GRC Risk Management & Mitigation Strategies 3 — Questions and Answers
Question 1: Which framework is most commonly associated with enterprise risk management (ERM) and uses components such as risk appetite and risk culture?
- ISO 27001
- COSO ERM (Correct answer)
- NIST RMF
- COBIT 5
Correct answer: COSO ERM
The COSO ERM framework provides guidance on enterprise-wide risk management, including risk culture, governance, and appetite.
Question 2: A risk that is deliberately accepted because its cost to mitigate exceeds the potential loss is called:
- Transferred risk
- Avoided risk
- Accepted risk (Correct answer)
- Controlled risk
Correct answer: Accepted risk
Risk acceptance (also called risk tolerance) means the organization knowingly chooses to live with the risk rather than spend resources reducing it.
Question 3: In a risk heat map, which axis typically represents the likelihood of a risk occurring?
- Vertical axis (Y-axis)
- Horizontal axis (X-axis) (Correct answer)
- Both axes equally
- Neither axis — heat maps don't show likelihood
Correct answer: Horizontal axis (X-axis)
Convention varies, but likelihood (probability) is most commonly plotted on the X-axis and impact on the Y-axis in risk heat maps.
Question 4: Which risk treatment option introduces new risks as a direct result of applying the original treatment?
- Residual risk
- Secondary risk (Correct answer)
- Inherent risk
- Accepted risk
Correct answer: Secondary risk
Secondary risks are unintended new risks created by implementing a risk response plan.
Question 5: What does a qualitative risk assessment rely on primarily?
- Dollar amounts and statistical probability
- Expert judgment and descriptive scales (e.g., High/Medium/Low) (Correct answer)
- Actuarial tables and historical loss data
- Automated scanning tools
Correct answer: Expert judgment and descriptive scales (e.g., High/Medium/Low)
Qualitative risk assessments use subjective scoring and descriptive categories rather than precise numerical data.
Question 6: The concept of 'risk appetite' is best defined as:
- The maximum loss an organization can absorb before insolvency
- The amount and type of risk an organization is willing to accept in pursuit of its objectives (Correct answer)
- The regulatory limit on risk exposure
- The cost of all active risk controls
Correct answer: The amount and type of risk an organization is willing to accept in pursuit of its objectives
Risk appetite reflects senior management's and the board's willingness to take on risk while pursuing strategic goals.
Question 7: When is a risk considered 'critical' in most GRC frameworks?
- When it requires board approval to address
- When it has both high likelihood and high impact (Correct answer)
- When it exceeds the organization's insurance limits
- When it is identified by an external auditor
Correct answer: When it has both high likelihood and high impact
Risks scoring high on both likelihood and impact axes are rated critical and typically require immediate prioritized treatment.
Which framework is most commonly associated with enterprise risk management (ERM) and uses components such as risk appetite and risk culture?