GRC Enterprise Risk Management Frameworks 3 — Questions and Answers
Question 1: Which of the following best describes a 'Key Risk Indicator' (KRI) in ERM?
- A measure of past losses from risk events
- A forward-looking metric that signals increasing risk exposure (Correct answer)
- A control test result that confirms effectiveness
- A financial ratio used in credit underwriting
Correct answer: A forward-looking metric that signals increasing risk exposure
KRIs are early-warning metrics that signal potential risk increases before a loss event occurs, enabling proactive management.
Question 2: In the NIST Cybersecurity Framework (CSF), which function focuses on limiting the impact of a cybersecurity incident?
- Identify
- Protect
- Respond (Correct answer)
- Recover
Correct answer: Respond
The Respond function of NIST CSF focuses on containing the impact of a cybersecurity incident once it has been detected.
Question 3: A risk register typically contains all of the following EXCEPT:
- Risk description and category
- Risk owner and response plan
- Likelihood and impact ratings
- Employee performance evaluations (Correct answer)
Correct answer: Employee performance evaluations
Risk registers document risk details, ownership, likelihood, impact, and treatment plans — HR performance data is not a risk register component.
Question 4: What does 'risk velocity' refer to in enterprise risk management?
- The financial magnitude of a risk event
- The speed at which a risk could impact the organization if it materializes (Correct answer)
- The number of risks identified in a period
- The frequency of risk committee meetings
Correct answer: The speed at which a risk could impact the organization if it materializes
Risk velocity measures how quickly a risk could escalate from identification to impact, influencing how rapidly a response must be activated.
Question 5: Which framework component ensures that risk information flows up, down, and across the organization?
- Risk Appetite
- Information and Communication (Correct answer)
- Control Environment
- Event Identification
Correct answer: Information and Communication
The Information and Communication component ensures relevant risk data is captured and distributed to stakeholders at all organizational levels.
Question 6: An organization decides not to launch a new product line because the associated risks exceed its appetite. Which response strategy does this represent?
- Transfer
- Reduce
- Accept
- Avoid (Correct answer)
Correct answer: Avoid
Avoidance means not pursuing an activity or decision because the risk is deemed unacceptable relative to the potential reward.
Question 7: In the Three Lines of Defense model, which line is responsible for risk ownership and day-to-day control implementation?
- Internal audit
- Second line (risk and compliance functions)
- First line (operational management) (Correct answer)
- Board of directors
Correct answer: First line (operational management)
The first line of defense — operational management — owns risks and is responsible for implementing and maintaining effective internal controls.
Which of the following best describes a 'Key Risk Indicator' (KRI) in ERM?