Risk Management and Internal Controls Flashcards
7 cards from real RCC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Management and Internal Controls flashcards as text
Which risk management framework is most commonly referenced by U.S. public companies for internal control over financial reporting?
Answer: COSO Internal Control – Integrated Framework
The COSO Internal Control – Integrated Framework is the predominant standard referenced by U.S. public companies under SOX requirements.
A control that prevents an error or irregularity from occurring in the first place is best described as a:
Answer: Preventive control
Preventive controls are designed to stop errors or fraud before they occur, unlike detective controls that identify issues after the fact.
Under enterprise risk management, 'risk appetite' is best defined as:
Answer: The amount of risk an organization is willing to accept in pursuit of its objectives
Risk appetite represents the level of risk an organization is prepared to accept while pursuing its strategic objectives.
Which of the following best describes the 'three lines of defense' model?
Answer: Operations, risk/compliance functions, and internal audit
The three lines of defense model assigns risk ownership to operational management (first), oversight to risk and compliance functions (second), and independent assurance to internal audit (third).
A company discovers that a single employee can both authorize and process payments. This is an example of a failure in:
Answer: Segregation of duties
Segregation of duties requires that no single individual controls all phases of a transaction to reduce the risk of error or fraud.
Which technique involves plotting risks on a grid based on their likelihood and potential impact?
Answer: Risk heat map
A risk heat map visually categorizes risks by likelihood and impact, helping prioritize management attention and resources.
Residual risk is best defined as:
Answer: Risk remaining after management controls have been applied
Residual risk is the level of risk that remains after existing controls and mitigation measures have been implemented.