CRMA Risk Management Frameworks 3 — Questions and Answers
Question 1: ISO 31000:2018 defines risk as:
- The probability of a negative event occurring
- The effect of uncertainty on objectives (Correct answer)
- A threat that may cause financial loss
- The likelihood of an adverse outcome multiplied by its impact
Correct answer: The effect of uncertainty on objectives
ISO 31000:2018 defines risk as 'the effect of uncertainty on objectives,' which encompasses both negative and positive effects.
Question 2: Which statement best describes a key structural difference between ISO 31000 and COSO ERM?
- ISO 31000 is mandatory for public companies; COSO ERM is voluntary
- ISO 31000 is a principles-based guidance document; COSO ERM provides a more detailed component-and-principle structure (Correct answer)
- COSO ERM applies only to financial risks; ISO 31000 covers all risk types
- ISO 31000 requires external certification; COSO ERM does not
Correct answer: ISO 31000 is a principles-based guidance document; COSO ERM provides a more detailed component-and-principle structure
ISO 31000 is a high-level principles-based guide applicable to any organization, while COSO ERM provides a more structured component-and-principle architecture primarily oriented toward enterprise-level governance.
Question 3: ISO 31000:2018 identifies which of the following as the first step in the risk management process?
- Risk assessment
- Communication and consultation
- Risk treatment
- Scope, context, and criteria establishment (Correct answer)
Correct answer: Scope, context, and criteria establishment
Establishing the scope, context, and criteria is the first step in the ISO 31000 risk management process, providing the basis for all subsequent steps.
Question 4: The NIST Risk Management Framework (RMF) was originally developed primarily for which sector?
- Financial services
- Healthcare
- Federal information systems (Correct answer)
- Insurance
Correct answer: Federal information systems
NIST RMF was developed by the National Institute of Standards and Technology to manage cybersecurity and privacy risk in U.S. federal information systems.
Question 5: A risk maturity model typically measures an organization's ERM capabilities across how many levels?
- Three
- Four
- Five (Correct answer)
- Seven
Correct answer: Five
Most risk maturity models (such as RIMS Risk Maturity Model) use five levels ranging from ad hoc/initial to optimized/advanced.
Question 6: Under the Basel II/III operational risk framework, the Advanced Measurement Approach (AMA) required banks to use:
- A standardized percentage of gross income
- A regulatory-set fixed capital charge
- Their own internal models validated by regulators (Correct answer)
- External loss data only
Correct answer: Their own internal models validated by regulators
The AMA allowed banks to use their own quantitative models for operational risk capital calculation, subject to regulatory approval and validation.
Question 7: Which ISO 31000 principle states that risk management should be tailored to the organization's context and objectives?
- Integrated
- Customized (Correct answer)
- Inclusive
- Dynamic
Correct answer: Customized
The 'Customized' principle in ISO 31000:2018 states that the risk management framework and process should be tailored and proportionate to the organization's context.
ISO 31000:2018 defines risk as: