RCMS Risk Assessment & Internal Controls 2 β Questions and Answers
Question 1: Which risk assessment methodology assigns numerical probability values and financial impact estimates to risks?
- Qualitative risk assessment
- Quantitative risk assessment (Correct answer)
- Inherent risk mapping
- Residual risk scoring
Correct answer: Quantitative risk assessment
Quantitative risk assessment uses numerical probabilities and financial figures to calculate expected loss values for each risk.
Question 2: A compliance officer discovers that a control designed to prevent duplicate payments has never been tested. This represents a failure in which control activity?
- Control design
- Control implementation
- Control monitoring (Correct answer)
- Control documentation
Correct answer: Control monitoring
Control monitoring requires periodic testing and evaluation to confirm that controls are operating effectively over time.
Question 3: Under COSO's Internal Control framework, which component addresses the organization's values, ethics, and commitment to competence?
- Risk Assessment
- Control Activities
- Control Environment (Correct answer)
- Information and Communication
Correct answer: Control Environment
The Control Environment is the foundation of COSO's framework and encompasses the tone set by leadership, ethics, and organizational culture.
Question 4: An organization implements a four-eyes principle requiring two managers to approve large wire transfers. This is an example of which type of control?
- Detective control
- Corrective control
- Preventive control (Correct answer)
- Compensating control
Correct answer: Preventive control
A dual-approval requirement prevents unauthorized transactions from occurring and is therefore a preventive control.
Question 5: Which concept describes the risk that remains after management has applied controls and mitigation measures?
- Inherent risk
- Residual risk (Correct answer)
- Control risk
- Detection risk
Correct answer: Residual risk
Residual risk is what remains after all risk responses and controls have been applied to reduce inherent risk.
Question 6: A company's board sets a policy that no single business unit may approve contracts exceeding $500,000. This is an example of which risk response strategy?
- Risk avoidance
- Risk transfer
- Risk acceptance
- Risk reduction (Correct answer)
Correct answer: Risk reduction
Requiring higher-level approvals for large contracts reduces exposure by adding oversight controls, making this a risk reduction strategy.
Question 7: Which document formally records identified risks, their likelihood, impact, ownership, and mitigation status?
- Control matrix
- Risk register (Correct answer)
- Audit log
- Compliance calendar
Correct answer: Risk register
A risk register is the central repository that tracks each identified risk along with its attributes and the status of related controls.
Which risk assessment methodology assigns numerical probability values and financial impact estimates to risks?