CRMA Risk Response and Treatment 2 — Questions and Answers
Question 1: What is the key distinction between inherent risk and residual risk?
- Inherent risk exists before controls; residual risk exists after controls are applied (Correct answer)
- Inherent risk is quantifiable; residual risk cannot be measured
- Inherent risk relates to internal factors; residual risk relates to external factors
- Inherent risk is strategic; residual risk is operational
Correct answer: Inherent risk exists before controls; residual risk exists after controls are applied
Inherent risk is the raw risk before any controls or responses, while residual risk is the remaining exposure after management applies its risk responses.
Question 2: Insurance is primarily an example of which risk response strategy?
- Risk avoidance
- Risk reduction
- Risk transfer (Correct answer)
- Risk acceptance
Correct answer: Risk transfer
Insurance transfers the financial consequences of a risk to an insurer in exchange for a premium, making it a classic example of risk transfer.
Question 3: In the context of CRMA, what is a 'control' in risk response?
- A policy that prevents employees from taking risks
- Any action, policy, or procedure that reduces the likelihood or impact of a risk (Correct answer)
- A financial reserve set aside to cover potential losses
- A regulatory requirement imposed by external authorities
Correct answer: Any action, policy, or procedure that reduces the likelihood or impact of a risk
A control is any action, policy, or procedure implemented by management to reduce the likelihood or impact of a risk event, supporting the risk response strategy.
Question 4: Which risk response approach is MOST appropriate for a low-likelihood, low-impact risk?
- Risk avoidance
- Risk transfer
- Risk acceptance (Correct answer)
- Risk reduction through multiple controls
Correct answer: Risk acceptance
Low-likelihood, low-impact risks typically fall within risk tolerance, making acceptance the most cost-effective and practical response.
Question 5: What is the primary role of internal audit in evaluating an organization's risk responses?
- Designing and implementing the risk responses on behalf of management
- Providing independent assurance that risk responses are effective and aligned with risk appetite (Correct answer)
- Approving management's risk response strategies before implementation
- Eliminating residual risk through audit recommendations
Correct answer: Providing independent assurance that risk responses are effective and aligned with risk appetite
Internal audit's assurance role includes independently evaluating whether risk responses are operating effectively and whether residual risk aligns with the organization's risk appetite.
Question 6: Risk response plans should include which of the following elements?
- Assigned ownership, timeline, specific actions, and metrics to measure effectiveness (Correct answer)
- Only the risk rating and the strategy chosen (avoid/reduce/transfer/accept)
- A list of all risks identified in the most recent risk assessment
- The external auditor's review and sign-off on each planned action
Correct answer: Assigned ownership, timeline, specific actions, and metrics to measure effectiveness
Effective risk response plans include clear ownership, timelines, specific actions to be taken, and metrics or indicators to monitor whether the response is working.
Question 7: An organization decides to outsource its IT infrastructure management to reduce cybersecurity risk exposure. This is an example of:
- Risk avoidance
- Risk acceptance
- Risk transfer (Correct answer)
- Risk reduction
Correct answer: Risk transfer
Outsourcing IT management shifts cybersecurity risk to a third-party vendor, which is a form of risk transfer even if some residual risk remains with the organization.
What is the key distinction between inherent risk and residual risk?