CPA Quiz: Apply Coso Erm Framework
20 questions · exam conditions
0:00
Apply Coso Erm FrameworkQuestion 1 of 20

Enterprise risk is within appetite, but one business unit exceeds its risk tolerance. What action best fits COSO ERM?

No action is needed overall
Investigate that unit's risk
Raise the risk appetite
Ignore, since appetite is met
← Back to quizzes

CPA Quiz

CPA Quiz: Apply Coso Erm Framework

Practice Apply Coso Erm Framework in CPA with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.

What this quiz covers

This quiz focuses on Apply Coso Erm Framework, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA.

How to use this quiz

Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.

All questions

Question 1

Enterprise risk is within appetite, but one business unit exceeds its risk tolerance. What action best fits COSO ERM?

  1. No action is needed overall
  2. Investigate that unit's risk (correct answer)
  3. Raise the risk appetite
  4. Ignore, since appetite is met
Explanation: Risk tolerance defines acceptable variation at the business-unit level, so exceeding it is a trigger for management action even when enterprise risk stays within appetite. You shouldn't ignore the breach or raise appetite to mask it. The tempting error is choosing no action because overall appetite is met, but unit-level tolerance is still a control limit that requires investigation.

Question 2

Residual vendor risk exceeds risk appetite after a mitigation; other responses exist. What next?

  1. Accept the residual risk
  2. Choose another risk response (correct answer)
  3. Stop all related operations
  4. Raise the risk appetite
Explanation: When residual risk still exceeds your risk appetite, accepting it is not viable because it violates your threshold. Since other responses exist, you should select a different risk response to bring residual risk within appetite. Raising appetite just to match the risk is backwards, and stopping operations is too drastic if other options remain.

Question 3

Current risk is $1M; risk appetite is $2M; capacity is $5M. Adding $0.5M of risk is:

  1. Approve; within appetite only
  2. Approve; within capacity only
  3. Approve; within both limits (correct answer)
  4. Reject; exceeds the limits
Explanation: Your current risk rises from 1M to 1.5M after adding 0.5M. Since 1.5M is under the 2M appetite and under the 5M capacity, the addition is within both limits. The tempting error is choosing 'within appetite only' because you focus on one threshold, but checking capacity gives the same approve result here.

Question 4

Supplier terms changed, but process risks were not reassessed. Which ERM process was neglected?

  1. Governance and culture
  2. Strategy and objective-setting
  3. Communication and reporting
  4. Review and revision of risks (correct answer)
Explanation: A change in supplier terms alters your risk exposure, so the risk assessment must be revisited to keep it current. Review and revision of risks is the ERM process that catches changed conditions and updates priorities. Communication and reporting is tempting because the new terms weren't communicated, but the failure was failing to reassess the risks themselves, not failing to report them.

Question 5

Impact is $500,000; a control cuts likelihood from 40% to 10%. Residual expected risk is?

  1. $50,000 (correct answer)
  2. $150,000
  3. $200,000
  4. $500,000
Explanation: Multiply impact by the remaining likelihood: 500,000 times 0.10 = 50,000. The control reduces likelihood from 40% to 10%, so residual expected risk is $50,000. The tempting $200,000 is the expected loss before the control, not after.

Question 6

In the context of COSO ERM, risk appetite is best defined as:

  1. The maximum financial loss the organization can sustain before becoming insolvent.
  2. The specific risk events that management has identified as possible.
  3. The amount and type of risk an organization is willing to accept in pursuit of its objectives. (correct answer)
  4. The level of risk remaining after controls have been applied.
Explanation: Risk appetite represents the organization's willingness to accept risk in pursuit of value creation. It reflects strategy and guides risk tolerance decisions. Answer C is correct. Maximum financial loss (A) describes risk capacity. Identified risk events (B) describe a risk inventory. Risk after controls (D) describes residual risk.

Question 7

The 'Performance' component of COSO ERM 2017 primarily involves:

  1. Reviewing whether the ERM framework itself is operating effectively.
  2. Setting the organization's mission, vision, and core values.
  3. Identifying, assessing, prioritizing, and responding to risks that affect the achievement of strategy and business objectives. (correct answer)
  4. Communicating risk information to internal and external stakeholders.
Explanation: The Performance component covers the core risk management process: identification, assessment, prioritization, and response. Answer C is correct. ERM effectiveness review (A) is Review and Revision. Mission and values (B) are Governance and Culture. Stakeholder communication (D) is Information, Communication, and Reporting.

Question 8

An organization maintains a risk register with identified risks, likelihood, impact, current controls, and risk owners. In COSO ERM, maintaining this register primarily supports which component?

  1. Performance - specifically risk identification, assessment, and prioritization. (correct answer)
  2. Governance and Culture - by establishing accountability for risks.
  3. Review and Revision - by providing historical data for trend analysis.
  4. Information, Communication, and Reporting - by distributing risk data to stakeholders.
Explanation: A risk register is the primary tool in the Performance component, documenting and prioritizing risks. Answer A is correct. While it may support governance (B), review (C), and reporting (D), its primary purpose is in the Performance component's risk identification and assessment activities.

Question 9

Under COSO ERM, a 'key risk indicator' (KRI) is best described as:

  1. A metric that provides early warning when a risk is increasing or approaching the risk tolerance threshold. (correct answer)
  2. A financial ratio used to assess an organization's solvency.
  3. A control test result indicating whether a specific control is operating effectively.
  4. A benchmark used to compare the organization's risk profile to industry peers.
Explanation: KRIs are forward-looking metrics that signal when risk levels are changing, enabling proactive management before tolerance is breached. Answer A is correct. Solvency ratios (B) are financial metrics. Control test results (C) are key control indicators. Benchmarks (D) are comparative measures, not KRIs.

Question 10

A risk has low likelihood but could result in significant reputational damage. Which response is most appropriate under COSO ERM?

  1. Accept the risk without any response since likelihood is low.
  2. Develop a crisis communication plan and monitor the risk given its potential reputational impact. (correct answer)
  3. Avoid the risk by ceasing all related business activities immediately.
  4. Transfer all reputational risk through a contractual indemnification clause.
Explanation: Reputational risks with significant impact warrant contingency planning and monitoring, even at low likelihood, because reputational damage can be severe and difficult to reverse. Answer B is correct. Accepting without response (A) is inappropriate for high-impact risks. Immediately ceasing activities (C) may be disproportionate. Reputational risk cannot be fully transferred (D).

Question 11

A company exits a high-risk market segment entirely to eliminate associated risks. Under COSO ERM, this response is classified as:

  1. Transfer
  2. Reduce
  3. Avoid (correct answer)
  4. Accept
Explanation: Exiting a business activity to eliminate risk exposure is the Avoid response strategy. Answer C is correct. Transfer (A) shifts risk to another party. Reduce (B) lowers likelihood or impact. Accept (D) takes no action.

Question 12

Under COSO ERM, the 'Information, Communication, and Reporting' component supports the other components primarily by:

  1. Designing and testing the effectiveness of key internal controls.
  2. Ensuring relevant risk information flows to all levels of the organization to enable informed decision-making. (correct answer)
  3. Setting the organization's risk appetite and tolerance thresholds.
  4. Identifying and assessing risks across all business units.
Explanation: The Information, Communication, and Reporting component ensures risk-relevant data is captured and communicated across the organization so stakeholders can fulfill risk management responsibilities. Answer B is correct. Control design and testing (A) is a Control Activities function. Risk appetite (C) is Governance and Culture. Risk identification and assessment (D) is the Performance component.

Question 13

An organization's board reviews and approves the risk appetite statement annually. Under COSO ERM, this falls within which component?

  1. Risk Assessment
  2. Governance and Culture (correct answer)
  3. Strategy and Objective-Setting
  4. Review and Revision
Explanation: Board oversight of risk appetite is part of the Governance and Culture component, which addresses board roles, management structure, and cultural expectations around risk. Answer B is correct. Risk Assessment (A) involves analyzing risks. Strategy and Objective-Setting (C) involves applying risk appetite. Review and Revision (D) involves monitoring performance.

Question 14

The COSO ERM 2017 framework introduced which significant enhancement compared to the 2004 version?

  1. Reduced the number of risk response categories from five to two.
  2. Eliminated the role of the board of directors in risk oversight.
  3. Greater emphasis on linking ERM to strategy-setting and the relationship between risk and performance. (correct answer)
  4. Required all organizations to adopt a zero-risk tolerance policy.
Explanation: The 2017 update strengthened the connection between ERM, strategy formulation, and performance management. Answer C is correct. Risk response categories were not reduced (A). Board oversight was retained and strengthened (B). Zero-risk tolerance was not introduced (D).

Question 15

Under the COSO ERM framework, which of the following best describes 'residual risk'?

  1. The risk identified during an initial risk assessment before any analysis.
  2. Risks arising from external environmental factors beyond management's control.
  3. The aggregate of all risks across the organization's business units.
  4. The risk remaining after management has implemented responses to reduce inherent risk. (correct answer)
Explanation: Residual risk is what remains after risk responses have been applied to inherent risk. Answer D is correct. Preliminary identified risk (A) is closer to inherent risk. External environmental factors (B) describe a source of risk. Portfolio-level aggregate risk (C) is a distinct concept.

Question 16

Under COSO ERM, which of the following is an example of a risk transfer response strategy?

  1. Purchasing insurance to shift the financial impact of a potential loss to a third party. (correct answer)
  2. Identifying all risks that could affect the achievement of organizational objectives.
  3. Setting the organization's overall risk appetite.
  4. Reporting risk information to the board of directors.
Explanation: Risk transfer - such as purchasing insurance - is one of the five risk response strategies under COSO ERM 2017 (avoid, accept, reduce, share/transfer, and pursue). Answer A is correct. Identifying risks (B) is part of Risk Assessment. Setting risk appetite (C) is Governance and Culture. Reporting to the board (D) is Information, Communication, and Reporting.

Question 17

A risk that falls within an organization's risk tolerance and requires no immediate action is best described under COSO ERM as:

  1. An inherent risk requiring additional controls.
  2. A key risk indicator requiring escalation.
  3. A risk that must be transferred to a third party.
  4. An accepted risk that is monitored but requires no additional response. (correct answer)
Explanation: Under COSO ERM, 'accept' is a valid risk response for risks within established tolerance. No additional action is required beyond monitoring. Answer D is correct. Inherent risks requiring controls (A) have not been assessed against tolerance. KRI escalation (B) implies the risk is moving outside tolerance. Transfer (C) is an active response.

Question 18

Under COSO ERM, which of the following best describes 'inherent risk'?

  1. Risk that remains after management implements its risk response strategies.
  2. Risk that arises from the organization's internal audit function.
  3. Risk that is transferred to a third party through insurance or contracts.
  4. The risk level existing before management applies any controls or risk responses. (correct answer)
Explanation: Inherent risk is the raw, uncontrolled risk level absent any management actions. Answer D is correct. Residual risk (A) is what remains after responses. Internal audit is a control function, not a risk source (B). Transferred risk (C) is a specific risk response outcome.

Question 19

A manufacturer qualifies a second supplier to reduce supply chain disruption risk. Under COSO ERM, this response is classified as:

  1. Accept
  2. Reduce (Mitigate) (correct answer)
  3. Avoid
  4. Transfer
Explanation: Qualifying a second supplier reduces the likelihood and/or impact of supply chain disruption - a risk reduction (mitigation) response. Answer B is correct. Accept (A) means taking no action. Avoid (C) would mean exiting the activity entirely. Transfer (D) shifts financial consequences to another party.

Question 20

Which of the following scenarios represents a failure in the 'Strategy and Objective-Setting' component of COSO ERM?

  1. An organization pursues an aggressive growth strategy without considering how the associated risks align with its stated risk appetite. (correct answer)
  2. Management fails to monitor residual risk levels against established thresholds.
  3. The internal audit function does not test key controls on a timely basis.
  4. Risk information is not effectively communicated to frontline employees.
Explanation: The Strategy and Objective-Setting component requires risk appetite to be considered during strategy development. Pursuing a strategy without assessing its risk implications is a failure here. Answer A is correct. Monitoring residual risks (B) is Review and Revision. Control testing (C) is a Control Activities issue. Communication failures (D) are Information, Communication, and Reporting.