1. Which of the following is an example of a strategic risk?
A. Failure of information technology systems
B. A downturn in market conditions due to poor strategic decisions
C. A fire in the organization‟s warehouse
D. Legal non-compliance fines
Answer: B) A downturn in market conditions due to poor strategic
decisions
Rationale: Strategic risks arise from decisions that affect the long-term
direction of the organization, such as poor planning or misjudging
market trends.
2. Which of the following best defines "risk likelihood"?
A. The financial impact of a risk occurring
B. The probability that a risk event will occur
C. The number of risks an organization faces
D. The extent of damage caused by a risk
Answer: B) The probability that a risk event will occur
Rationale: Risk likelihood refers to the probability that a particular risk
will occur within a defined time frame.
,3. Which of the following is an example of a risk that could be managed
through "risk retention"?
A. Liability insurance for property damage
B. Transferring the risk to an external consultant
C. Accepting the risk without mitigating action due to low impact
D. Avoiding all risks through changes to business strategy
Answer: C) Accepting the risk without mitigating action due to low
impact
Rationale: Risk retention involves accepting the potential consequences
of a risk, often when the cost of mitigation is greater than the potential
impact.
4. What is a key aspect of "enterprise risk management" (ERM)?
A. It focuses only on financial risks within an organization
B. It integrates risk management across all levels and departments of
the organization
C. It ignores external risks and focuses solely on internal operations
D. It requires only the compliance department to manage risks
Answer: B) It integrates risk management across all levels and
departments of the organization
Rationale: ERM takes a holistic approach by managing risks across all
departments, ensuring that all types of risks, both internal and
external, are addressed in a coordinated manner.
, 5. What does the term „risk mitigation‟ primarily focus on?
A. Increasing the likelihood of risks occurring
B. Reducing the impact or likelihood of identified risks
C. Ignoring minor risks
D. Accepting all risks without intervention
Answer: B) Reducing the impact or likelihood of identified risks
Rationale: Risk mitigation involves taking actions to reduce either the
probability of a risk occurring or its potential impact on the
organization.
6. Which of the following would most likely be considered a
"compliance risk"?
A. A delay in product delivery
B. A change in regulations that affects the organization‟s operations
C. A fluctuation in stock prices
D. A breakdown in IT systems
Answer: B) A change in regulations that affects the organization‟s
operations
Rationale: Compliance risks arise from the possibility of non-
compliance with laws, regulations, and policies that can impact the
organization.
7. Which of the following is a key characteristic of operational risk?
A. Failure of information technology systems
B. A downturn in market conditions due to poor strategic decisions
C. A fire in the organization‟s warehouse
D. Legal non-compliance fines
Answer: B) A downturn in market conditions due to poor strategic
decisions
Rationale: Strategic risks arise from decisions that affect the long-term
direction of the organization, such as poor planning or misjudging
market trends.
2. Which of the following best defines "risk likelihood"?
A. The financial impact of a risk occurring
B. The probability that a risk event will occur
C. The number of risks an organization faces
D. The extent of damage caused by a risk
Answer: B) The probability that a risk event will occur
Rationale: Risk likelihood refers to the probability that a particular risk
will occur within a defined time frame.
,3. Which of the following is an example of a risk that could be managed
through "risk retention"?
A. Liability insurance for property damage
B. Transferring the risk to an external consultant
C. Accepting the risk without mitigating action due to low impact
D. Avoiding all risks through changes to business strategy
Answer: C) Accepting the risk without mitigating action due to low
impact
Rationale: Risk retention involves accepting the potential consequences
of a risk, often when the cost of mitigation is greater than the potential
impact.
4. What is a key aspect of "enterprise risk management" (ERM)?
A. It focuses only on financial risks within an organization
B. It integrates risk management across all levels and departments of
the organization
C. It ignores external risks and focuses solely on internal operations
D. It requires only the compliance department to manage risks
Answer: B) It integrates risk management across all levels and
departments of the organization
Rationale: ERM takes a holistic approach by managing risks across all
departments, ensuring that all types of risks, both internal and
external, are addressed in a coordinated manner.
, 5. What does the term „risk mitigation‟ primarily focus on?
A. Increasing the likelihood of risks occurring
B. Reducing the impact or likelihood of identified risks
C. Ignoring minor risks
D. Accepting all risks without intervention
Answer: B) Reducing the impact or likelihood of identified risks
Rationale: Risk mitigation involves taking actions to reduce either the
probability of a risk occurring or its potential impact on the
organization.
6. Which of the following would most likely be considered a
"compliance risk"?
A. A delay in product delivery
B. A change in regulations that affects the organization‟s operations
C. A fluctuation in stock prices
D. A breakdown in IT systems
Answer: B) A change in regulations that affects the organization‟s
operations
Rationale: Compliance risks arise from the possibility of non-
compliance with laws, regulations, and policies that can impact the
organization.
7. Which of the following is a key characteristic of operational risk?