RCMS Risk Assessment & Internal Controls 4 — Questions and Answers
Question 1: Under the COSO ERM framework, which category of objectives focuses on the efficiency and effectiveness of the organization's operations?
- Reporting objectives
- Compliance objectives
- Operations objectives (Correct answer)
- Strategic objectives
Correct answer: Operations objectives
Operations objectives in COSO ERM address the efficiency and effectiveness of the entity's operations, including performance and profitability goals.
Question 2: A company transfers its cybersecurity risk exposure by purchasing a cyber-liability insurance policy. Which risk response strategy does this represent?
- Risk avoidance
- Risk acceptance
- Risk transfer (Correct answer)
- Risk reduction
Correct answer: Risk transfer
Purchasing insurance shifts the financial consequences of a risk event to a third party (the insurer), which is the risk transfer strategy.
Question 3: Which element of a risk appetite statement specifies the maximum level of risk the organization is willing to take to achieve its strategic objectives?
- Risk tolerance (Correct answer)
- Risk capacity
- Risk threshold
- Risk limit
Correct answer: Risk tolerance
Risk tolerance defines the acceptable variation in outcomes relative to objectives, representing the boundary the organization is willing to operate within.
Question 4: A compliance manager receives an alert that monthly transaction monitoring exceptions have risen 40% above baseline. This alert is triggered by which risk management tool?
- A risk register update
- A Key Risk Indicator breach (Correct answer)
- A control self-assessment finding
- An audit committee report
Correct answer: A Key Risk Indicator breach
A KRI breach occurs when a metric crosses a pre-set threshold, signaling elevated risk and triggering management escalation.
Question 5: Which internal control is MOST effective at detecting unauthorized changes made to master vendor file data?
- Requiring dual approval before vendor creation
- Conducting periodic reconciliations of vendor file changes to an authorized change log (Correct answer)
- Restricting vendor file access to the accounts payable manager only
- Encrypting the vendor database at rest
Correct answer: Conducting periodic reconciliations of vendor file changes to an authorized change log
Reconciling vendor file changes against an authorized log is a detective control that identifies unauthorized additions, deletions, or modifications after they occur.
Question 6: In a risk heat map, which quadrant requires the most immediate management attention?
- Low likelihood, high impact
- High likelihood, low impact
- Low likelihood, low impact
- High likelihood, high impact (Correct answer)
Correct answer: High likelihood, high impact
Risks that are both highly likely and have severe impact rank highest on a heat map and demand priority mitigation resources.
Question 7: Which practice BEST demonstrates an effective 'three lines of defense' model for internal controls?
- The internal audit team also manages compliance testing to reduce headcount
- Business units own and manage their controls, compliance oversees them, and internal audit independently assesses all three (Correct answer)
- External auditors replace internal audit as the third line to save costs
- Risk management and compliance report jointly to the CFO to streamline governance
Correct answer: Business units own and manage their controls, compliance oversees them, and internal audit independently assesses all three
The three lines model separates operational ownership (first line), oversight functions like compliance (second line), and independent assurance (third line) to avoid conflicts of interest.
Under the COSO ERM framework, which category of objectives focuses on the efficiency and effectiveness of the organization's operations?