis
- Expected monetary value analysis
Correct answer: Risk probability and impact matrix
The probability and impact matrix (risk matrix) combines qualitative scales to classify risks as high, medium, or low priority.
Question 2: In the context of CRMA, 'inherent risk' is best defined as:
- The risk remaining after all controls are applied
- The risk level that exists before any mitigating controls are in place (Correct answer)
- Risk that is embedded in the organization's culture
- The risk accepted by the board of directors
Correct answer: The risk level that exists before any mitigating controls are in place
Inherent risk is the exposure an organization faces in the absence of any actions taken to alter the risk's likelihood or impact.
Question 3: An internal auditor conducts interviews with process owners to identify risks. Which risk identification technique is being used?
- Checklists
- Facilitated risk workshops
- Subject matter expert inquiry (Correct answer)
- Environmental scanning
Correct answer: Subject matter expert inquiry
Interviewing subject matter experts or process owners is a direct inquiry technique for eliciting risk information from knowledgeable individuals.
Question 4: A technology company faces the risk that a competitor could launch a superior product within 12 months. Which risk category does this most likely represent?
- Operational risk
- Strategic risk (Correct answer)
- Compliance risk
- Financial risk
Correct answer: Strategic risk
Competitive threats that affect an organization's strategic position and market share are classified as strategic risks.
Question 5: Which statement about risk workshops is MOST accurate?
- They should be limited to senior executives to ensure strategic relevance
- They are most effective when facilitated by an independent party to reduce groupthink (Correct answer)
- They replace the need for quantitative risk analysis
- They should only be conducted annually per IIA standards
Correct answer: They are most effective when facilitated by an independent party to reduce groupthink
Independent facilitation reduces bias and groupthink, producing more comprehensive and honest risk identification outcomes.
Question 6: The PESTEL framework is used in risk identification primarily to assess risks arising from:
- Internal process failures and control gaps
- External macro-environmental factors affecting the organization (Correct answer)
- Project-level schedule and cost overruns
- Cybersecurity vulnerabilities in IT infrastructure
Correct answer: External macro-environmental factors affecting the organization
PESTEL (Political, Economic, Social, Technological, Environmental, Legal) analyzes external macro-environmental forces that create organizational risks.
Question 7: When a risk is described as having 'low likelihood but high impact,' which quadrant of a standard risk matrix does it occupy?
- High priority requiring immediate mitigation
- Monitor only with no action required
- Significant risk requiring contingency planning (Correct answer)
- Acceptable risk within normal tolerance
Correct answer: Significant risk requiring contingency planning
Low likelihood/high impact risks are significant enough to require contingency or response planning despite their infrequent occurrence.
Which qualitative risk analysis tool uses predefined scales for both likelihood and impact to rank risks for prioritization?