All questions
Question 1
A not-for-profit social services agency is deploying an artificial intelligence chatbot to triage client requests. The agency expects to reduce administrative costs by 500,000ona12 million budget, but the chatbot will be trained on prior case notes that may contain sensitive personal information. Which internal factor should management prioritize?
- Establishing controls over data quality, privacy, and human review to prevent inappropriate disclosures and service errors (correct answer)
- Increasing investment income by shifting reserves into higher-volatility securities
- Reducing program spending to improve the current-year operating surplus
- Changing the method used to allocate overhead to programs
Explanation: The concept of business risk analysis being tested is prioritizing internal controls for AI deployment in not-for-profit services. Key facts include an AI chatbot for triage using sensitive case notes, with expected cost reductions but data privacy concerns. The correct answer aligns with business analysis principles by emphasizing controls to prevent disclosures and errors, per data governance frameworks. Choice B is incorrect as it addresses investment volatility not related to AI, while C focuses on spending reductions overlooking privacy risks in COSO principles. Choice D is an allocation method not mitigating the core internal data risks in assessments. A framework for evaluating such risks includes data privacy impact assessments and control designs. Management should prioritize by testing controls and ensuring compliance with ethical standards.
Question 2
When evaluating business risks, a company identifies a potential cybersecurity breach. The likelihood of the event is assessed as low, but the potential impact, including financial loss, regulatory fines, and reputational damage, is assessed as catastrophic. How should management prioritize this risk?
- Low priority, because the event is unlikely to occur.
- High priority, because the potential impact threatens the organization's viability. (correct answer)
- Moderate priority, to be addressed after all high-likelihood risks are mitigated.
- It should be accepted without action, as the probability is low.
Explanation: The correct answer is B. Risk evaluation is a function of both likelihood and impact. Even if an event has a low probability of occurring, a catastrophic impact requires that it be treated as a high-priority risk. These types of risks can threaten the ongoing survival of the business and must be managed carefully.
A, C, and D are incorrect because they inappropriately dismiss the severity of the potential impact, which is a critical component of risk assessment.
Question 3
An accounts payable clerk has access to create new vendors, approve invoices, and schedule payments. The company has no independent review of new vendors or changes to existing vendor bank account information. This lack of oversight primarily addresses which element of the fraud triangle?
- Pressure
- Opportunity (correct answer)
- Rationalization
- Incentive
Explanation: The correct answer is B. Opportunity refers to the circumstances that allow fraud to occur. In this case, the weak internal control—specifically, the lack of segregation of duties and independent review—creates an opportunity for the clerk to commit fraud, such as creating a fictitious vendor and paying fraudulent invoices.
A and D are incorrect because pressure (or incentive) refers to an individual's motivation for committing fraud, such as financial hardship. C is incorrect because rationalization is the mindset or justification an individual uses to make their fraudulent actions seem acceptable.
Question 4
A company has outsourced its entire data storage, processing, and IT infrastructure to a single, dominant cloud service provider. While this has reduced costs, it primarily exposes the company to a significant risk of:
- Physical theft of on-premise servers.
- Business disruption due to dependency on a single vendor. (correct answer)
- Data entry errors by company employees.
- Non-compliance with internal software development standards.
Explanation: The correct answer is B. This scenario describes vendor concentration risk. By relying on a single provider for critical functions, the company is vulnerable to major business disruptions if that provider experiences a significant outage, a security breach, a drastic price increase, or goes out of business. This is a key risk to evaluate in vendor management.
A is incorrect because the servers are no longer on-premise. C is an operational risk but is not directly created by the outsourcing decision. D is an IT governance risk unrelated to the use of a third-party infrastructure provider.
Question 5
What is the primary purpose of an organization's board of directors establishing and communicating a formal risk appetite statement?
- To detail the specific internal control procedures to be performed for every process.
- To completely eliminate the possibility of financial losses.
- To satisfy a mandatory SEC reporting requirement for all public companies.
- To guide strategic planning and decision-making by defining the level of risk the entity is willing to accept. (correct answer)
Explanation: The correct answer is D. A risk appetite statement defines the amount and type of risk that an organization is willing to pursue or accept in the pursuit of its objectives. It serves as a high-level guide for management, helping to align strategy, resource allocation, and infrastructure with the board's risk philosophy.
A is incorrect because a risk appetite statement is a high-level guide, not a detailed procedural manual. B is incorrect as it is impossible to eliminate all risks. C is incorrect because while risk disclosure is required, a specific formal risk appetite statement is a leading practice, not a universal SEC mandate.
Question 6
A company's risk assessment team evaluates the risk of a major system failure. They determine that the potential loss from such an event would be $500,000. Based on historical data and system diagnostics, they estimate the probability of this event occurring in the next year to be 5%.
What is the expected annual loss from this specific risk?
- $500,000
- $25,000 (correct answer)
- $5,000
- $2,500
Explanation: The correct answer is B. Expected loss is a quantitative risk assessment technique calculated as the product of the potential loss and the probability of occurrence. In this case, the calculation is:
Expected Loss = Potential Loss × Probability
Expected Loss = $500,000 × 5% = $25,000.
A is the total potential loss, not the expected annual loss. C and D are incorrect calculations.
Question 7
Which of the following activities is a core principle within the Risk Assessment component of the 2013 COSO Internal Control Framework?
- The organization selects, develops, and performs ongoing and/or separate evaluations of internal controls.
- The organization demonstrates a commitment to attract, develop, and retain competent individuals.
- The organization considers the potential for fraud in assessing risks to the achievement of objectives. (correct answer)
- The organization selects and develops general control activities over technology.
Explanation: The correct answer is C. Principle 8 of the COSO framework, which falls under the Risk Assessment component, explicitly states that the organization should consider the potential for fraud when assessing risks. This involves evaluating incentives, pressures, opportunities, and rationalizations for fraud.
A is a principle of the Monitoring Activities component. B is a principle of the Control Environment component. D is a principle of the Control Activities component.
Question 8
After its risk assessment, a company determines that a potential new venture in a politically unstable country has an unacceptably high level of risk. The company's board of directors decides to cancel the project entirely before any significant investment is made. This risk response is best described as:
- Risk reduction
- Risk sharing
- Risk acceptance
- Risk avoidance (correct answer)
Explanation: The correct answer is D. Risk avoidance is a response strategy that involves deciding not to become involved in, or to withdraw from, a risk situation. By canceling the project, the company is avoiding the associated risks altogether.
A (reduction or mitigation) would involve implementing controls to lower the risk. B (sharing or transfer) would involve actions like buying insurance or partnering with another company. C (acceptance) would mean proceeding with the project despite the identified risks.
Question 9
An internal auditor identifies a significant flaw in a company's cybersecurity defenses. This vulnerability could not only lead to a data breach (an operational risk) but also result in large regulatory fines (a compliance risk) and severe damage to the company's brand (a reputational risk). This scenario best illustrates which key concept in risk evaluation?
- All risks can eventually be eliminated through proper controls.
- Risks are often interrelated and can have cascading impacts across different categories. (correct answer)
- External risks are always more impactful than internal risks.
- Risk evaluation is a one-time process that does not require ongoing monitoring.
Explanation: The correct answer is B. This scenario highlights that a single risk event, like a cybersecurity failure, rarely exists in isolation. It can trigger a chain reaction, leading to impacts in various other risk categories (operational, compliance, reputational, financial). Effective risk evaluation requires understanding these interrelationships.
A is incorrect because not all risks can be eliminated. C is an invalid generalization; the impact of internal vs. external risks varies. D is incorrect as risk evaluation is a continuous, dynamic process.
Question 10
An organization's IT policy allows software developers to directly access and modify the code in the live production environment to fix bugs quickly. From an IT general controls perspective, this practice significantly increases the risk of:
- Failure to obtain volume discounts on software licenses.
- Inefficient use of hardware resources.
- Unauthorized or improperly tested changes disrupting business operations. (correct answer)
- Delays in the initial development of new applications.
Explanation: The correct answer is C. This practice violates the principle of segregation of duties between development, testing, and production environments. A fundamental IT general control is change management, which ensures that all changes are authorized, tested, and properly deployed. Allowing developers direct production access bypasses these controls, increasing the risk of introducing errors, malicious code, or other disruptions.
A, B, and D are potential IT issues, but they are not the primary risk created by this specific control weakness.
Question 11
A U.S.-based company has issued a significant amount of debt with a floating interest rate tied to the Secured Overnight Financing Rate (SOFR). If economic forecasts predict that the central bank will raise benchmark rates several times over the next year, the company is most directly exposed to:
- Foreign currency risk
- Credit risk
- Interest rate risk (correct answer)
- Commodity price risk
Explanation: The correct answer is C. Interest rate risk is the potential for loss that can result from changes in interest rates. Since the company's debt has a variable interest rate, an increase in benchmark rates will lead to higher interest payments, reducing profitability and cash flow.
A is incorrect as the debt is in the company's home currency. B is incorrect because this refers to the risk that the company's customers won't pay, not the risk related to its own debt. D is incorrect as the risk is not tied to raw material prices.
Question 12
A division manager is facing significant personal financial difficulties. At the same time, the manager's performance is measured by achieving an aggressive quarterly profit target, with a substantial cash bonus at stake. The manager has the authority to approve large vendor payments without a secondary review.
The manager's personal financial difficulties and the bonus structure primarily represent which component of the fraud triangle?
- Opportunity
- Collusion
- Rationalization
- Pressure/Incentive (correct answer)
Explanation: The correct answer is D. Pressure, also referred to as incentive or motivation, is what causes an individual to commit fraud. In this case, both the personal financial problems (a classic pressure) and the aggressive bonus structure (a strong incentive) provide the motivation for the manager to engage in fraudulent activity to meet the target.
A, opportunity, is represented by the manager's authority to approve payments without review. C, rationalization, is the internal justification the manager might use, which is not described. B, collusion, is not a component of the fraud triangle.
Question 13
An organization's board of directors wants to identify and evaluate the most significant risks to its long-term strategy and business model, such as disruptive technologies, major shifts in consumer behavior, and geopolitical events. Which risk assessment approach would be most suitable for this purpose?
- A bottom-up risk assessment focused on process-level controls in the accounting department.
- A compliance audit against current industry regulations.
- A top-down strategic risk assessment involving senior leadership and the board. (correct answer)
- A review of IT help desk tickets to identify recurring system issues.
Explanation: The correct answer is C. A top-down approach begins at the entity level with the organization's objectives and strategies. It is ideal for identifying the high-level, significant risks that could impede the achievement of those long-term goals. This aligns perfectly with the board's focus on strategic threats.
A and D are examples of bottom-up approaches that identify more granular, operational risks but would likely miss the major strategic risks. B is too narrow, focusing only on compliance risk.
Question 14
A pharmaceutical company is subject to complex regulations from the Food and Drug Administration (FDA) regarding drug manufacturing processes. Failure to adhere to these regulations could result in significant fines, production halts, and forced recalls. This potential for loss is best described as:
- Reputational risk
- Compliance risk (correct answer)
- Market risk
- Strategic risk
Explanation: The correct answer is B. Compliance risk is the risk of legal or regulatory sanctions, financial loss, or loss to reputation an organization may suffer as a result of its failure to comply with laws, regulations, rules, related self-regulatory organization standards, and codes of conduct. The FDA regulations are a clear example of this.
A is incorrect because reputational damage would be a consequence of a compliance failure, but the root cause is compliance risk. C and D are incorrect as the risk stems directly from adherence to specific external rules, not from market movements or high-level strategic choices.
Question 15
When a company is considering a large capital investment, it creates a financial model to project the net present value (NPV). Management is concerned about the uncertainty in its initial assumptions for sales volume and variable costs. Which of the following techniques would be most useful for evaluating the project's risk profile?
- DuPont analysis
- Sensitivity analysis (correct answer)
- Common-size financial statement analysis
- Activity-based costing
Explanation: The correct answer is B. Sensitivity analysis is a risk assessment technique used in capital budgeting to determine how the NPV (or other outcomes) will change in response to a given change in a single input variable, holding all others constant. This allows management to identify the variables that have the most impact on the outcome and understand the project's vulnerability to forecasting errors.
A is used to analyze return on equity. C is used to compare financial statements across periods or companies. D is a method for allocating overhead costs.
Question 16
Management uses a risk heat map to visually represent the results of its risk assessment. Where on the map would a risk be placed if it is deemed to have a very low probability of occurring but would result in a moderate financial loss if it did?
- High impact, high likelihood quadrant.
- Low impact, high likelihood quadrant.
- High impact, low likelihood quadrant. (correct answer)
- Low impact, low likelihood quadrant.
Explanation: The correct answer is C. A risk with very low probability of occurring corresponds to 'low likelihood.' A moderate financial loss would typically be classified as 'high impact' on a standard risk heat map that divides risks into high/low categories, as it represents a significant financial consequence even if not catastrophic.
A is for critical risks that are both severe and likely. B is for risks that occur frequently but have minor consequences. D is for risks that are both unlikely and have minimal impact when they occur.
Question 17
An internal audit identifies a significant risk of data entry errors in the accounts payable process. Management responds by implementing an automated three-way matching system. The level of risk that remains after this control is implemented is referred to as:
- Inherent risk
- Control risk
- Residual risk (correct answer)
- Detection risk
Explanation: The correct answer is C. Residual risk is the risk that remains after management has taken action to mitigate it, such as implementing an internal control. It is the net risk after considering the effectiveness of controls.
A is incorrect because inherent risk is the level of risk before any controls or mitigation strategies are applied. B is incorrect because control risk is the risk that a control will fail to prevent or detect a misstatement. D is incorrect because detection risk is the risk that an auditor's procedures will not detect a material misstatement.
Question 18
A company's primary manufacturing facility relies on a single, aging piece of custom machinery for a critical step in its production line. Frequent breakdowns of this machine have led to production stoppages and delayed shipments. This situation is a primary example of:
- Credit risk
- Liquidity risk
- Operational risk (correct answer)
- Market risk
Explanation: The correct answer is C. Operational risk is the risk of loss resulting from inadequate or failed internal processes, people, and systems or from external events. The potential for failure of a critical piece of machinery is a classic example of an internal systems failure that falls under operational risk.
A, B, and D are all types of financial risk. Credit risk relates to a counterparty's failure to pay, liquidity risk relates to the inability to meet short-term obligations, and market risk relates to losses from factors that affect the entire market, like interest rate changes.
Question 19
A well-established technology company decides to enter the highly competitive and rapidly evolving electric vehicle market. The success of this new venture is uncertain and depends heavily on consumer adoption, regulatory changes, and intense competition from existing manufacturers.
The primary business risk this company is undertaking by launching this new venture is best classified as:
- Operational risk
- Financial risk
- Compliance risk
- Strategic risk (correct answer)
Explanation: The correct answer is D. Strategic risk relates to the high-level decisions that affect an organization's ability to achieve its goals and objectives. Entering a new, competitive market is a major strategic decision with significant uncertainty, directly impacting the company's long-term direction and viability.
A is incorrect because operational risk relates to failures in internal processes, people, and systems. B is incorrect because while the venture has financial implications, the root risk is strategic; financial risk is more specific, such as interest rate or credit risk. C is incorrect because compliance risk relates to violations of laws and regulations, which is a factor but not the primary classification for the entire market entry decision.
Question 20
A manufacturing company is conducting its annual enterprise risk management (ERM) process. Management wants to ensure it identifies a broad range of risks, from day-to-day operational issues to long-term strategic threats, and foster a sense of shared ownership for risk management.
Which of the following risk identification techniques would be most effective for achieving the company's goals?
- Reviewing the prior year's internal audit findings.
- Interviewing only the Chief Financial Officer and the Chief Executive Officer.
- Conducting facilitated risk assessment workshops with cross-functional teams. (correct answer)
- Using a generic manufacturing industry risk checklist from an external consultant.
Explanation: The correct answer is C. Facilitated workshops with cross-functional teams bring together diverse perspectives from different parts of the business. This collaborative approach is highly effective for identifying a comprehensive range of risks (operational, strategic, etc.) and promotes a culture of shared responsibility for risk management.
A is too narrow, focusing only on past issues. B is a top-down approach that would likely miss granular operational risks. D is a useful starting point but lacks the specific context of the company and may not uncover unique or emerging risks.