SOC Risk Assessment & Management 3 — Questions and Answers
Question 1: When assessing the severity of a risk in a SOC engagement, an auditor considers both the likelihood of a risk occurring and its:
- Detection timing
- Potential impact on service commitments (Correct answer)
- Number of controls in place
- Cost of remediation
Correct answer: Potential impact on service commitments
Risk severity is determined by combining the likelihood of occurrence with the potential impact on the entity's ability to meet its service commitments.
Question 2: A financial services firm uses a SOC 1 Type II report to assess a payroll processor. The Type II report differs from a Type I report in that it:
- Covers a point in time rather than a period
- Includes testing of operating effectiveness over a period (Correct answer)
- Only addresses the design of controls
- Is restricted to internal use only
Correct answer: Includes testing of operating effectiveness over a period
A Type II report covers a defined period (minimum six months) and includes the auditor's tests of operating effectiveness, unlike the Type I which only addresses design.
Question 3: Which risk assessment framework is most commonly referenced alongside COSO when evaluating internal controls in a SOC engagement?
- ISO 31000
- NIST SP 800-30
- COSO Internal Control – Integrated Framework (Correct answer)
- COBIT 2019
Correct answer: COSO Internal Control – Integrated Framework
COSO's Internal Control – Integrated Framework is the primary framework referenced in SOC engagements for evaluating control design and effectiveness.
Question 4: An entity's board sets a policy that no single transaction can expose the company to more than $500,000 in loss. This policy best represents the concept of:
- Risk capacity
- Risk tolerance (Correct answer)
- Inherent risk
- Control risk
Correct answer: Risk tolerance
Risk tolerance refers to the acceptable level of variation in outcomes relative to the achievement of objectives, often expressed in quantitative terms.
Question 5: During a SOC 2 examination, the auditor notes that the service organization's risk assessment process does not consider fraud risk. This is most likely a deficiency related to:
- CC5.1 – Control activities
- CC3.3 – Considers the potential for fraud in assessing risks (Correct answer)
- CC7.2 – Monitoring of controls
- CC9.1 – Vendor and business partner risk management
Correct answer: CC3.3 – Considers the potential for fraud in assessing risks
CC3.3 specifically requires that the risk assessment process consider the potential for fraud, including fraudulent financial reporting and misappropriation of assets.
Question 6: A company decides to discontinue a high-risk product line entirely to eliminate exposure. This is an example of which risk response?
- Risk mitigation
- Risk transfer
- Risk avoidance (Correct answer)
- Risk acceptance
Correct answer: Risk avoidance
Risk avoidance involves exiting or not engaging in activities that give rise to risk, eliminating the exposure entirely.
Question 7: In a SOC engagement, 'inherent risk' refers to risk:
- After considering the effect of related control activities
- That remains after management's risk response
- Before considering any controls or risk responses (Correct answer)
- Associated with the auditor's sampling methodology
Correct answer: Before considering any controls or risk responses
Inherent risk is the risk to an entity in the absence of any actions management might take to alter the risk's likelihood or impact.
When assessing the severity of a risk in a SOC engagement, an auditor considers both the likelihood of a risk occurring and its: