1. What is the primary purpose of risk management in an organisation?
A. To eliminate every possible risk
B. To identify, assess, and manage uncertainty affecting objectives
C. To increase the number of organisational policies
D. To transfer all risks to insurers
Answer: B
Rationale: Risk management involves identifying and assessing uncertainties and implementing
appropriate responses to support the achievement of organisational objectives.
2. Which of the following best describes risk?
A. A guaranteed financial loss
B. The effect of uncertainty on objectives
C. An event that has already occurred
D. A control implemented by management
Answer: B
Rationale: Risk is generally associated with uncertainty and its potential effect, whether positive
or negative, on the achievement of objectives.
3. Risk identification should ideally occur:
A. Only after a loss occurs
B. Continuously throughout organisational activities
C. Once every ten years
D. Only during external audits
Answer: B
,Rationale: Risks can change as internal and external conditions change, so risk identification
should be an ongoing process.
4. Which two factors are commonly considered when assessing a risk?
A. Salary and experience
B. Likelihood and impact
C. Profit and taxation
D. Policy and procedure
Answer: B
Rationale: Risk assessments commonly evaluate the likelihood that an event will occur and the
potential impact if it does.
5. A risk with a high likelihood and high impact would generally require:
A. Immediate attention and strong management action
B. No monitoring
C. Automatic acceptance
D. Removal from the risk register
Answer: A
Rationale: Risks that are both highly likely and potentially severe normally receive high priority.
6. What is a risk register?
A. A list of employee salaries
B. A document recording identified risks and their management
C. A register of company assets only
D. A financial statement
Answer: B
Rationale: A risk register records risks, their causes, consequences, ratings, controls, owners,
and treatment actions.
, 7. Risk avoidance involves:
A. Accepting a risk without action
B. Eliminating the activity that creates the risk
C. Monitoring a risk only
D. Increasing the level of exposure
Answer: B
Rationale: Avoidance means deciding not to undertake an activity or removing the source of
exposure where practical.
8. Risk reduction involves:
A. Increasing uncertainty
B. Implementing controls to reduce likelihood or impact
C. Ignoring the risk
D. Recording the risk without action
Answer: B
Rationale: Risk reduction uses controls and other measures to decrease either the probability or
consequences of a risk.
9. Risk transfer commonly occurs through:
A. Insurance or contractual arrangements
B. Ignoring the risk
C. Eliminating all controls
D. Increasing the likelihood of failure
Answer: A
Rationale: Insurance and contracts can transfer certain financial or operational consequences
to another party.
10. Risk acceptance is most appropriate when:
A. The organisation understands the risk and decides it is within tolerance
B. Management does not know about the risk