Specialist CERLS Exam
Question 1. Which of the following best describes the shift from traditional siloed risk
management to enterprise‑wide risk leadership?
A) Isolating risk owners within functional departments
B) Centralizing all risk decisions in the finance team
C) Integrating risk considerations into strategic decision‑making across the organization
D) Delegating risk reporting solely to external auditors
Answer: C
Explanation: Enterprise‑wide risk leadership breaks down silos by embedding risk analysis in
strategy, operations, and governance, ensuring a holistic view rather than isolated pockets.
Question 2. In defining risk appetite, an organization primarily establishes:
A) The exact monetary loss it can tolerate each year
B) The qualitative and quantitative boundaries for acceptable risk taking aligned with its
capacity and objectives
C) The list of all possible threats it must eliminate
D) The number of risk managers it will hire
Answer: B
Explanation: Risk appetite sets the level of risk an organization is willing to accept, expressed in
both qualitative statements and quantitative limits, and aligns with strategic goals and capacity.
Question 3. How can risk be leveraged to create value for an organization?
A) By avoiding any new initiatives that involve uncertainty
B) By using risk assessments to identify opportunities for innovation and competitive advantage
C) By outsourcing all risky functions to third‑party vendors
D) By focusing solely on regulatory compliance
Answer: B
, AIIM Certified Enterprise Risk Leadership
Specialist CERLS Exam
Explanation: Treating risk as a source of insight enables firms to spot growth opportunities,
innovate, and differentiate, turning uncertainty into a strategic asset.
Question 4. Which cognitive bias most often leads executives to underestimate the probability
of rare, high‑impact events?
A) Confirmation bias
B) Availability heuristic
C) Overconfidence bias
D) Anchoring bias
Answer: B
Explanation: The availability heuristic causes people to judge the likelihood of events based on
how easily examples come to mind, leading to underestimation of rare “black‑swan” events.
Question 5. The board’s “credible challenge” function is intended to:
A) Approve every operational decision made by management
B) Provide independent, constructive questioning of risk‑related strategies and assumptions
C) Replace the role of the CRO in day‑to‑day risk oversight
D) Ensure the board meets its statutory filing deadlines
Answer: B
Explanation: Credible challenge involves the board rigorously interrogating management’s risk
assumptions and strategies to improve decision quality and governance.
Question 6. Which of the following is a primary responsibility of the Chief Risk Officer (CRO)?
A) Conducting all internal audits across finance, HR, and IT
B) Designing, implementing, and overseeing the enterprise risk management framework
C) Setting product pricing strategies
, AIIM Certified Enterprise Risk Leadership
Specialist CERLS Exam
D) Managing the organization’s marketing campaigns
Answer: B
Explanation: The CRO leads the ERM program, ensuring risk identification, assessment,
mitigation, and reporting across the enterprise.
Question 7. A Board Risk Committee typically focuses on:
A) Daily operational risk monitoring
B) High‑level risk oversight, policy approval, and alignment with strategy
C) Recruiting and onboarding new employees
D) Managing the organization’s social media presence
Answer: B
Explanation: The Board Risk Committee provides governance oversight, reviews risk policies,
and ensures risk management aligns with strategic objectives.
Question 8. Which principle of COSO ERM 2017 emphasizes the need to embed risk
considerations into strategic planning?
A) Governance and Culture
B) Strategy and Objective‑Setting
C) Performance
D) Review, Monitoring, and Reporting
Answer: B
Explanation: The “Strategy and Objective‑Setting” component ensures that risk is considered
when formulating strategy and setting objectives.
Question 9. To cultivate a risk‑aware culture across the “Three Lines of Defense,” an
organization should:
A) Issue a single annual risk memo from the CEO
, AIIM Certified Enterprise Risk Leadership
Specialist CERLS Exam
B) Provide ongoing training, clear communication, and incentives that reinforce risk‑responsible
behavior at all levels
C) Restrict risk information to senior leadership only
D) Eliminate the second line of defense to simplify reporting
Answer: B
Explanation: Continuous education, transparent communication, and aligned incentives embed
risk awareness throughout governance, management, and assurance functions.
Question 10. Which of the following is an effective method for preventing corporate fraud?
A) Rotating employees randomly without documentation
B) Implementing robust internal controls, whistle‑blower mechanisms, and ethical training
programs
C) Allowing unrestricted access to financial systems for all staff
D) Relying solely on external auditors for fraud detection
Answer: B
Explanation: Strong controls, a safe channel for reporting concerns, and a culture of ethics
collectively reduce fraud risk.
Question 11. How can performance‑based compensation influence risk‑taking behavior?
A) It has no impact on employee decisions
B) It can encourage excessive risk‑seeking if rewards are tied only to short‑term results
C) It always reduces risk‑taking by adding safeguards
D) It eliminates the need for risk monitoring
Answer: B
Explanation: Compensation linked only to short‑term outcomes may incentivize employees to
take undue risks to meet targets, potentially undermining risk controls.