Presentations Risk Assessment & Management 3 — Questions and Answers
Question 1: A speaker presents four risk response strategies. Which strategy involves shifting the financial impact of a risk to a third party?
- Transfer (Correct answer)
- Avoid
- Mitigate
- Accept
Correct answer: Transfer
Risk transfer shifts the financial burden of a risk to another party, commonly through insurance or contractual agreements.
Question 2: During a risk workshop presentation, a facilitator introduces FMEA. What does the acronym FMEA stand for?
- Failure Mode and Effects Analysis (Correct answer)
- Frequency Measurement and Estimation Approach
- Financial Management and Evaluation Assessment
- Fault Mitigation and Error Avoidance
Correct answer: Failure Mode and Effects Analysis
FMEA (Failure Mode and Effects Analysis) is a systematic process for identifying potential failures and evaluating their impact.
Question 3: A risk presenter uses the term 'risk velocity.' What does this concept describe?
- How quickly a risk can impact the organization after it materializes (Correct answer)
- The rate at which new risks are identified in a project
- The speed at which risk mitigation plans are executed
- The frequency of risk review meetings
Correct answer: How quickly a risk can impact the organization after it materializes
Risk velocity refers to how rapidly a risk event moves from occurrence to full impact on the organization.
Question 4: In a presentation on financial risk, which metric measures the potential loss in a portfolio over a specific time period at a given confidence level?
- Value at Risk (VaR) (Correct answer)
- Net Present Value (NPV)
- Return on Investment (ROI)
- Earnings Before Interest and Taxes (EBIT)
Correct answer: Value at Risk (VaR)
Value at Risk (VaR) quantifies the maximum expected loss over a defined period at a specified confidence level, commonly 95% or 99%.
Question 5: A compliance officer presents a risk matrix and labels one cell 'critical.' Which combination of risk attributes typically earns this label?
- High probability and high impact (Correct answer)
- Low probability and high impact
- High probability and low impact
- Medium probability and medium impact
Correct answer: High probability and high impact
A 'critical' risk rating results from the combination of high likelihood of occurrence and severe consequences if it occurs.
Question 6: When presenting enterprise risk management (ERM), which framework is most commonly referenced as a global standard?
- COSO ERM Framework (Correct answer)
- ISO 9001
- COBIT 2019
- NIST Cybersecurity Framework
Correct answer: COSO ERM Framework
The COSO ERM Framework (Committee of Sponsoring Organizations) is the most widely recognized global standard for enterprise risk management.
Question 7: A project sponsor asks why the risk register shows 'inherent risk' alongside 'residual risk.' What is inherent risk?
- The raw risk level before any controls are applied (Correct answer)
- Risk that cannot be eliminated under any circumstances
- Risk accepted as part of normal business operations
- Risk that has already materialized into an actual loss
Correct answer: The raw risk level before any controls are applied
Inherent risk is the level of risk exposure that exists before implementing any mitigation or control measures.
A speaker presents four risk response strategies.
Which strategy involves shifting the financial impact of a risk to a third party?