CRMA Risk Management Frameworks 2 — Questions and Answers
Question 1: The COSO ERM 2017 framework is organized around how many interrelated components?
- Three
- Five (Correct answer)
- Seven
- Nine
Correct answer: Five
COSO ERM 2017 contains five interrelated components: Governance & Culture, Strategy & Objective-Setting, Performance, Review & Revision, and Information, Communication & Reporting.
Question 2: Which COSO ERM 2017 component specifically addresses how an organization defines its risk appetite in the context of business strategy?
- Governance & Culture
- Strategy & Objective-Setting (Correct answer)
- Review & Revision
- Performance
Correct answer: Strategy & Objective-Setting
The Strategy & Objective-Setting component is where the organization links risk appetite to strategy and articulates business objectives.
Question 3: How does COSO ERM 2017 differ most significantly from the original COSO ERM 2004 framework?
- It removes the internal environment component
- It explicitly integrates ERM with strategy and performance (Correct answer)
- It reduces the number of risk categories from eight to five
- It focuses exclusively on financial reporting risk
Correct answer: It explicitly integrates ERM with strategy and performance
The 2017 update explicitly linked enterprise risk management to strategy-setting and performance, reflecting that ERM is not just a compliance exercise.
Question 4: Under the COSO ERM 2017 'Performance' component, which activity involves identifying the severity of risks relative to risk appetite?
- Risk governance
- Risk prioritization (Correct answer)
- Risk communication
- Risk financing
Correct answer: Risk prioritization
Risk prioritization within the Performance component involves assessing the severity of identified risks and ranking them relative to the organization's risk appetite.
Question 5: In COSO ERM 2017, the 'Information, Communication & Reporting' component primarily supports which activity?
- Setting strategic objectives
- Identifying inherent risk
- Enabling informed risk decisions across the organization (Correct answer)
- Establishing board-level risk committees
Correct answer: Enabling informed risk decisions across the organization
This component ensures that relevant, quality information about risk is communicated throughout the organization to support decision-making at all levels.
Question 6: Which principle belongs to the 'Governance & Culture' component of COSO ERM 2017?
- Identifies risk
- Assesses severity of risk
- Defines desired culture (Correct answer)
- Develops portfolio view
Correct answer: Defines desired culture
Defining desired culture is one of the five principles within the Governance & Culture component, reflecting the board and management's tone at the top.
Question 7: The COSO ERM 2017 'Review & Revision' component is most analogous to which phase of a standard management cycle?
- Plan
- Do
- Check and Act (Correct answer)
- Define
Correct answer: Check and Act
Review & Revision corresponds to the Check and Act phases of the Plan-Do-Check-Act cycle, where management evaluates ERM performance and makes improvements.
The COSO ERM 2017 framework is organized around how many interrelated components?