CSPT Risk Management & Assessment — Questions and Answers
Question 1: What is the first step in the risk management process?
- Risk identification — recognizing potential threats and vulnerabilities (Correct answer)
- Risk transfer — purchasing insurance immediately
- Risk acceptance — deciding to live with all risks
- Risk avoidance — canceling all activities
Correct answer: Risk identification — recognizing potential threats and vulnerabilities
Risk identification is the critical first step in risk management, involving systematic recognition and documentation of potential threats and vulnerabilities.
Question 2: What does a risk matrix assess?
- The probability and impact of identified risks (Correct answer)
- Only the financial cost of risks
- The number of employees affected
- The timeline for risk resolution
Correct answer: The probability and impact of identified risks
A risk matrix evaluates risks based on two dimensions: the probability (likelihood) of occurrence and the potential impact (severity) if the risk materializes.
Question 3: Which risk response strategy involves reducing the likelihood or impact of a risk?
- Risk mitigation (Correct answer)
- Risk acceptance
- Risk transfer
- Risk escalation
Correct answer: Risk mitigation
Risk mitigation involves taking proactive steps to reduce either the probability of a risk occurring or its potential impact if it does occur.
Question 4: What is the purpose of a risk register?
- To document, track, and manage all identified risks throughout a project or operation (Correct answer)
- To eliminate all risks before starting work
- To assign blame when problems occur
- To satisfy audit requirements only
Correct answer: To document, track, and manage all identified risks throughout a project or operation
A risk register is a living document that records all identified risks, their assessments, response plans, and status updates throughout the lifecycle of a project or operation.
Question 5: What distinguishes inherent risk from residual risk?
- Inherent risk exists before controls; residual risk remains after controls are applied (Correct answer)
- Inherent risk is financial; residual risk is operational
- Inherent risk is internal; residual risk is external
- There is no meaningful difference between them
Correct answer: Inherent risk exists before controls; residual risk remains after controls are applied
Inherent risk is the level of risk present before any controls are implemented, while residual risk is the level that remains after controls and mitigations are applied.
Question 6: Why is regular risk reassessment important?
- Because the risk landscape changes as conditions, activities, and environments evolve (Correct answer)
- Because regulators require it exactly once per year
- Because it provides work for risk management teams
- Because initial assessments are always wrong
Correct answer: Because the risk landscape changes as conditions, activities, and environments evolve
Regular risk reassessment is essential because risks are dynamic — new threats emerge, existing risks change in severity, and the effectiveness of controls may vary over time.
What is the first step in the risk management process?