โ† All RCMS Flashcard Decks

Risk Assessment & Internal Controls Flashcards

7 cards from real RCMS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Assessment & Internal Controls flashcards as text
  1. Which risk assessment methodology assigns numerical probability values and financial impact estimates to risks?

    Answer: Quantitative risk assessment

    Quantitative risk assessment uses numerical probabilities and financial figures to calculate expected loss values for each risk.

  2. A compliance officer discovers that a control designed to prevent duplicate payments has never been tested. This represents a failure in which control activity?

    Answer: Control monitoring

    Control monitoring requires periodic testing and evaluation to confirm that controls are operating effectively over time.

  3. Under COSO's Internal Control framework, which component addresses the organization's values, ethics, and commitment to competence?

    Answer: Control Environment

    The Control Environment is the foundation of COSO's framework and encompasses the tone set by leadership, ethics, and organizational culture.

  4. An organization implements a four-eyes principle requiring two managers to approve large wire transfers. This is an example of which type of control?

    Answer: Preventive control

    A dual-approval requirement prevents unauthorized transactions from occurring and is therefore a preventive control.

  5. Which concept describes the risk that remains after management has applied controls and mitigation measures?

    Answer: Residual risk

    Residual risk is what remains after all risk responses and controls have been applied to reduce inherent risk.

  6. A company's board sets a policy that no single business unit may approve contracts exceeding $500,000. This is an example of which risk response strategy?

    Answer: Risk reduction

    Requiring higher-level approvals for large contracts reduces exposure by adding oversight controls, making this a risk reduction strategy.

  7. Which document formally records identified risks, their likelihood, impact, ownership, and mitigation status?

    Answer: Risk register

    A risk register is the central repository that tracks each identified risk along with its attributes and the status of related controls.