What this quiz covers
This quiz focuses on Apply Coso Erm Framework, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.
In the context of COSO ERM, risk appetite is best defined as:
CPA Isc Quiz
Practice Apply Coso Erm Framework in CPA Isc with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.
This quiz focuses on Apply Coso Erm Framework, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.
Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.
In the context of COSO ERM, risk appetite is best defined as:
Explanation: Risk appetite represents the organization's willingness to accept risk in pursuit of value creation. It reflects strategy and guides risk tolerance decisions. Answer C is correct. Maximum financial loss (A) describes risk capacity. Identified risk events (B) describe a risk inventory. Risk after controls (D) describes residual risk.
The 'Performance' component of COSO ERM 2017 primarily involves:
Explanation: The Performance component covers the core risk management process: identification, assessment, prioritization, and response. Answer C is correct. ERM effectiveness review (A) is Review and Revision. Mission and values (B) are Governance and Culture. Stakeholder communication (D) is Information, Communication, and Reporting.
An organization maintains a risk register with identified risks, likelihood, impact, current controls, and risk owners. In COSO ERM, maintaining this register primarily supports which component?
Explanation: A risk register is the primary tool in the Performance component, documenting and prioritizing risks. Answer A is correct. While it may support governance (B), review (C), and reporting (D), its primary purpose is in the Performance component's risk identification and assessment activities.
Under COSO ERM, a 'key risk indicator' (KRI) is best described as:
Explanation: KRIs are forward-looking metrics that signal when risk levels are changing, enabling proactive management before tolerance is breached. Answer A is correct. Solvency ratios (B) are financial metrics. Control test results (C) are key control indicators. Benchmarks (D) are comparative measures, not KRIs.
A risk has low likelihood but could result in significant reputational damage. Which response is most appropriate under COSO ERM?
Explanation: Reputational risks with significant impact warrant contingency planning and monitoring, even at low likelihood, because reputational damage can be severe and difficult to reverse. Answer B is correct. Accepting without response (A) is inappropriate for high-impact risks. Immediately ceasing activities (C) may be disproportionate. Reputational risk cannot be fully transferred (D).
A company exits a high-risk market segment entirely to eliminate associated risks. Under COSO ERM, this response is classified as:
Explanation: Exiting a business activity to eliminate risk exposure is the Avoid response strategy. Answer C is correct. Transfer (A) shifts risk to another party. Reduce (B) lowers likelihood or impact. Accept (D) takes no action.
Under COSO ERM, the 'Information, Communication, and Reporting' component supports the other components primarily by:
Explanation: The Information, Communication, and Reporting component ensures risk-relevant data is captured and communicated across the organization so stakeholders can fulfill risk management responsibilities. Answer B is correct. Control design and testing (A) is a Control Activities function. Risk appetite (C) is Governance and Culture. Risk identification and assessment (D) is the Performance component.
An organization's board reviews and approves the risk appetite statement annually. Under COSO ERM, this falls within which component?
Explanation: Board oversight of risk appetite is part of the Governance and Culture component, which addresses board roles, management structure, and cultural expectations around risk. Answer B is correct. Risk Assessment (A) involves analyzing risks. Strategy and Objective-Setting (C) involves applying risk appetite. Review and Revision (D) involves monitoring performance.
The COSO ERM 2017 framework introduced which significant enhancement compared to the 2004 version?
Explanation: The 2017 update strengthened the connection between ERM, strategy formulation, and performance management. Answer C is correct. Risk response categories were not reduced (A). Board oversight was retained and strengthened (B). Zero-risk tolerance was not introduced (D).
Under the COSO ERM framework, which of the following best describes 'residual risk'?
Explanation: Residual risk is what remains after risk responses have been applied to inherent risk. Answer D is correct. Preliminary identified risk (A) is closer to inherent risk. External environmental factors (B) describe a source of risk. Portfolio-level aggregate risk (C) is a distinct concept.
Under COSO ERM, which of the following is an example of a risk transfer response strategy?
Explanation: Risk transfer - such as purchasing insurance - is one of the five risk response strategies under COSO ERM 2017 (avoid, accept, reduce, share/transfer, and pursue). Answer A is correct. Identifying risks (B) is part of Risk Assessment. Setting risk appetite (C) is Governance and Culture. Reporting to the board (D) is Information, Communication, and Reporting.
A risk that falls within an organization's risk tolerance and requires no immediate action is best described under COSO ERM as:
Explanation: Under COSO ERM, 'accept' is a valid risk response for risks within established tolerance. No additional action is required beyond monitoring. Answer D is correct. Inherent risks requiring controls (A) have not been assessed against tolerance. KRI escalation (B) implies the risk is moving outside tolerance. Transfer (C) is an active response.
Under COSO ERM, which of the following best describes 'inherent risk'?
Explanation: Inherent risk is the raw, uncontrolled risk level absent any management actions. Answer D is correct. Residual risk (A) is what remains after responses. Internal audit is a control function, not a risk source (B). Transferred risk (C) is a specific risk response outcome.
A manufacturer qualifies a second supplier to reduce supply chain disruption risk. Under COSO ERM, this response is classified as:
Explanation: Qualifying a second supplier reduces the likelihood and/or impact of supply chain disruption - a risk reduction (mitigation) response. Answer B is correct. Accept (A) means taking no action. Avoid (C) would mean exiting the activity entirely. Transfer (D) shifts financial consequences to another party.
Which of the following scenarios represents a failure in the 'Strategy and Objective-Setting' component of COSO ERM?
Explanation: The Strategy and Objective-Setting component requires risk appetite to be considered during strategy development. Pursuing a strategy without assessing its risk implications is a failure here. Answer A is correct. Monitoring residual risks (B) is Review and Revision. Control testing (C) is a Control Activities issue. Communication failures (D) are Information, Communication, and Reporting.
Under COSO ERM, 'risk tolerance' differs from 'risk appetite' in that risk tolerance:
Explanation: Risk appetite is the broad strategic statement of acceptable risk. Risk tolerance is the acceptable variation around specific objectives - more granular and operational. Answer B is correct. Both are set internally (A). Both apply to all risk types (C). Risk appetite is the higher-level concept (D).
Which statement about COSO ERM and COSO ICIF is correct?
Explanation: COSO ERM encompasses strategy through performance, while ICIF focuses specifically on internal control effectiveness. ERM is the broader framework. Answer C is correct. They are distinct frameworks (A). ICIF does not address strategic risk (B). Both apply to all organization types (D).
Under the COSO ERM 2017 framework, which of the following represents the first component?
Explanation: The COSO ERM 2017 framework has five components. Governance and Culture is the foundational first component, setting oversight responsibilities and cultural expectations around risk. Answer A is correct. Risk Assessment (B) is a term from COSO ICIF. Control Activities (C) and Information and Communication (D) are components of COSO ICIF, not the primary ERM components.
The five components of COSO ERM 2017 in order are:
Explanation: The five COSO ERM 2017 components are: Governance and Culture, Strategy and Objective-Setting, Performance, Review and Revision, and Information, Communication, and Reporting. Answer D is correct. Answer A lists COSO ICIF components. Answer B is the NIST Cybersecurity Framework. Answer C is a supply chain framework.
Under COSO ERM, the concept of 'portfolio view of risk' means that:
Explanation: A portfolio view requires assessing how individual risks interact and combine enterprise-wide, since collectively risks may exceed acceptable levels even when each appears manageable in isolation. Answer D is correct. The view is enterprise-wide, not IT-only (A). It requires cross-unit coordination (B). It encompasses all risk types (C).