GRC Risk Assessment and Identification Techniques 2 — Questions and Answers
Question 1: Which analytical framework examines Political, Economic, Social, Technological, Legal, and Environmental factors to identify external risks?
- SWOT analysis
- COSO framework
- PESTLE analysis (Correct answer)
- ISO 31000
Correct answer: PESTLE analysis
PESTLE analysis scans the external macro-environment across six categories to surface strategic and operational risks beyond the organization's control.
Question 2: In quantitative risk assessment, Monte Carlo simulation is used to:
- Rank risks qualitatively using color-coded heat maps
- Run thousands of random scenarios to model the probability distribution of potential outcomes (Correct answer)
- Assign controls to risks based on cost-benefit ratios
- Calculate inherent risk before applying controls
Correct answer: Run thousands of random scenarios to model the probability distribution of potential outcomes
Monte Carlo simulation repeatedly samples random values for uncertain variables to produce a statistical distribution of possible risk outcomes and their probabilities.
Question 3: What is the definition of 'residual risk' in a GRC context?
- The total of all identified risks before assessment
- The portion of risk that remains after controls and mitigation measures have been applied (Correct answer)
- The risk transferred to insurers or third parties
- The maximum possible loss from a single risk event
Correct answer: The portion of risk that remains after controls and mitigation measures have been applied
Residual risk is the remaining level of risk exposure after the organization has implemented its chosen controls and mitigation actions.
Question 4: Key Risk Indicators (KRIs) are best described as:
- Lagging metrics that confirm a risk event has already occurred
- Leading metrics that provide early warning signals that a risk may be increasing (Correct answer)
- Policy documents that define acceptable risk thresholds
- Audit findings documenting control deficiencies
Correct answer: Leading metrics that provide early warning signals that a risk may be increasing
KRIs are forward-looking metrics that signal a rising probability of a risk materializing, enabling proactive management before the event occurs.
Question 5: Fault tree analysis (FTA) is a risk assessment technique that:
- Identifies all potential benefits of a control environment
- Uses a top-down, deductive logic diagram to trace causes leading to an undesired top event (Correct answer)
- Maps process flows to compliance requirements
- Ranks risks numerically by expected monetary value
Correct answer: Uses a top-down, deductive logic diagram to trace causes leading to an undesired top event
FTA starts with an undesired outcome at the top and deductively maps the combinations of failures or faults that could cause it using AND/OR logic gates.
Question 6: Scenario analysis in GRC is primarily used to:
- Automate risk reporting across business units
- Evaluate the potential impact of specific hypothetical risk events on the organization (Correct answer)
- Replace the need for a risk register
- Calculate the annualized loss expectancy of cyber incidents
Correct answer: Evaluate the potential impact of specific hypothetical risk events on the organization
Scenario analysis assesses how plausible future events (e.g., a major data breach or supply chain disruption) could affect the organization, supporting strategic risk planning.
Question 7: In risk assessment, Expected Monetary Value (EMV) is calculated as:
- The sum of all risk scores across all business units
- Probability of risk occurrence multiplied by the financial impact of the risk (Correct answer)
- The cost of controls divided by residual risk exposure
- The annualized premium paid for risk transfer through insurance
Correct answer: Probability of risk occurrence multiplied by the financial impact of the risk
EMV = Probability × Impact, providing a single financial figure that represents the weighted average expected loss from a risk event.
Which analytical framework examines Political, Economic, Social, Technological, Legal, and Environmental factors to identify external risks?