CRO Strategic Planning & Crisis Management 2 — Questions and Answers
Question 1: During a strategic risk assessment, a CRO discovers that a key competitor has launched a disruptive technology. Which response best reflects integrated strategic risk management?
- Immediately halt current strategic initiatives
- Incorporate the competitive threat into the risk-adjusted strategic plan and escalate to the board (Correct answer)
- Transfer the risk to the CFO for financial modeling
- Document the threat in the risk register and take no further action
Correct answer: Incorporate the competitive threat into the risk-adjusted strategic plan and escalate to the board
Integrated strategic risk management requires embedding emerging threats into the strategic plan and ensuring board-level visibility for appropriate response.
Question 2: A Chief Risk Officer is developing a crisis communication plan. Which element is most critical to include to maintain stakeholder confidence during a major operational crisis?
- A list of all internal employees by department
- Pre-approved message templates with designated spokespersons and escalation triggers (Correct answer)
- A comprehensive audit of historical incidents
- Detailed technical remediation procedures for IT staff
Correct answer: Pre-approved message templates with designated spokespersons and escalation triggers
Pre-approved templates with clear spokespersons and escalation triggers ensure consistent, timely communication that preserves stakeholder trust during crises.
Question 3: Which framework is most widely used to align enterprise risk management with an organization's overall strategic objectives?
- ISO 31000
- COSO ERM 2017 (Correct answer)
- Basel III
- NIST Cybersecurity Framework
Correct answer: COSO ERM 2017
COSO ERM 2017 explicitly integrates risk management with strategy setting and performance management at the enterprise level.
Question 4: A company's crisis management team is conducting a post-incident review after a supply chain disruption. What is the PRIMARY purpose of this review?
- Assign blame to responsible departments
- Identify lessons learned to improve future crisis response plans (Correct answer)
- Satisfy regulatory reporting requirements
- Calculate insurance claim amounts
Correct answer: Identify lessons learned to improve future crisis response plans
Post-incident reviews are fundamentally about capturing lessons learned to strengthen crisis preparedness and response for future events.
Question 5: In strategic risk planning, what does 'risk appetite articulation' primarily help an organization accomplish?
- Eliminate all identified risks from the risk register
- Define the boundaries within which management may pursue strategic objectives (Correct answer)
- Determine the annual insurance premium budget
- Establish the organizational chart for the risk department
Correct answer: Define the boundaries within which management may pursue strategic objectives
Risk appetite articulation sets the boundaries of acceptable risk-taking, guiding management decisions when pursuing strategic goals.
Question 6: A CRO must present a scenario analysis to the board covering a potential economic recession. Which approach best demonstrates the value of scenario planning in strategic risk management?
- Present only the worst-case scenario to maximize board attention
- Model multiple plausible scenarios with associated strategic responses and triggers (Correct answer)
- Use historical data exclusively to project future outcomes
- Limit analysis to risks already reflected in the annual budget
Correct answer: Model multiple plausible scenarios with associated strategic responses and triggers
Effective scenario analysis presents multiple plausible futures with pre-defined strategic responses, enabling proactive rather than reactive decision-making.
Question 7: Which concept describes the maximum tolerable downtime for a critical business process before the organization suffers unacceptable consequences during a crisis?
- Recovery Point Objective (RPO)
- Recovery Time Objective (RTO)
- Maximum Tolerable Period of Disruption (MTPD) (Correct answer)
- Business Impact Analysis (BIA)
Correct answer: Maximum Tolerable Period of Disruption (MTPD)
The Maximum Tolerable Period of Disruption (MTPD) defines the longest duration a critical process can be unavailable before unacceptable harm results.
During a strategic risk assessment, a CRO discovers that a key competitor has launched a disruptive technology.
Which response best reflects integrated strategic risk management?