RIMS-CRMP
Complete Practice Question Bank
Certified Risk Management Professional · 50 Questions with Answers & Rationales
C O M P RE H E N S I V E C OV E RAGE :
ERM · Risk Governance · Risk Analysis · Risk Appetite
— Maturity · Resilience · Transfer · Frameworks
Edition 1 · July 2026 · Complete CRMP Exam Preparation
★★★★★
Prepare · Pr act ice · Pa ss
Excellence in Risk Management Education
,RIMS-CRMP Q1-16 CORE ERM CONCEPTS
Questions 1–16: Core ERM Concepts, Frameworks &
Governance
1 Enterprise Risk Management (ERM) is best defined as:
A A strategic discipline that supports the achievement of an organization's objectives by
addressing the full spectrum of its risk and managing the combined impact of those risks as an
interrelated risk portfolio
B A compliance function focused solely on regulatory requirements
C The process of purchasing insurance to cover all organizational losses
D A financial audit designed to identify fraud and operational errors
CORRECT ANSWER
A — Strategic discipline managing the full spectrum of risk as an interrelated
portfolio
RATIONALE
ERM is fundamentally a strategic discipline, not merely a compliance or insurance function. It
supports organizational objectives by considering the full range of risks — strategic, operational,
financial, and hazard — and understanding how these risks interact. The key differentiator of
ERM from traditional risk management is its treatment of risks as an interrelated portfolio rather
than as isolated events managed in silos. This holistic approach enables organizations to identify
risk concentrations, correlations, and diversification benefits that would otherwise remain
hidden.
,2 Corporate governance in the context of risk management refers to:
A The system of rules, practices, and processes by which a company is directed and controlled,
establishing the framework for risk oversight
B The daily operational decisions made by middle management
C The marketing strategy used to promote the company's brand
D The technology systems used to monitor financial transactions
CORRECT ANSWER
A — System of rules and practices directing and controlling the organization
RATIONALE
Corporate governance establishes the overarching framework within which risk management
operates. It defines the roles and responsibilities of the board of directors, executive management,
and oversight committees in directing and controlling the organization. Effective governance
ensures that risk appetite is set at the board level, that management accountability for risk is
clearly defined, and that risk information flows appropriately to decision-makers at all levels.
3 Risk appetite is defined as:
A The total exposed amount that an organization wishes to undertake on the basis of risk-return
trade-offs for one or more desired and expected outcomes
B The specific operational limits placed on individual business units
C The maximum dollar amount of insurance coverage purchased annually
D The number of risk incidents reported in the previous quarter
CORRECT ANSWER
A — Total exposed amount based on risk-return trade-offs
RATIONALE
Risk appetite is a strategic-level concept that expresses how much risk the organization is willing
to accept in pursuit of value creation. It is not a set of operational limits (those are risk tolerances)
but rather a broad statement of the organization's willingness to accept uncertainty. Risk appetite
guides decisions about which opportunities to pursue, which risks to mitigate, and how
resources should be allocated across the enterprise.
, 4 Risk tolerance differs from risk appetite in that risk tolerance:
A Operationalizes risk appetite by establishing specific, measurable boundaries for acceptable
variation from expected outcomes
B Is set at the board level and never changes
C Applies only to financial risks and not to operational risks
D Replaces the need for risk appetite statements entirely
CORRECT ANSWER
A — Establishes specific, measurable boundaries for acceptable variation
RATIONALE
While risk appetite provides the broad strategic direction for risk-taking, risk tolerance translates
that direction into concrete, measurable parameters. Tolerances may be expressed as specific loss
limits, variance thresholds, or key risk indicator boundaries. They provide the operational
guidance that business units and risk owners need to make day-to-day decisions that align with
the organization's overall risk philosophy.