← All GRC Flashcard Decks

Enterprise Risk Management Frameworks Flashcards

7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Enterprise Risk Management Frameworks flashcards as text
  1. A bowtie diagram in risk management is used to visualize:

    Answer: Causes (threats) on the left and consequences on the right, with the risk event at the center

    A bowtie diagram places the risk event at the center, with threat pathways on the left side and consequence pathways on the right, along with barriers.

  2. Which of the following statements about risk tolerance vs. risk appetite is MOST accurate?

    Answer: Risk appetite is broader and strategic; risk tolerance is the specific acceptable variation around that appetite

    Risk appetite expresses the overall level of risk an organization accepts in pursuit of value; risk tolerance specifies acceptable deviations from objectives within that appetite.

  3. In ERM, what does 'emerging risk' refer to?

    Answer: A newly identified or evolving risk that is not yet fully understood or quantified

    Emerging risks are novel or evolving threats — such as new technologies or geopolitical shifts — that have uncertain characteristics and require monitoring.

  4. Which of the following is an example of a 'risk treatment' option under ISO 31000:2018?

    Answer: Taking out an insurance policy to transfer risk

    ISO 31000 defines risk treatment as the process of selecting and implementing options to modify risk, including transferring it through insurance.

  5. A risk committee is reviewing a strategic risk that has a low probability but catastrophic potential impact. Which concept best justifies prioritizing this risk despite its low likelihood?

    Answer: Black swan theory

    Black swan theory, developed by Nassim Taleb, emphasizes that rare, extreme-impact events warrant special attention even when their probability appears negligible.

  6. Which COSO ERM principle states that organizations should develop a 'portfolio view' of risk?

    Answer: Develops Portfolio View

    The 'Develops Portfolio View' principle requires management to aggregate risks across business units to understand the total risk profile relative to appetite.

  7. An organization's ERM program is described as 'ad hoc and reactive' with no formal processes. At which maturity level would this program be classified under a standard ERM maturity model?

    Answer: Initial

    The Initial (or Ad Hoc) maturity level describes organizations where risk management is informal, reactive, and not systematically applied.