Risk Assessment & Internal Controls Flashcards
7 cards from real RCMS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Assessment & Internal Controls flashcards as text
Which risk assessment methodology assigns numerical probability values and financial impact estimates to risks?
Answer: Quantitative risk assessment
Quantitative risk assessment uses numerical probabilities and financial figures to calculate expected loss values for each risk.
A compliance officer discovers that a control designed to prevent duplicate payments has never been tested. This represents a failure in which control activity?
Answer: Control monitoring
Control monitoring requires periodic testing and evaluation to confirm that controls are operating effectively over time.
Under COSO's Internal Control framework, which component addresses the organization's values, ethics, and commitment to competence?
Answer: Control Environment
The Control Environment is the foundation of COSO's framework and encompasses the tone set by leadership, ethics, and organizational culture.
An organization implements a four-eyes principle requiring two managers to approve large wire transfers. This is an example of which type of control?
Answer: Preventive control
A dual-approval requirement prevents unauthorized transactions from occurring and is therefore a preventive control.
Which concept describes the risk that remains after management has applied controls and mitigation measures?
Answer: Residual risk
Residual risk is what remains after all risk responses and controls have been applied to reduce inherent risk.
A company's board sets a policy that no single business unit may approve contracts exceeding $500,000. This is an example of which risk response strategy?
Answer: Risk reduction
Requiring higher-level approvals for large contracts reduces exposure by adding oversight controls, making this a risk reduction strategy.
Which document formally records identified risks, their likelihood, impact, ownership, and mitigation status?
Answer: Risk register
A risk register is the central repository that tracks each identified risk along with its attributes and the status of related controls.