SOC Risk Assessment & Management 2 — Questions and Answers
Question 1: In a SOC 2 engagement, which risk assessment component focuses on how management identifies risks that could prevent the entity from achieving its service commitments?
- Risk tolerance setting
- Risk identification (Correct answer)
- Control activity design
- Residual risk acceptance
Correct answer: Risk identification
Risk identification is the process by which management recognizes risks that could prevent achievement of service commitments and system requirements.
Question 2: A service organization outsources its data backup to a subservice provider. Under the carve-out method in a SOC 1 report, how are the subservice organization's controls treated?
- They are tested and included in the report
- They are excluded from the scope and description (Correct answer)
- They are noted as compensating controls
- They are evaluated via complementary user entity controls
Correct answer: They are excluded from the scope and description
Under the carve-out method, the subservice organization's controls are excluded from the service organization's description and from the scope of the auditor's examination.
Question 3: Which qualitative risk analysis technique assigns risks to categories such as High, Medium, or Low based on likelihood and impact?
- Monte Carlo simulation
- Risk matrix (heat map) (Correct answer)
- Expected monetary value analysis
- Decision tree analysis
Correct answer: Risk matrix (heat map)
A risk matrix or heat map plots likelihood against impact to assign qualitative ratings of High, Medium, or Low.
Question 4: Under COSO ERM, 'risk appetite' is best described as:
- The maximum loss an entity can absorb before insolvency
- The amount of risk an entity is willing to accept in pursuit of value (Correct answer)
- The residual risk remaining after controls are applied
- The probability that a risk event will materialize
Correct answer: The amount of risk an entity is willing to accept in pursuit of value
COSO ERM defines risk appetite as the amount of risk, on a broad level, an entity is willing to accept in pursuit of value.
Question 5: A SOC 2 auditor identifies that a service organization has no formal process for updating its risk register when new services are launched. Which Trust Services Criteria principle does this most directly impact?
- Availability
- Processing Integrity
- Common Criteria – CC3 (Risk Assessment) (Correct answer)
- Common Criteria – CC9 (Risk Mitigation)
Correct answer: Common Criteria – CC3 (Risk Assessment)
CC3 covers risk assessment requirements, including identifying and analyzing risks when changes to the environment occur, such as launching new services.
Question 6: Which of the following best represents a 'risk response' strategy where an organization decides to share risk with a third party?
- Risk avoidance
- Risk acceptance
- Risk transfer (Correct answer)
- Risk reduction
Correct answer: Risk transfer
Risk transfer involves sharing the financial consequences of a risk with another party, commonly through insurance or outsourcing agreements.
Question 7: In the context of SOC engagements, complementary user entity controls (CUECs) are important because they:
- Replace the service organization's own controls entirely
- Are tested by the service auditor as part of the examination
- Represent controls the user entity must implement for the system to operate effectively (Correct answer)
- Are only applicable in SOC 1 Type II reports
Correct answer: Represent controls the user entity must implement for the system to operate effectively
CUECs are controls that the service organization assumes user entities have in place; the service organization's controls alone may be insufficient without them.
In a SOC 2 engagement, which risk assessment component focuses on how management identifies risks that could prevent the entity from achieving its service commitments?