Risk Assessment and Identification Techniques Flashcards
7 cards from real GRC practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Assessment and Identification Techniques flashcards as text
Which tool is most commonly used to document and track identified risks, their likelihood, potential impact, and assigned owners within an organization?
Answer: Risk register
A risk register is the primary GRC artifact for cataloging risks along with their attributes such as likelihood, impact, owner, and mitigation status.
A risk heat map that plots risks by likelihood on one axis and impact on the other is also known as a:
Answer: Risk matrix
A risk matrix (heat map) uses a two-axis grid of likelihood and impact to visually prioritize risks by their severity.
What is the primary difference between qualitative and quantitative risk assessment?
Answer: Qualitative uses descriptive rankings; quantitative uses numerical values and statistical methods
Qualitative assessments categorize risks using descriptive scales (high/medium/low), while quantitative assessments assign numerical probabilities and financial impact figures.
In GRC, what does 'inherent risk' refer to?
Answer: The risk that exists before any controls or mitigating actions are implemented
Inherent risk is the level of risk in the absence of any controls or mitigating measures, representing the raw exposure.
Which risk identification technique involves gathering input from a panel of experts through multiple anonymous rounds of questionnaires to reach consensus?
Answer: Delphi technique
The Delphi technique uses iterative, anonymous expert surveys to converge on a consensus view of risk likelihood and impact.
What is the relationship between risk appetite and risk tolerance in GRC?
Answer: Risk appetite is the broad level of risk accepted; risk tolerance is the acceptable variance around that level
Risk appetite sets the overall amount of risk an organization is willing to accept, while risk tolerance defines the acceptable variation or deviation within that appetite.
A bow-tie analysis in risk management is best described as:
Answer: A diagram connecting risk causes on the left to consequences on the right with the hazard/risk event at the center
A bow-tie diagram visually represents threat causes (left side), the central risk event, preventive controls, and consequence mitigation controls (right side).