CRMA Risk Management Governance 3 — Questions and Answers
Question 1: Which of the following best distinguishes risk appetite from risk tolerance in an ERM governance context?
- Risk appetite is operational; risk tolerance is strategic
- Risk appetite is the amount of risk desired to pursue strategy; risk tolerance is the acceptable variance around that level (Correct answer)
- Risk appetite is set by regulators; risk tolerance is set by the board
- Risk appetite applies only to financial risks; risk tolerance applies to all risk categories
Correct answer: Risk appetite is the amount of risk desired to pursue strategy; risk tolerance is the acceptable variance around that level
Risk appetite expresses the desired risk level aligned with strategy, while risk tolerance defines the acceptable band of deviation from that appetite.
Question 2: What is the primary indicator of a strong risk culture within an organization?
- A large risk management department headcount
- Employees at all levels proactively identify and escalate risks without fear of reprisal (Correct answer)
- Zero reported risk events in the past fiscal year
- The board meets with the CRO at least once per year
Correct answer: Employees at all levels proactively identify and escalate risks without fear of reprisal
A strong risk culture is evidenced by voluntary, fearless risk identification and escalation at every organizational level.
Question 3: The concept of 'tone at the top' in risk governance primarily refers to:
- The decibel level of board discussions about risk
- Senior leadership modeling risk-aware behavior and reinforcing accountability (Correct answer)
- The CRO's authority to override business unit decisions
- Regulatory guidance issued at the federal level
Correct answer: Senior leadership modeling risk-aware behavior and reinforcing accountability
Tone at the top means that senior leaders visibly demonstrate and reinforce a risk-aware culture through their own behavior and decisions.
Question 4: Risk capacity differs from risk appetite in that risk capacity represents:
- The board's preferred level of risk-taking
- The maximum risk an organization can absorb before threatening its survival (Correct answer)
- The variance allowed around the approved risk appetite
- The number of risk categories tracked in the risk register
Correct answer: The maximum risk an organization can absorb before threatening its survival
Risk capacity is the absolute maximum level of risk the organization can bear, above which its viability is threatened.
Question 5: When business unit managers are designated as 'risk owners,' this governance practice primarily ensures:
- Internal audit can delegate testing responsibilities to management
- Accountability for identifying, monitoring, and responding to specific risks rests with those closest to them (Correct answer)
- The Risk Committee can reduce its meeting frequency
- Legal liability for risk events transfers to individual employees
Correct answer: Accountability for identifying, monitoring, and responding to specific risks rests with those closest to them
Designating risk owners places accountability with those who have the most direct knowledge of and control over specific risks.
Question 6: A Risk Appetite Statement should be reviewed and approved by:
- The internal audit function annually
- The Chief Risk Officer without board involvement
- The board of directors, typically at least annually (Correct answer)
- Business unit heads collectively through a consensus vote
Correct answer: The board of directors, typically at least annually
The Risk Appetite Statement requires board approval because it reflects the organization's strategic risk posture and is a governance-level decision.
Question 7: Which scenario best illustrates a 'risk culture misalignment' problem?
- The board reviews risk reports quarterly instead of monthly
- Sales staff are incentivized to take risks that exceed the approved risk appetite to hit revenue targets (Correct answer)
- The CRO reports to both the CEO and the board simultaneously
- The risk register is stored in a spreadsheet rather than a GRC system
Correct answer: Sales staff are incentivized to take risks that exceed the approved risk appetite to hit revenue targets
Incentive structures that reward exceeding risk appetite directly undermine governance and signal a cultural misalignment between stated risk policy and actual behavior.
Which of the following best distinguishes risk appetite from risk tolerance in an ERM governance context?