Risk Assessment and Identification Techniques Flashcards
7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Assessment and Identification Techniques flashcards as text
Which analytical framework examines Political, Economic, Social, Technological, Legal, and Environmental factors to identify external risks?
Answer: PESTLE analysis
PESTLE analysis scans the external macro-environment across six categories to surface strategic and operational risks beyond the organization's control.
In quantitative risk assessment, Monte Carlo simulation is used to:
Answer: Run thousands of random scenarios to model the probability distribution of potential outcomes
Monte Carlo simulation repeatedly samples random values for uncertain variables to produce a statistical distribution of possible risk outcomes and their probabilities.
What is the definition of 'residual risk' in a GRC context?
Answer: The portion of risk that remains after controls and mitigation measures have been applied
Residual risk is the remaining level of risk exposure after the organization has implemented its chosen controls and mitigation actions.
Key Risk Indicators (KRIs) are best described as:
Answer: Leading metrics that provide early warning signals that a risk may be increasing
KRIs are forward-looking metrics that signal a rising probability of a risk materializing, enabling proactive management before the event occurs.
Fault tree analysis (FTA) is a risk assessment technique that:
Answer: Uses a top-down, deductive logic diagram to trace causes leading to an undesired top event
FTA starts with an undesired outcome at the top and deductively maps the combinations of failures or faults that could cause it using AND/OR logic gates.
Scenario analysis in GRC is primarily used to:
Answer: Evaluate the potential impact of specific hypothetical risk events on the organization
Scenario analysis assesses how plausible future events (e.g., a major data breach or supply chain disruption) could affect the organization, supporting strategic risk planning.
In risk assessment, Expected Monetary Value (EMV) is calculated as:
Answer: Probability of risk occurrence multiplied by the financial impact of the risk
EMV = Probability × Impact, providing a single financial figure that represents the weighted average expected loss from a risk event.