CSM Risk Management & Corporate Governance 3 — Questions and Answers
Question 1: The Three Lines of Defense model assigns risk ownership in the first line to which group?
- Internal audit function
- Risk management and compliance departments
- Business operations and management (Correct answer)
- External regulators and auditors
Correct answer: Business operations and management
In the Three Lines of Defense model, the first line consists of business operations and management who own and manage risks day-to-day.
Question 2: Which of the following BEST describes a 'black swan' event in the context of strategic risk management?
- A predictable risk with high financial impact
- A routine operational failure
- A rare, high-impact event that was difficult to predict beforehand (Correct answer)
- A risk that only affects the financial services industry
Correct answer: A rare, high-impact event that was difficult to predict beforehand
A black swan event is characterized by its extreme rarity, severe impact, and the tendency for people to rationalize it as predictable only after the fact.
Question 3: Stakeholder theory in corporate governance argues that corporations should create value for which group?
- Shareholders only
- Senior management and board members
- All parties with a stake in the company's activities (Correct answer)
- Government regulators exclusively
Correct answer: All parties with a stake in the company's activities
Stakeholder theory holds that corporations must consider and balance the interests of all stakeholders, including employees, customers, suppliers, and communities.
Question 4: A company with strong corporate governance is LEAST likely to exhibit which characteristic?
- Transparent financial disclosures
- Independent board members
- Concentrated decision-making power in one executive (Correct answer)
- Regular shareholder voting rights
Correct answer: Concentrated decision-making power in one executive
Good governance distributes power through checks and balances; concentrating authority in a single individual is a governance red flag.
Question 5: What does 'residual risk' refer to in enterprise risk management?
- Risks that have already materialized
- The level of risk remaining after controls are applied (Correct answer)
- Risks transferred to third parties
- The maximum possible loss from a single event
Correct answer: The level of risk remaining after controls are applied
Residual risk is the risk exposure that remains after implementing risk controls and mitigation measures.
Question 6: Which scenario BEST illustrates a reputational risk for a publicly traded corporation?
- A temporary 2% decline in quarterly revenue
- A data breach exposing customer personal information (Correct answer)
- An increase in raw material costs
- A minor delay in product delivery
Correct answer: A data breach exposing customer personal information
A data breach damages customer trust and public perception, which can have long-lasting effects on brand value and stakeholder relationships.
Question 7: In the context of board governance, 'say on pay' refers to which shareholder right?
- The right to set minimum wage for employees
- An advisory vote on executive compensation packages (Correct answer)
- The ability to freeze executive salaries during losses
- A binding vote to reject CEO bonuses
Correct answer: An advisory vote on executive compensation packages
'Say on pay' gives shareholders an advisory (typically non-binding) vote to express approval or disapproval of executive compensation practices.
The Three Lines of Defense model assigns risk ownership in the first line to which group?