RCC Risk Management and Internal Controls 2 — Questions and Answers
Question 1: Which risk management framework is most commonly referenced by U.S. public companies for internal control over financial reporting?
- ISO 31000
- COSO Internal Control – Integrated Framework (Correct answer)
- COBIT 2019
- NIST RMF
Correct answer: COSO Internal Control – Integrated Framework
The COSO Internal Control – Integrated Framework is the predominant standard referenced by U.S. public companies under SOX requirements.
Question 2: A control that prevents an error or irregularity from occurring in the first place is best described as a:
- Detective control
- Corrective control
- Preventive control (Correct answer)
- Compensating control
Correct answer: Preventive control
Preventive controls are designed to stop errors or fraud before they occur, unlike detective controls that identify issues after the fact.
Question 3: Under enterprise risk management, 'risk appetite' is best defined as:
- The maximum loss a firm can sustain before insolvency
- The amount of risk an organization is willing to accept in pursuit of its objectives (Correct answer)
- The residual risk remaining after controls are applied
- The probability that a risk event will materialize
Correct answer: The amount of risk an organization is willing to accept in pursuit of its objectives
Risk appetite represents the level of risk an organization is prepared to accept while pursuing its strategic objectives.
Question 4: Which of the following best describes the 'three lines of defense' model?
- Regulators, auditors, and legal counsel
- Operations, risk/compliance functions, and internal audit (Correct answer)
- Board, CEO, and CFO
- External auditors, regulators, and whistleblowers
Correct answer: Operations, risk/compliance functions, and internal audit
The three lines of defense model assigns risk ownership to operational management (first), oversight to risk and compliance functions (second), and independent assurance to internal audit (third).
Question 5: A company discovers that a single employee can both authorize and process payments. This is an example of a failure in:
- Risk appetite alignment
- Segregation of duties (Correct answer)
- Detective control design
- Tone at the top
Correct answer: Segregation of duties
Segregation of duties requires that no single individual controls all phases of a transaction to reduce the risk of error or fraud.
Question 6: Which technique involves plotting risks on a grid based on their likelihood and potential impact?
- Monte Carlo simulation
- Risk heat map (Correct answer)
- Sensitivity analysis
- Control self-assessment
Correct answer: Risk heat map
A risk heat map visually categorizes risks by likelihood and impact, helping prioritize management attention and resources.
Question 7: Residual risk is best defined as:
- Risk identified but not yet assessed
- Risk that has already materialized into a loss
- Risk remaining after management controls have been applied (Correct answer)
- Inherent risk multiplied by control effectiveness
Correct answer: Risk remaining after management controls have been applied
Residual risk is the level of risk that remains after existing controls and mitigation measures have been implemented.
Which risk management framework is most commonly referenced by U.S. public companies for internal control over financial reporting?