GRC Enterprise Risk Management Frameworks 5 — Questions and Answers
Question 1: A bowtie diagram in risk management is used to visualize:
- The financial impact of risks over time
- Causes (threats) on the left and consequences on the right, with the risk event at the center (Correct answer)
- The hierarchy of risk owners across the organization
- The relationship between key risk indicators and key performance indicators
Correct answer: Causes (threats) on the left and consequences on the right, with the risk event at the center
A bowtie diagram places the risk event at the center, with threat pathways on the left side and consequence pathways on the right, along with barriers.
Question 2: Which of the following statements about risk tolerance vs. risk appetite is MOST accurate?
- They are synonymous and used interchangeably in all frameworks
- Risk appetite is broader and strategic; risk tolerance is the specific acceptable variation around that appetite (Correct answer)
- Risk tolerance is set by the board; risk appetite is set by management
- Risk appetite applies to financial risks only; risk tolerance applies to operational risks
Correct answer: Risk appetite is broader and strategic; risk tolerance is the specific acceptable variation around that appetite
Risk appetite expresses the overall level of risk an organization accepts in pursuit of value; risk tolerance specifies acceptable deviations from objectives within that appetite.
Question 3: In ERM, what does 'emerging risk' refer to?
- A risk that has already materialized and caused a loss
- A newly identified or evolving risk that is not yet fully understood or quantified (Correct answer)
- A risk that has been transferred to a third party
- A risk elevated from low to high priority after reassessment
Correct answer: A newly identified or evolving risk that is not yet fully understood or quantified
Emerging risks are novel or evolving threats — such as new technologies or geopolitical shifts — that have uncertain characteristics and require monitoring.
Question 4: Which of the following is an example of a 'risk treatment' option under ISO 31000:2018?
- Documenting a risk in the risk register
- Conducting a risk workshop with stakeholders
- Taking out an insurance policy to transfer risk (Correct answer)
- Assigning a KRI threshold to a risk
Correct answer: Taking out an insurance policy to transfer risk
ISO 31000 defines risk treatment as the process of selecting and implementing options to modify risk, including transferring it through insurance.
Question 5: A risk committee is reviewing a strategic risk that has a low probability but catastrophic potential impact. Which concept best justifies prioritizing this risk despite its low likelihood?
- Risk velocity
- Black swan theory (Correct answer)
- Risk aggregation
- Risk diversification
Correct answer: Black swan theory
Black swan theory, developed by Nassim Taleb, emphasizes that rare, extreme-impact events warrant special attention even when their probability appears negligible.
Question 6: Which COSO ERM principle states that organizations should develop a 'portfolio view' of risk?
- Analyzes Business Context
- Defines Risk Appetite
- Develops Portfolio View (Correct answer)
- Pursues Improvement in Enterprise Risk Management
Correct answer: Develops Portfolio View
The 'Develops Portfolio View' principle requires management to aggregate risks across business units to understand the total risk profile relative to appetite.
Question 7: An organization's ERM program is described as 'ad hoc and reactive' with no formal processes. At which maturity level would this program be classified under a standard ERM maturity model?
- Optimized
- Managed
- Defined
- Initial (Correct answer)
Correct answer: Initial
The Initial (or Ad Hoc) maturity level describes organizations where risk management is informal, reactive, and not systematically applied.
A bowtie diagram in risk management is used to visualize: