CSC Risk Management & Quality Assurance 2 — Questions and Answers
Question 1: A senior consultant discovers mid-project that a key vendor may be acquired, threatening delivery timelines. Which risk response strategy is MOST appropriate?
- Accept the risk and document it in the risk register
- Transfer the risk by requiring the vendor to post a performance bond
- Develop a contingency plan with an alternate vendor while negotiating contract protections (Correct answer)
- Avoid the risk by immediately terminating the vendor contract
Correct answer: Develop a contingency plan with an alternate vendor while negotiating contract protections
Developing a contingency plan with an alternate vendor combines mitigation and contingency response, addressing the risk without prematurely disrupting delivery.
Question 2: In a quality management context, what does 'cost of poor quality' (COPQ) primarily include?
- Costs of prevention activities and quality training
- Internal failure costs, external failure costs, and lost business opportunity costs (Correct answer)
- Inspection and testing costs only
- Costs associated with hiring quality assurance personnel
Correct answer: Internal failure costs, external failure costs, and lost business opportunity costs
COPQ encompasses internal failures (rework, scrap), external failures (warranty, recalls), and lost business due to poor reputation.
Question 3: Which quantitative risk analysis technique uses repeated simulations to model the range of possible project outcomes?
- SWOT Analysis
- Monte Carlo Simulation (Correct answer)
- Delphi Technique
- Failure Mode and Effects Analysis (FMEA)
Correct answer: Monte Carlo Simulation
Monte Carlo Simulation runs thousands of iterations with varying inputs to produce a probability distribution of possible outcomes.
Question 4: A client's quality audit reveals that defect rates have increased despite a new inspection process. What should the senior consultant investigate first?
- Whether the inspection criteria are too stringent
- Whether the root causes of defects were addressed or only detection was improved (Correct answer)
- Whether the quality team needs additional headcount
- Whether competitor products have similar defect rates
Correct answer: Whether the root causes of defects were addressed or only detection was improved
Improved detection without root cause elimination will expose more defects but not reduce their occurrence.
Question 5: What is the primary purpose of a Risk Breakdown Structure (RBS) in senior consulting engagements?
- To assign dollar values to each identified risk
- To hierarchically organize risks by category for systematic identification and tracking (Correct answer)
- To rank risks by their probability scores
- To document the risk owner for each identified threat
Correct answer: To hierarchically organize risks by category for systematic identification and tracking
An RBS organizes risks into hierarchical categories (technical, external, organizational) to ensure comprehensive identification and structured management.
Question 6: During a consulting engagement, a risk that was rated 'low probability, high impact' suddenly becomes likely. What is the consultant's immediate obligation?
- Archive the original risk assessment and start a new one
- Escalate to the risk register owner and re-evaluate the risk's priority score (Correct answer)
- Implement the contingency plan without stakeholder notification
- Close the risk and document it as an issue instead
Correct answer: Escalate to the risk register owner and re-evaluate the risk's priority score
When a risk's probability changes materially, it must be re-evaluated and re-prioritized, and relevant stakeholders must be informed.
Question 7: Which quality philosophy emphasizes that quality must be designed into a product or process rather than inspected in after the fact?
- Six Sigma DMAIC model
- Zero Defects philosophy
- Quality by Design (QbD) (Correct answer)
- Total Quality Management (TQM)
Correct answer: Quality by Design (QbD)
Quality by Design (QbD) holds that quality should be built into the process from inception, not verified through end-stage inspection.
A senior consultant discovers mid-project that a key vendor may be acquired, threatening delivery timelines.
Which risk response strategy is MOST appropriate?