US CMA Part 2 ยท Chapter 7
Enterprise risk management MCQs with Answers
15 multiple-choice questions on Enterprise risk management for US CMA Part 2 Strategic Financial Management. Try each one before revealing the answer and explanation.
Practise this chapter interactivelyQuestion 1
A treasury portfolio is worth $20,000,000. Its daily returns are normally distributed with a mean of zero and a standard deviation of 1.2%. Using a one-tailed z-value of 1.65 for 95% confidence, what is the one-day 95% value at risk (VaR)?
- A) $470,400
- B) $559,200
- C) $396,000
- D) $240,000
Show answer & explanation
Answer: C) $396,000
VaR = z x standard deviation x portfolio value = 1.65 x 1.2% x $20,000,000 = $396,000. There is a 5% chance of losing more than $396,000 in one day. Using 2.33 gives 99% VaR ($559,200), and 1.96 is the two-tailed 95% value.
Question 2
A flood that destroys a company's main distribution center is an example of which category of risk?
- A) Financial risk
- B) Market risk
- C) Hazard risk
- D) Strategic risk
Show answer & explanation
Answer: C) Hazard risk
Hazard risks arise from natural events, accidents and other perils such as fire, flood, theft or injury, and are often insurable. Financial risks relate to interest rates, exchange rates, credit and liquidity; strategic risks arise from business strategy and the competitive environment.
Question 3
A traditional film camera manufacturer loses most of its market after customers switch to smartphone photography. This is primarily an example of:
- A) Credit risk
- B) Operational risk
- C) Hazard risk
- D) Strategic risk
Show answer & explanation
Answer: D) Strategic risk
Strategic risk arises from the choice and execution of strategy and from shifts in the business environment, such as technological change, competitor actions or changing customer preferences. Operational risk relates to failures of internal processes, people and systems, and credit risk to counterparties failing to pay.
Question 4
Which statement best distinguishes risk appetite from risk tolerance?
- A) Risk appetite applies only to financial risks, whereas risk tolerance applies only to operational risks
- B) Risk appetite is set by front-line managers for individual transactions; risk tolerance is set by the board for the whole organization
- C) Risk appetite is the broad amount of risk an organization is willing to accept in pursuit of value; risk tolerance is the acceptable variation in performance around specific objectives
- D) Risk appetite is the risk remaining after controls; risk tolerance is the risk before any controls
Show answer & explanation
Answer: C) Risk appetite is the broad amount of risk an organization is willing to accept in pursuit of value; risk tolerance is the acceptable variation in performance around specific objectives
Risk appetite is a high-level, organization-wide statement, set by management with board oversight, of the types and amount of risk the entity is willing to accept in pursuit of its mission and value. Risk tolerance (the acceptable variation in performance) is more granular and relates to particular objectives or metrics. Risk before and after controls describes inherent and residual risk.
Question 5
A company purchases a commercial liability insurance policy to cover potential customer injury claims. Which risk response does this represent?
- A) Accepting the risk
- B) Exploiting the risk
- C) Avoiding the risk
- D) Sharing (transferring) the risk
Show answer & explanation
Answer: D) Sharing (transferring) the risk
Buying insurance shares or transfers the financial consequences of a risk to another party in exchange for a premium. Avoidance means exiting the activity that gives rise to the risk, acceptance means taking no action beyond monitoring, and reduction means using controls to lower likelihood or impact.
Question 6
A risk assessment rates the risk of unauthorized wire transfers as high before considering controls. After dual authorization and daily bank reconciliations are introduced, the risk is rated low. The low rating is the:
- A) Risk appetite
- B) Inherent risk
- C) Residual risk
- D) Detection risk
Show answer & explanation
Answer: C) Residual risk
Inherent risk is the risk in the absence of any management actions or controls. Residual risk is the risk that remains after management's responses, such as controls, have been applied. Management compares residual risk with risk appetite to decide whether further action is needed.
Question 7
Which of the following is NOT one of the five components of the COSO Enterprise Risk Management - Integrating with Strategy and Performance framework?
- A) Performance
- B) Review and revision
- C) Governance and culture
- D) Control activities
Show answer & explanation
Answer: D) Control activities
The COSO ERM framework (2017) has five components: Governance and Culture; Strategy and Objective-Setting; Performance; Review and Revision; and Information, Communication, and Reporting. Control activities is a component of the separate COSO Internal Control - Integrated Framework.
Question 8
Ormsby Chemicals estimates a 4% annual probability of an environmental spill that would cost $2,500,000. What is the expected annual loss from this risk?
- A) $1,000,000
- B) $2,400,000
- C) $2,500,000
- D) $100,000
Show answer & explanation
Answer: D) $100,000
Expected loss = probability x impact = 4% x $2,500,000 = $100,000. Comparing this figure with the annual cost of a risk response (for example an insurance premium) helps decide whether the response is cost-effective.
Question 9
In a risk heat map that plots likelihood against impact, which risks should generally receive the highest priority for management attention?
- A) Risks with high likelihood but low impact
- B) Risks with low likelihood and low impact
- C) Risks that have already been fully insured
- D) Risks with both high likelihood and high impact
Show answer & explanation
Answer: D) Risks with both high likelihood and high impact
A heat map shows each risk's assessed likelihood and impact. Those in the high-likelihood, high-impact zone pose the greatest threat to objectives and are prioritized for response. Low-impact frequent risks may be handled through routine controls, while low-likelihood, high-impact risks often call for contingency plans or insurance.
Question 10
Which of the following is the best example of a key risk indicator (KRI)?
- A) The historical cost of property, plant and equipment
- B) The number of shares authorized in the corporate charter
- C) A rising rate of employee turnover in the IT security team, monitored monthly
- D) Last year's audited net income
Show answer & explanation
Answer: C) A rising rate of employee turnover in the IT security team, monitored monthly
Key risk indicators are metrics, ideally forward-looking, that provide early warning of increasing exposure to a risk. Rising turnover among security staff may signal greater cybersecurity risk before an incident occurs. Historical results and static balances describe past outcomes rather than changing risk exposure.
Question 11
As part of its business continuity plan, a bank maintains a fully equipped backup data center with current copies of all systems and data, ready to take over operations within minutes. This backup facility is a:
- A) Warm site
- B) Cold site
- C) Hot site
- D) Reciprocal agreement
Show answer & explanation
Answer: C) Hot site
A hot site is fully configured with hardware, software and up-to-date data, enabling near-immediate recovery. A cold site provides space and utilities but no equipment, and a warm site has some equipment but needs time and data restoration. A reciprocal agreement relies on another organization's facilities.
Question 12
Pendle Logistics faces a 10% annual chance of a cyberattack causing a $1,000,000 loss. A security upgrade costing $60,000 per year would reduce the probability to 3%. What is the net annual benefit (cost) of the upgrade based on expected values?
- A) Net cost of $30,000
- B) Net cost of $25,000
- C) Net benefit of $10,000
- D) Net benefit of $40,000
Show answer & explanation
Answer: C) Net benefit of $10,000
Expected loss without upgrade = 10% x $1,000,000 = $100,000. With upgrade = 3% x $1,000,000 = $30,000. Reduction in expected loss = $70,000. Net benefit = $70,000 - $60,000 = $10,000. Comparing the cost with the full original expected loss ($100,000) overstates the benefit because some risk remains.
Question 13
Which of the following is an example of operational risk?
- A) A decline in the value of foreign currency receivables
- B) A rise in market interest rates on floating-rate debt
- C) Losses caused by employees repeatedly keying incorrect prices into the billing system
- D) A competitor launching a superior product
Show answer & explanation
Answer: C) Losses caused by employees repeatedly keying incorrect prices into the billing system
Operational risk is the risk of loss from inadequate or failed internal processes, people and systems, or from external events. Data entry errors are a people and process failure. Currency and interest rate movements are financial (market) risks, and a competitor's product launch is a strategic risk.
Question 14
A company decides to withdraw entirely from a politically unstable country rather than continue operating there. This risk response is:
- A) Avoidance
- B) Acceptance
- C) Sharing
- D) Reduction
Show answer & explanation
Answer: A) Avoidance
Avoidance eliminates a risk by exiting or not undertaking the activity that creates it. It is appropriate when no other response brings the risk within the organization's risk appetite at an acceptable cost. Reduction lowers likelihood or impact, sharing transfers part of the risk, and acceptance retains it.
Question 15
Which of the following is a recognized limitation of value at risk (VaR) as a risk measure?
- A) It can only be calculated for a single asset, not a portfolio
- B) It does not indicate how large losses may be in the cases where the VaR threshold is exceeded
- C) It cannot be expressed in currency terms
- D) It ignores the probability of losses entirely
Show answer & explanation
Answer: B) It does not indicate how large losses may be in the cases where the VaR threshold is exceeded
VaR states the maximum loss expected at a given confidence level over a set period, in currency terms, and is commonly computed for portfolios. However, it says nothing about the size of losses in the tail beyond the threshold, and it often relies on normal distribution assumptions that understate extreme events. Measures such as conditional VaR (expected shortfall) and stress testing address this gap.
