CRO Enterprise Risk Management & Governance 2 — Questions and Answers
Question 1: Under the COSO ERM framework, which component ensures that risk responses are embedded into day-to-day operational processes?
- Risk Assessment
- Control Activities (Correct answer)
- Information & Communication
- Monitoring Activities
Correct answer: Control Activities
Control Activities are the policies and procedures that help ensure risk responses are effectively carried out throughout the organization.
Question 2: A company's board of directors delegates risk oversight to a dedicated committee. Which governance principle does this best illustrate?
- Risk aggregation
- Tone at the top
- Three lines of defense
- Board-level risk committee oversight (Correct answer)
Correct answer: Board-level risk committee oversight
Establishing a dedicated board-level risk committee provides focused oversight of the enterprise risk management program, a recognized governance best practice.
Question 3: In ERM, 'risk appetite' differs from 'risk tolerance' primarily because:
- Risk appetite is quantitative while risk tolerance is qualitative
- Risk appetite is the broad desired level of risk while tolerance defines acceptable variation from that level (Correct answer)
- Risk tolerance applies only to financial risks while appetite covers all risks
- Risk appetite is set by regulators while tolerance is set by management
Correct answer: Risk appetite is the broad desired level of risk while tolerance defines acceptable variation from that level
Risk appetite is the overall desired risk-taking posture, while risk tolerance defines the acceptable variance or boundaries around that appetite.
Question 4: Which ERM approach is best suited when a firm faces a risk where both frequency and severity are highly uncertain?
- Expected loss modeling
- Scenario analysis (Correct answer)
- Key risk indicators
- Control self-assessment
Correct answer: Scenario analysis
Scenario analysis is most effective for risks with highly uncertain frequency and severity because it explores plausible future states rather than relying on historical data.
Question 5: A CRO is asked to present the risk profile to the board. Which format most effectively communicates aggregate enterprise risk?
- Individual risk register entries
- Departmental audit reports
- An enterprise risk heat map with trend indicators (Correct answer)
- A list of key risk indicators by business unit
Correct answer: An enterprise risk heat map with trend indicators
An enterprise risk heat map with trend indicators provides the board a consolidated view of risk likelihood, impact, and directional movement across the organization.
Question 6: The 'second line of defense' in the three-lines-of-defense model is best represented by:
- Internal audit functions
- Front-line business managers
- Risk management and compliance functions (Correct answer)
- External regulators and auditors
Correct answer: Risk management and compliance functions
The second line consists of risk management and compliance functions that provide oversight, policies, and challenge to the first line's risk-taking activities.
Question 7: When setting risk limits for a strategic business initiative, which factor should the CRO weight most heavily?
- Historical loss data from comparable initiatives
- Alignment of risk limits with the board-approved risk appetite statement (Correct answer)
- Benchmark limits used by industry peers
- The initiative's projected return on equity
Correct answer: Alignment of risk limits with the board-approved risk appetite statement
Risk limits must be anchored to the board-approved risk appetite statement to ensure strategic alignment and governance consistency.
Under the COSO ERM framework, which component ensures that risk responses are embedded into day-to-day operational processes?