Enterprise Risk Management
Professional Examination Practice Exam
2026 | 100 Questions & Answers with
Detailed Rationales | Complete
Enterprise Risk Management Exam Prep
& Study Guide
1. What is the primary objective of Enterprise Risk Management (ERM)?
A. Eliminate every risk facing the organization
B. Create and protect organizational value by managing risk
C. Transfer all risks to insurance companies
D. Focus only on financial risks
Answer: Create and protect organizational value by managing risk
Rationale: ERM is designed to identify, assess, respond to, and monitor risks in a
coordinated manner so that the organization can achieve its objectives while
protecting and creating value.
2. Which statement best describes enterprise risk?
A. A risk limited to one operational department
B. A risk that only affects financial reporting
C. A risk that can affect the organization's ability to achieve strategic and
,business objectives
D. A risk that can always be insured
Answer: A risk that can affect the organization's ability to achieve strategic and
business objectives
Rationale: Enterprise risks can arise across strategic, financial, operational,
compliance, technology, reputational, and other areas and may influence
achievement of organizational objectives.
3. Which component of ERM establishes the overall approach to managing
risk?
A. Risk treatment
B. Risk monitoring
C. Risk governance
D. Risk transfer
Answer: Risk governance
Rationale: Risk governance establishes accountability, authority, oversight,
policies, and structures for managing risk throughout the organization.
4. What is risk appetite?
A. The maximum amount of insurance purchased
B. The amount and type of risk an organization is willing to pursue or retain in
achieving its objectives
C. The amount of risk that has already occurred
D. The total number of identified risks
Answer: The amount and type of risk an organization is willing to pursue or
retain in achieving its objectives
Rationale: Risk appetite expresses the organization's willingness to accept risk in
pursuit of strategic and business objectives.
5. What is risk tolerance?
,A. The organization's mission statement
B. The acceptable level of variation around objectives or risk appetite
C. The total amount of risk eliminated
D. The organization's insurance limit
Answer: The acceptable level of variation around objectives or risk appetite
Rationale: Risk tolerance translates broader risk appetite into acceptable
boundaries for specific objectives, processes, or risk categories.
6. What is inherent risk?
A. Risk remaining after controls
B. Risk that has been insured
C. Risk existing before considering the effects of controls or other risk responses
D. Risk that has already caused a loss
Answer: Risk existing before considering the effects of controls or other risk
responses
Rationale: Inherent risk represents the exposure before controls, mitigations, or
other responses are considered.
7. What is residual risk?
A. Risk before controls
B. Risk remaining after risk responses and controls are considered
C. Risk that cannot be identified
D. Risk transferred to a regulator
Answer: Risk remaining after risk responses and controls are considered
Rationale: Residual risk is the exposure that remains after management
implements controls and other risk treatments.
8. Which risk response involves discontinuing an activity that creates
unacceptable exposure?
, A. Accept
B. Transfer
C. Reduce
D. Avoid
Answer: Avoid
Rationale: Risk avoidance eliminates the activity, process, product, or
circumstance that creates the risk.
9. Which response involves reducing the likelihood or impact of a risk?
A. Avoid
B. Reduce
C. Accept
D. Exploit
Answer: Reduce
Rationale: Risk reduction uses controls, safeguards, process changes, or other
measures to decrease the likelihood and/or impact of an adverse event.
10.What does risk transfer accomplish?
A. It eliminates the underlying risk
B. It shifts some or all of the financial or operational consequences to another
party
C. It guarantees that the risk will never occur
D. It removes management accountability
Answer: It shifts some or all of the financial or operational consequences to
another party
Rationale: Insurance, contractual arrangements, and outsourcing can transfer
certain consequences, although the organization may retain residual exposure
and accountability.
11.What is risk acceptance?