CPA Isc Quiz: Apply Coso Erm Framework
20 questions · exam conditions
0:00
Apply Coso Erm FrameworkQuestion 1 of 20

In the context of COSO ERM, risk appetite is best defined as:

The maximum financial loss the organization can sustain before becoming insolvent.
The specific risk events that management has identified as possible.
The amount and type of risk an organization is willing to accept in pursuit of its objectives.
The level of risk remaining after controls have been applied.
← Back to quizzes

CPA Isc Quiz

CPA Isc Quiz: Apply Coso Erm Framework

Practice Apply Coso Erm Framework in CPA Isc with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.

What this quiz covers

This quiz focuses on Apply Coso Erm Framework, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.

How to use this quiz

Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.

All questions

Question 1

In the context of COSO ERM, risk appetite is best defined as:

  1. The maximum financial loss the organization can sustain before becoming insolvent.
  2. The specific risk events that management has identified as possible.
  3. The amount and type of risk an organization is willing to accept in pursuit of its objectives. (correct answer)
  4. The level of risk remaining after controls have been applied.

Explanation: Risk appetite represents the organization's willingness to accept risk in pursuit of value creation. It reflects strategy and guides risk tolerance decisions. Answer C is correct. Maximum financial loss (A) describes risk capacity. Identified risk events (B) describe a risk inventory. Risk after controls (D) describes residual risk.

Question 2

The 'Performance' component of COSO ERM 2017 primarily involves:

  1. Reviewing whether the ERM framework itself is operating effectively.
  2. Setting the organization's mission, vision, and core values.
  3. Identifying, assessing, prioritizing, and responding to risks that affect the achievement of strategy and business objectives. (correct answer)
  4. Communicating risk information to internal and external stakeholders.

Explanation: The Performance component covers the core risk management process: identification, assessment, prioritization, and response. Answer C is correct. ERM effectiveness review (A) is Review and Revision. Mission and values (B) are Governance and Culture. Stakeholder communication (D) is Information, Communication, and Reporting.

Question 3

An organization maintains a risk register with identified risks, likelihood, impact, current controls, and risk owners. In COSO ERM, maintaining this register primarily supports which component?

  1. Performance - specifically risk identification, assessment, and prioritization. (correct answer)
  2. Governance and Culture - by establishing accountability for risks.
  3. Review and Revision - by providing historical data for trend analysis.
  4. Information, Communication, and Reporting - by distributing risk data to stakeholders.

Explanation: A risk register is the primary tool in the Performance component, documenting and prioritizing risks. Answer A is correct. While it may support governance (B), review (C), and reporting (D), its primary purpose is in the Performance component's risk identification and assessment activities.

Question 4

Under COSO ERM, a 'key risk indicator' (KRI) is best described as:

  1. A metric that provides early warning when a risk is increasing or approaching the risk tolerance threshold. (correct answer)
  2. A financial ratio used to assess an organization's solvency.
  3. A control test result indicating whether a specific control is operating effectively.
  4. A benchmark used to compare the organization's risk profile to industry peers.

Explanation: KRIs are forward-looking metrics that signal when risk levels are changing, enabling proactive management before tolerance is breached. Answer A is correct. Solvency ratios (B) are financial metrics. Control test results (C) are key control indicators. Benchmarks (D) are comparative measures, not KRIs.

Question 5

A risk has low likelihood but could result in significant reputational damage. Which response is most appropriate under COSO ERM?

  1. Accept the risk without any response since likelihood is low.
  2. Develop a crisis communication plan and monitor the risk given its potential reputational impact. (correct answer)
  3. Avoid the risk by ceasing all related business activities immediately.
  4. Transfer all reputational risk through a contractual indemnification clause.

Explanation: Reputational risks with significant impact warrant contingency planning and monitoring, even at low likelihood, because reputational damage can be severe and difficult to reverse. Answer B is correct. Accepting without response (A) is inappropriate for high-impact risks. Immediately ceasing activities (C) may be disproportionate. Reputational risk cannot be fully transferred (D).

Question 6

A company exits a high-risk market segment entirely to eliminate associated risks. Under COSO ERM, this response is classified as:

  1. Transfer
  2. Reduce
  3. Avoid (correct answer)
  4. Accept

Explanation: Exiting a business activity to eliminate risk exposure is the Avoid response strategy. Answer C is correct. Transfer (A) shifts risk to another party. Reduce (B) lowers likelihood or impact. Accept (D) takes no action.

Question 7

Under COSO ERM, the 'Information, Communication, and Reporting' component supports the other components primarily by:

  1. Designing and testing the effectiveness of key internal controls.
  2. Ensuring relevant risk information flows to all levels of the organization to enable informed decision-making. (correct answer)
  3. Setting the organization's risk appetite and tolerance thresholds.
  4. Identifying and assessing risks across all business units.

Explanation: The Information, Communication, and Reporting component ensures risk-relevant data is captured and communicated across the organization so stakeholders can fulfill risk management responsibilities. Answer B is correct. Control design and testing (A) is a Control Activities function. Risk appetite (C) is Governance and Culture. Risk identification and assessment (D) is the Performance component.

Question 8

An organization's board reviews and approves the risk appetite statement annually. Under COSO ERM, this falls within which component?

  1. Risk Assessment
  2. Governance and Culture (correct answer)
  3. Strategy and Objective-Setting
  4. Review and Revision

Explanation: Board oversight of risk appetite is part of the Governance and Culture component, which addresses board roles, management structure, and cultural expectations around risk. Answer B is correct. Risk Assessment (A) involves analyzing risks. Strategy and Objective-Setting (C) involves applying risk appetite. Review and Revision (D) involves monitoring performance.

Question 9

The COSO ERM 2017 framework introduced which significant enhancement compared to the 2004 version?

  1. Reduced the number of risk response categories from five to two.
  2. Eliminated the role of the board of directors in risk oversight.
  3. Greater emphasis on linking ERM to strategy-setting and the relationship between risk and performance. (correct answer)
  4. Required all organizations to adopt a zero-risk tolerance policy.

Explanation: The 2017 update strengthened the connection between ERM, strategy formulation, and performance management. Answer C is correct. Risk response categories were not reduced (A). Board oversight was retained and strengthened (B). Zero-risk tolerance was not introduced (D).

Question 10

Under the COSO ERM framework, which of the following best describes 'residual risk'?

  1. The risk identified during an initial risk assessment before any analysis.
  2. Risks arising from external environmental factors beyond management's control.
  3. The aggregate of all risks across the organization's business units.
  4. The risk remaining after management has implemented responses to reduce inherent risk. (correct answer)

Explanation: Residual risk is what remains after risk responses have been applied to inherent risk. Answer D is correct. Preliminary identified risk (A) is closer to inherent risk. External environmental factors (B) describe a source of risk. Portfolio-level aggregate risk (C) is a distinct concept.

Question 11

Under COSO ERM, which of the following is an example of a risk transfer response strategy?

  1. Purchasing insurance to shift the financial impact of a potential loss to a third party. (correct answer)
  2. Identifying all risks that could affect the achievement of organizational objectives.
  3. Setting the organization's overall risk appetite.
  4. Reporting risk information to the board of directors.

Explanation: Risk transfer - such as purchasing insurance - is one of the five risk response strategies under COSO ERM 2017 (avoid, accept, reduce, share/transfer, and pursue). Answer A is correct. Identifying risks (B) is part of Risk Assessment. Setting risk appetite (C) is Governance and Culture. Reporting to the board (D) is Information, Communication, and Reporting.

Question 12

A risk that falls within an organization's risk tolerance and requires no immediate action is best described under COSO ERM as:

  1. An inherent risk requiring additional controls.
  2. A key risk indicator requiring escalation.
  3. A risk that must be transferred to a third party.
  4. An accepted risk that is monitored but requires no additional response. (correct answer)

Explanation: Under COSO ERM, 'accept' is a valid risk response for risks within established tolerance. No additional action is required beyond monitoring. Answer D is correct. Inherent risks requiring controls (A) have not been assessed against tolerance. KRI escalation (B) implies the risk is moving outside tolerance. Transfer (C) is an active response.

Question 13

Under COSO ERM, which of the following best describes 'inherent risk'?

  1. Risk that remains after management implements its risk response strategies.
  2. Risk that arises from the organization's internal audit function.
  3. Risk that is transferred to a third party through insurance or contracts.
  4. The risk level existing before management applies any controls or risk responses. (correct answer)

Explanation: Inherent risk is the raw, uncontrolled risk level absent any management actions. Answer D is correct. Residual risk (A) is what remains after responses. Internal audit is a control function, not a risk source (B). Transferred risk (C) is a specific risk response outcome.

Question 14

A manufacturer qualifies a second supplier to reduce supply chain disruption risk. Under COSO ERM, this response is classified as:

  1. Accept
  2. Reduce (Mitigate) (correct answer)
  3. Avoid
  4. Transfer

Explanation: Qualifying a second supplier reduces the likelihood and/or impact of supply chain disruption - a risk reduction (mitigation) response. Answer B is correct. Accept (A) means taking no action. Avoid (C) would mean exiting the activity entirely. Transfer (D) shifts financial consequences to another party.

Question 15

Which of the following scenarios represents a failure in the 'Strategy and Objective-Setting' component of COSO ERM?

  1. An organization pursues an aggressive growth strategy without considering how the associated risks align with its stated risk appetite. (correct answer)
  2. Management fails to monitor residual risk levels against established thresholds.
  3. The internal audit function does not test key controls on a timely basis.
  4. Risk information is not effectively communicated to frontline employees.

Explanation: The Strategy and Objective-Setting component requires risk appetite to be considered during strategy development. Pursuing a strategy without assessing its risk implications is a failure here. Answer A is correct. Monitoring residual risks (B) is Review and Revision. Control testing (C) is a Control Activities issue. Communication failures (D) are Information, Communication, and Reporting.

Question 16

Under COSO ERM, 'risk tolerance' differs from 'risk appetite' in that risk tolerance:

  1. Is set by external regulators while risk appetite is set by management.
  2. Represents acceptable variation in outcomes around specific objectives, while risk appetite reflects the overall willingness to accept risk. (correct answer)
  3. Applies only to financial risks while risk appetite applies to all risk types.
  4. Is a higher-level concept than risk appetite.

Explanation: Risk appetite is the broad strategic statement of acceptable risk. Risk tolerance is the acceptable variation around specific objectives - more granular and operational. Answer B is correct. Both are set internally (A). Both apply to all risk types (C). Risk appetite is the higher-level concept (D).

Question 17

Which statement about COSO ERM and COSO ICIF is correct?

  1. COSO ERM and COSO ICIF are identical frameworks with different names.
  2. COSO ICIF is broader because it addresses strategic risks.
  3. COSO ERM is broader than COSO ICIF; ICIF focuses on internal control while ERM encompasses strategy, risk, and performance. (correct answer)
  4. COSO ERM applies only to financial institutions while COSO ICIF applies to all organizations.

Explanation: COSO ERM encompasses strategy through performance, while ICIF focuses specifically on internal control effectiveness. ERM is the broader framework. Answer C is correct. They are distinct frameworks (A). ICIF does not address strategic risk (B). Both apply to all organization types (D).

Question 18

Under the COSO ERM 2017 framework, which of the following represents the first component?

  1. Governance and Culture (correct answer)
  2. Risk Assessment
  3. Control Activities
  4. Information and Communication

Explanation: The COSO ERM 2017 framework has five components. Governance and Culture is the foundational first component, setting oversight responsibilities and cultural expectations around risk. Answer A is correct. Risk Assessment (B) is a term from COSO ICIF. Control Activities (C) and Information and Communication (D) are components of COSO ICIF, not the primary ERM components.

Question 19

The five components of COSO ERM 2017 in order are:

  1. Control Environment, Risk Assessment, Control Activities, Information & Communication, Monitoring.
  2. Identify, Protect, Detect, Respond, Recover.
  3. Plan, Source, Make, Deliver, Return.
  4. Governance & Culture, Strategy & Objective-Setting, Performance, Review & Revision, Information, Communication & Reporting. (correct answer)

Explanation: The five COSO ERM 2017 components are: Governance and Culture, Strategy and Objective-Setting, Performance, Review and Revision, and Information, Communication, and Reporting. Answer D is correct. Answer A lists COSO ICIF components. Answer B is the NIST Cybersecurity Framework. Answer C is a supply chain framework.

Question 20

Under COSO ERM, the concept of 'portfolio view of risk' means that:

  1. All risks must be managed within the IT department's project portfolio.
  2. Each business unit manages its own risks independently without enterprise reference.
  3. Only financial risks are included in the enterprise risk portfolio.
  4. Management considers interrelationships among risks across the organization to understand the aggregate risk profile. (correct answer)

Explanation: A portfolio view requires assessing how individual risks interact and combine enterprise-wide, since collectively risks may exceed acceptable levels even when each appears manageable in isolation. Answer D is correct. The view is enterprise-wide, not IT-only (A). It requires cross-unit coordination (B). It encompasses all risk types (C).