Under the COSO ERM 2017 framework, which of the following represents the first component?
Opening subject page...
Loading your content
CPA Isc Quiz
Practice Apply Coso Erm Framework in CPA Isc with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.
Question 1 / 20
0 of 20 answered
Under the COSO ERM 2017 framework, which of the following represents the first component?
This quiz focuses on Apply Coso Erm Framework, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.
Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.
Under the COSO ERM 2017 framework, which of the following represents the first component?
Explanation: The COSO ERM 2017 framework has five components. Governance and Culture is the foundational first component, setting oversight responsibilities and cultural expectations around risk. Answer A is correct. Risk Assessment (B) is a term from COSO ICIF. Control Activities (C) and Information and Communication (D) are components of COSO ICIF, not the primary ERM components.
In the context of COSO ERM, risk appetite is best defined as:
Explanation: Risk appetite represents the organization's willingness to accept risk in pursuit of value creation. It reflects strategy and guides risk tolerance decisions. Answer C is correct. Maximum financial loss (A) describes risk capacity. Identified risk events (B) describe a risk inventory. Risk after controls (D) describes residual risk.
Under the COSO ERM framework, which of the following best describes 'residual risk'?
Explanation: Residual risk is what remains after risk responses have been applied to inherent risk. Answer D is correct. Preliminary identified risk (A) is closer to inherent risk. External environmental factors (B) describe a source of risk. Portfolio-level aggregate risk (C) is a distinct concept.
Under COSO ERM, which of the following is an example of a risk transfer response strategy?
Explanation: Risk transfer - such as purchasing insurance - is one of the five risk response strategies under COSO ERM 2017 (avoid, accept, reduce, share/transfer, and pursue). Answer A is correct. Identifying risks (B) is part of Risk Assessment. Setting risk appetite (C) is Governance and Culture. Reporting to the board (D) is Information, Communication, and Reporting.
A risk that falls within an organization's risk tolerance and requires no immediate action is best described under COSO ERM as:
Explanation: Under COSO ERM, 'accept' is a valid risk response for risks within established tolerance. No additional action is required beyond monitoring. Answer D is correct. Inherent risks requiring controls (A) have not been assessed against tolerance. KRI escalation (B) implies the risk is moving outside tolerance. Transfer (C) is an active response.
The 'Performance' component of COSO ERM 2017 primarily involves:
Explanation: The Performance component covers the core risk management process: identification, assessment, prioritization, and response. Answer C is correct. ERM effectiveness review (A) is Review and Revision. Mission and values (B) are Governance and Culture. Stakeholder communication (D) is Information, Communication, and Reporting.
Under COSO ERM, which of the following best describes 'inherent risk'?
Explanation: Inherent risk is the raw, uncontrolled risk level absent any management actions. Answer D is correct. Residual risk (A) is what remains after responses. Internal audit is a control function, not a risk source (B). Transferred risk (C) is a specific risk response outcome.
A manufacturer qualifies a second supplier to reduce supply chain disruption risk. Under COSO ERM, this response is classified as:
Explanation: Qualifying a second supplier reduces the likelihood and/or impact of supply chain disruption - a risk reduction (mitigation) response. Answer B is correct. Accept (A) means taking no action. Avoid (C) would mean exiting the activity entirely. Transfer (D) shifts financial consequences to another party.
An organization maintains a risk register with identified risks, likelihood, impact, current controls, and risk owners. In COSO ERM, maintaining this register primarily supports which component?
Explanation: A risk register is the primary tool in the Performance component, documenting and prioritizing risks. Answer A is correct. While it may support governance (B), review (C), and reporting (D), its primary purpose is in the Performance component's risk identification and assessment activities.
Under COSO ERM, a 'key risk indicator' (KRI) is best described as:
Explanation: KRIs are forward-looking metrics that signal when risk levels are changing, enabling proactive management before tolerance is breached. Answer A is correct. Solvency ratios (B) are financial metrics. Control test results (C) are key control indicators. Benchmarks (D) are comparative measures, not KRIs.
The five components of COSO ERM 2017 in order are:
Explanation: The five COSO ERM 2017 components are: Governance and Culture, Strategy and Objective-Setting, Performance, Review and Revision, and Information, Communication, and Reporting. Answer D is correct. Answer A lists COSO ICIF components. Answer B is the NIST Cybersecurity Framework. Answer C is a supply chain framework.
A risk has low likelihood but could result in significant reputational damage. Which response is most appropriate under COSO ERM?
Explanation: Reputational risks with significant impact warrant contingency planning and monitoring, even at low likelihood, because reputational damage can be severe and difficult to reverse. Answer B is correct. Accepting without response (A) is inappropriate for high-impact risks. Immediately ceasing activities (C) may be disproportionate. Reputational risk cannot be fully transferred (D).
A company exits a high-risk market segment entirely to eliminate associated risks. Under COSO ERM, this response is classified as:
Explanation: Exiting a business activity to eliminate risk exposure is the Avoid response strategy. Answer C is correct. Transfer (A) shifts risk to another party. Reduce (B) lowers likelihood or impact. Accept (D) takes no action.
Under COSO ERM, the concept of 'portfolio view of risk' means that:
Explanation: A portfolio view requires assessing how individual risks interact and combine enterprise-wide, since collectively risks may exceed acceptable levels even when each appears manageable in isolation. Answer D is correct. The view is enterprise-wide, not IT-only (A). It requires cross-unit coordination (B). It encompasses all risk types (C).
Under COSO ERM, the 'Information, Communication, and Reporting' component supports the other components primarily by:
Explanation: The Information, Communication, and Reporting component ensures risk-relevant data is captured and communicated across the organization so stakeholders can fulfill risk management responsibilities. Answer B is correct. Control design and testing (A) is a Control Activities function. Risk appetite (C) is Governance and Culture. Risk identification and assessment (D) is the Performance component.
The COSO Enterprise Risk Management (ERM) framework is primarily designed to:
Explanation: The COSO ERM framework provides a structured approach for organizations to manage uncertainty and risk in pursuit of their objectives. Answer B is correct. Encryption standards (A), accounting standards (C), and IT infrastructure standards (D) are outside the scope of the COSO ERM framework.
An organization's board reviews and approves the risk appetite statement annually. Under COSO ERM, this falls within which component?
Explanation: Board oversight of risk appetite is part of the Governance and Culture component, which addresses board roles, management structure, and cultural expectations around risk. Answer B is correct. Risk Assessment (A) involves analyzing risks. Strategy and Objective-Setting (C) involves applying risk appetite. Review and Revision (D) involves monitoring performance.
A risk has very high potential impact but very low likelihood. Under COSO ERM, the most appropriate initial response is typically to:
Explanation: A high-impact, low-likelihood risk warrants monitoring and contingency planning. The high impact means consequences could be severe. Answer C is correct. Extensive controls immediately (A) may not be cost-effective. Automatic transfer (B) ignores needed analysis. Removing from the register (D) is inappropriate for high-impact risks.
The COSO ERM 2017 framework introduced which significant enhancement compared to the 2004 version?
Explanation: The 2017 update strengthened the connection between ERM, strategy formulation, and performance management. Answer C is correct. Risk response categories were not reduced (A). Board oversight was retained and strengthened (B). Zero-risk tolerance was not introduced (D).
The 'Review and Revision' component of COSO ERM 2017 is primarily concerned with:
Explanation: Review and Revision involves monitoring ERM performance, assessing changes in business context, and revising the framework to improve effectiveness. Answer D is correct. Identifying new risks (A) is Performance. Setting risk appetite (B) is Governance and Culture. Designing controls (C) is also Performance.