120 Practice Questions with Answers & Rationales
1. Which of the following best defines 'risk' according to ISO 31000?
A. The probability of a negative financial outcome occurring within a fiscal year
B. The effect of uncertainty on objectives
C. A hazard that must be insured against to protect organizational assets
D. The variance between budgeted and actual expenditures
Correct Answer: B. The effect of uncertainty on objectives
Rationale: ISO 31000 defines risk as 'the effect of uncertainty on objectives,' a
definition that is deliberately broad and covers both positive and negative deviations
from expected outcomes, not just financial or insurable hazards.
2. Under an enterprise risk management (ERM) approach, risk is primarily
viewed as:
A. A siloed concern managed independently by each business unit
B. An issue relevant only to the finance and insurance functions
C. A portfolio of interrelated exposures that should be managed holistically across
the organization
D. A static list of hazards reviewed once a year by internal audit
Correct Answer: C. A portfolio of interrelated exposures that should be managed
holistically across the organization
Rationale: ERM treats risk holistically, recognizing that risks across business units are
interconnected and should be aggregated and managed at the enterprise level rather
than in silos, enabling better prioritization and resource allocation.
,3. Which statement best describes 'risk appetite'?
A. The maximum amount of risk an organization can technically bear before
insolvency
B. The amount and type of risk an organization is willing to pursue or retain in order
to achieve its objectives
C. The specific numeric threshold used only for market risk exposures
D. The insurance premium budget approved by the board each year
Correct Answer: B. The amount and type of risk an organization is willing to
pursue or retain in order to achieve its objectives
Rationale: Risk appetite is a strategic, qualitative-to-quantitative statement of the
amount and type of risk an organization is willing to accept in pursuit of its objectives.
It is distinct from risk capacity (the maximum it could bear) and risk tolerance
(acceptable variation around specific objectives).
4. How does 'risk tolerance' differ from 'risk appetite'?
A. Risk tolerance is set by regulators while risk appetite is set by shareholders
B. Risk tolerance refers to the acceptable variation around specific objectives or
metrics, while risk appetite is the broader, strategic statement of risk-taking
willingness
C. There is no meaningful difference; the terms are interchangeable in every
framework
D. Risk tolerance applies only to hazard risks, while risk appetite applies only to
strategic risks
Correct Answer: B. Risk tolerance refers to the acceptable variation around
specific objectives or metrics, while risk appetite is the broader, strategic
statement of risk-taking willingness
Rationale: Risk appetite is the high-level, strategic amount of risk an entity is willing to
accept, while risk tolerance operationalizes that appetite into acceptable ranges of
variation for specific objectives, metrics, or risk categories.
,5. A risk management framework, as described in ISO 31000, primarily provides:
A. A detailed technical methodology for pricing insurance policies
B. The foundations and organizational arrangements for designing, implementing,
monitoring, and continually improving risk management
C. A checklist of mandatory controls for financial reporting
D. A legal contract between the risk manager and the board
Correct Answer: B. The foundations and organizational arrangements for
designing, implementing, monitoring, and continually improving risk
management
Rationale: The ISO 31000 framework is the set of foundational elements (leadership,
commitment, integration, design, implementation, evaluation, improvement) that
support embedding risk management throughout an organization; it is not itself a
technical or legal instrument.
6. Which of the following is the correct sequence of the core ISO 31000 risk
management process steps?
A. Communication and consultation; establishing context; risk assessment; risk
treatment; monitoring and review; recording and reporting (all supported
throughout)
B. Risk treatment; risk identification; risk financing; claims handling
C. Risk financing; risk transfer; risk retention; risk avoidance
D. Internal audit; external audit; board approval; disclosure
Correct Answer: A. Communication and consultation; establishing context; risk
assessment; risk treatment; monitoring and review; recording and reporting (all
supported throughout)
Rationale: ISO 31000's process comprises scope/context/criteria, risk assessment
(identification, analysis, evaluation), and risk treatment, with
communication/consultation and monitoring/review and recording/reporting operating
continuously throughout the process.
, 7. In the COSO ERM Framework (2017), risk management is best described as
being integrated with:
A. Only the internal audit function
B. Strategy and performance
C. Only regulatory compliance activities
D. Only the insurance procurement process
Correct Answer: B. Strategy and performance
Rationale: The COSO ERM Framework, 'Enterprise Risk Management—Integrating
with Strategy and Performance,' emphasizes that risk management should be
embedded in strategy-setting and performance management rather than treated as a
separate, compliance-only activity.
8. Which of the following best describes the role of the board of directors in risk
governance?
A. Executing day-to-day risk mitigation activities
B. Providing oversight of the risk management framework and holding management
accountable for its execution
C. Personally approving every individual insurance claim
D. Performing risk identification workshops with front-line staff
Correct Answer: B. Providing oversight of the risk management framework and
holding management accountable for its execution
Rationale: The board's role in risk governance is oversight: setting risk appetite,
approving the risk management framework/policy, and holding executive management
accountable for implementation, rather than performing operational risk activities itself.