GRC Risk Assessment and Identification Techniques 1 — Questions and Answers
Question 1: Which tool is most commonly used to document and track identified risks, their likelihood, potential impact, and assigned owners within an organization?
- Risk register (Correct answer)
- Control matrix
- Audit log
- Policy repository
Correct answer: Risk register
A risk register is the primary GRC artifact for cataloging risks along with their attributes such as likelihood, impact, owner, and mitigation status.
Question 2: A risk heat map that plots risks by likelihood on one axis and impact on the other is also known as a:
- Bow-tie diagram
- Risk matrix (Correct answer)
- Fault tree
- Control map
Correct answer: Risk matrix
A risk matrix (heat map) uses a two-axis grid of likelihood and impact to visually prioritize risks by their severity.
Question 3: What is the primary difference between qualitative and quantitative risk assessment?
- Qualitative uses monetary values; quantitative uses descriptive rankings
- Qualitative uses descriptive rankings; quantitative uses numerical values and statistical methods (Correct answer)
- Qualitative is performed by auditors; quantitative is performed by management
- Qualitative applies only to cyber risk; quantitative applies to financial risk
Correct answer: Qualitative uses descriptive rankings; quantitative uses numerical values and statistical methods
Qualitative assessments categorize risks using descriptive scales (high/medium/low), while quantitative assessments assign numerical probabilities and financial impact figures.
Question 4: In GRC, what does 'inherent risk' refer to?
- The risk remaining after controls are applied
- The risk that exists before any controls or mitigating actions are implemented (Correct answer)
- The risk transferred to a third party
- The risk accepted by senior management
Correct answer: The risk that exists before any controls or mitigating actions are implemented
Inherent risk is the level of risk in the absence of any controls or mitigating measures, representing the raw exposure.
Question 5: Which risk identification technique involves gathering input from a panel of experts through multiple anonymous rounds of questionnaires to reach consensus?
- SWOT analysis
- Delphi technique (Correct answer)
- Fault tree analysis
- Control self-assessment
Correct answer: Delphi technique
The Delphi technique uses iterative, anonymous expert surveys to converge on a consensus view of risk likelihood and impact.
Question 6: What is the relationship between risk appetite and risk tolerance in GRC?
- They are synonymous terms used interchangeably
- Risk appetite is the broad level of risk accepted; risk tolerance is the acceptable variance around that level (Correct answer)
- Risk tolerance defines strategic objectives; risk appetite defines day-to-day operations
- Risk appetite applies to financial risk only; tolerance applies to operational risk
Correct answer: Risk appetite is the broad level of risk accepted; risk tolerance is the acceptable variance around that level
Risk appetite sets the overall amount of risk an organization is willing to accept, while risk tolerance defines the acceptable variation or deviation within that appetite.
Question 7: A bow-tie analysis in risk management is best described as:
- A diagram connecting risk causes on the left to consequences on the right with the hazard/risk event at the center (Correct answer)
- A matrix mapping controls to risks in a two-by-two grid
- A ranking tool that assigns numeric scores to risks based on severity
- A process flowchart showing audit procedures
Correct answer: A diagram connecting risk causes on the left to consequences on the right with the hazard/risk event at the center
A bow-tie diagram visually represents threat causes (left side), the central risk event, preventive controls, and consequence mitigation controls (right side).
Which tool is most commonly used to document and track identified risks, their likelihood, potential impact, and assigned owners within an organization?