CRO Enterprise Risk Management & Governance 3 — Questions and Answers
Question 1: Which of the following best describes 'residual risk' in the context of enterprise risk management?
- The risk that remains after all possible mitigation strategies have been exhausted
- The risk remaining after management applies controls and risk responses (Correct answer)
- The difference between inherent risk and regulatory capital requirements
- Risk exposures that have not yet been identified by the ERM framework
Correct answer: The risk remaining after management applies controls and risk responses
Residual risk is the level of risk that remains after management has implemented controls and other risk responses to address inherent risk.
Question 2: A CRO discovers that a business unit's actual risk exposure consistently exceeds its approved risk limit. The most appropriate immediate action is to:
- Increase the risk limit to match actual exposures
- Require the business unit to reduce exposure or obtain board approval for a limit exception (Correct answer)
- Report the breach to regulators immediately
- Suspend business unit operations until compliance is achieved
Correct answer: Require the business unit to reduce exposure or obtain board approval for a limit exception
A risk limit breach requires either reducing exposure to within the approved limit or following a formal exception process that may include board escalation.
Question 3: Which ERM maturity model stage is characterized by risk management being consistently applied enterprise-wide with quantitative metrics and continuous improvement?
- Initial / Ad hoc
- Defined
- Managed and Measured
- Optimized (Correct answer)
Correct answer: Optimized
The Optimized stage represents the highest ERM maturity, where risk management is data-driven, continuously improved, and fully embedded across the enterprise.
Question 4: An organization's risk committee requires that all emerging risks be formally logged. The PRIMARY benefit of this practice is:
- Demonstrating regulatory compliance
- Enabling proactive identification and monitoring before risks materialize (Correct answer)
- Reducing the organization's insurance premiums
- Satisfying external auditor requirements
Correct answer: Enabling proactive identification and monitoring before risks materialize
Formally logging emerging risks enables proactive monitoring and response planning before those risks escalate into material losses.
Question 5: In ERM governance, 'risk culture' is most directly shaped by:
- The comprehensiveness of the risk register
- Leadership behavior, incentives, and accountability structures (Correct answer)
- The sophistication of risk modeling tools
- The frequency of risk committee meetings
Correct answer: Leadership behavior, incentives, and accountability structures
Risk culture is fundamentally driven by how leaders behave, what behaviors are rewarded, and how accountability for risk outcomes is assigned.
Question 6: Which risk treatment strategy is most appropriate when a risk's potential impact is catastrophic but its likelihood is extremely low?
- Accept the risk and monitor passively
- Transfer the risk through insurance or contractual means (Correct answer)
- Avoid the risk by eliminating the activity
- Reduce the risk through additional internal controls
Correct answer: Transfer the risk through insurance or contractual means
Transferring catastrophic low-frequency risks through insurance or contracts is typically the most cost-effective strategy, preserving capital while protecting against tail events.
Question 7: A CRO is designing the annual ERM reporting cycle. Which report should be delivered to the full board (not just the risk committee)?
- Detailed operational risk incident logs
- Enterprise risk profile and key risk trends summary (Correct answer)
- Business unit-level key risk indicator dashboards
- Internal audit findings by risk category
Correct answer: Enterprise risk profile and key risk trends summary
The full board requires an enterprise-level risk profile and trend summary to fulfill its governance oversight responsibility, while granular details are managed at committee level.
Which of the following best describes 'residual risk' in the context of enterprise risk management?