Risk Assessment & Internal Controls Flashcards
7 cards from real RCMS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Assessment & Internal Controls flashcards as text
Under the COSO ERM framework, which category of objectives focuses on the efficiency and effectiveness of the organization's operations?
Answer: Operations objectives
Operations objectives in COSO ERM address the efficiency and effectiveness of the entity's operations, including performance and profitability goals.
A company transfers its cybersecurity risk exposure by purchasing a cyber-liability insurance policy. Which risk response strategy does this represent?
Answer: Risk transfer
Purchasing insurance shifts the financial consequences of a risk event to a third party (the insurer), which is the risk transfer strategy.
Which element of a risk appetite statement specifies the maximum level of risk the organization is willing to take to achieve its strategic objectives?
Answer: Risk tolerance
Risk tolerance defines the acceptable variation in outcomes relative to objectives, representing the boundary the organization is willing to operate within.
A compliance manager receives an alert that monthly transaction monitoring exceptions have risen 40% above baseline. This alert is triggered by which risk management tool?
Answer: A Key Risk Indicator breach
A KRI breach occurs when a metric crosses a pre-set threshold, signaling elevated risk and triggering management escalation.
Which internal control is MOST effective at detecting unauthorized changes made to master vendor file data?
Answer: Conducting periodic reconciliations of vendor file changes to an authorized change log
Reconciling vendor file changes against an authorized log is a detective control that identifies unauthorized additions, deletions, or modifications after they occur.
In a risk heat map, which quadrant requires the most immediate management attention?
Answer: High likelihood, high impact
Risks that are both highly likely and have severe impact rank highest on a heat map and demand priority mitigation resources.
Which practice BEST demonstrates an effective 'three lines of defense' model for internal controls?
Answer: Business units own and manage their controls, compliance oversees them, and internal audit independently assesses all three
The three lines model separates operational ownership (first line), oversight functions like compliance (second line), and independent assurance (third line) to avoid conflicts of interest.