WorksheetsChapter 4
Total questions: 18
Worksheet time: 9mins
According to COSO ERM, which of the following is not an inherent challenge that arises as part of establishing strategy and business objectives?
Ensuring culture is clearly articulated by the board
Possibility of strategy not aligning
Implications from the strategy chosen
Risk to achieving the strategy
According to COSO ERM, all of the following are elements of an organization’s internal environment except:
Setting organizational objectives.
Establishing risk appetite.
Assigning authority and responsibility.
Having predominantly independent directors on the board.
Which of the following external events will most likely impact a defense contractor that relies on large government contracts for its success?
Economic event
Natural environment event
Political event
Social event
Which of the following is not an example of a risk-sharing strategy?
Outsourcing a noncore, high-risk area
Selling a nonstrategic business unit
Hedging against interest rate fluctuations
Buying an insurance policy to protect against adverse weather
An organization tracks a website hosting anonymous blogs about its industry. Recently, anonymous posts have focused on potential legislation that could have a dramatic effect on this industry. Which of the following may create the greatest risk if this organization makes business decisions based on the information contained on this website?
Appropriateness of the information
Timeliness of the information
Accessibility of the information
Accuracy and reliability of the information
Which of the following risk management activities is out of sequence in terms of timing?
Identify, assess, and prioritize risks
Develop risk responses/treatments
Determine key organizational objectives
Monitor the effectiveness of risk responses/treatments
Who is responsible for implementing ERM?
The chief financial officer
The chief audit executive
The chief compliance officer
Management throughout the organization
Which of the following is not a potential value driver for implementing ERM?
Financial results will improve in the short run
There will be fewer surprises from year to year
There will be better information available to make risk decisions
An organization’s risk appetite can be aligned with strategic planning
Which of the following is the best reason for the CAE to consider the organization’s strategic plan in developing the annual internal audit plan?
To emphasize the importance of the internal audit function to the organization
To ensure that the internal audit plan will be approved by senior management
To make recommendations to improve the strategic plan
To ensure that the internal audit plan supports the overall business objectives.
When senior management accepts a level of residual risk that the CAE believes is unacceptable to the organization, the CAE should:
Report the unacceptable risk level immediately to the chair of the audit committee and the independent outside audit firm partner
Resign his or her position in the organization
Discuss the matter with knowledgeable members of senior management and, if not resolved, take it to the audit committee
Accept senior management’s position because it establishes the risk appetite for the organization
The CAE is asked to lead the enterprise risk assessment as part of an organization’s implementation of ERM. Which of the following would not be relevant with respect to protecting the internal audit function’s independence and the objectivity of its internal auditors?
A cross-section of management is involved in assessing the impact and likelihood of each risk
Risk owners are assigned responsibility for each key risk
A member of senior management presents the results of the risk assessment to the board and communicates that it represents the organization’s risk profile
The internal audit function obtains assistance from an outside consultant in the conduct of the formal risk assessment session
An internal audit engagement was included in the approved internal audit plan. This is considered a moderately high-risk audit based on the internal audit function’s risk model. It is currently on a two-year audit cycle. Which of the following will likely have the greatest impact on the scope and approach of the internal audit engagement?
The area being audited involves the processing of a high volume of transactions
Certain components of the process are outsourced
A new system was implemented during the year, which changed how the transactions are processed
The total dollars processed in this area are material
A manufacturing company has identified the following risk: “ Failure of employees to conduct required quality control procedures may result in a high level of customer return. “ To which type of objective does this risk most directly relate?
Strategic
Operations
Reporting
Compliance
A risk that a new competitor will significantly reduce the market share of an organization's product likely relates to which type of objective?
Strategic
Operations
Reporting
Compliance
When assessing the risk associated with an activity, an internal auditor should:
Determine how the risk should best be managed.
Provide assurance on the management of the risk.
Update the risk management process based on risk exposures.
Design controls to mitigate the identified risks.
One of the challenges of ERM in an organization that has a centralized structure is that:
It may be difficult to raise awareness of the impact of work actions on other employees or work areas
Employees in these structures are inherently less risk averse
Managers have less incentive to implement and monitor controls
Effective controls are more difficult to design, and consistent application is more difficult to achieve across the organization
The function of the chief risk officer is most effective when he or she:
Manages risk as a member of senior management.
Shares the management of risk with line management.
Shares the management of risk with the CAE.
Monitors risk as part of the ERM team.
Enterprise risk management:
Guarantees achievement of business objectives
Requires establishment of risk and control activities by internal auditors
Involves the identification of events with negative impacts on business objectives
Includes selection of best risk response for the organization
