The CA Hub
All US CMA Part 2 chapters

US CMA Part 2 ยท Chapter 7

Enterprise risk management MCQs with Answers

15 multiple-choice questions on Enterprise risk management for US CMA Part 2 Strategic Financial Management. Try each one before revealing the answer and explanation.

Practise this chapter interactively
  1. Question 1

    A treasury portfolio is worth $20,000,000. Its daily returns are normally distributed with a mean of zero and a standard deviation of 1.2%. Using a one-tailed z-value of 1.65 for 95% confidence, what is the one-day 95% value at risk (VaR)?

    • A) $470,400
    • B) $559,200
    • C) $396,000
    • D) $240,000
    Show answer & explanation

    Answer: C) $396,000

    VaR = z x standard deviation x portfolio value = 1.65 x 1.2% x $20,000,000 = $396,000. There is a 5% chance of losing more than $396,000 in one day. Using 2.33 gives 99% VaR ($559,200), and 1.96 is the two-tailed 95% value.

  2. Question 2

    A flood that destroys a company's main distribution center is an example of which category of risk?

    • A) Financial risk
    • B) Market risk
    • C) Hazard risk
    • D) Strategic risk
    Show answer & explanation

    Answer: C) Hazard risk

    Hazard risks arise from natural events, accidents and other perils such as fire, flood, theft or injury, and are often insurable. Financial risks relate to interest rates, exchange rates, credit and liquidity; strategic risks arise from business strategy and the competitive environment.

  3. Question 3

    A traditional film camera manufacturer loses most of its market after customers switch to smartphone photography. This is primarily an example of:

    • A) Credit risk
    • B) Operational risk
    • C) Hazard risk
    • D) Strategic risk
    Show answer & explanation

    Answer: D) Strategic risk

    Strategic risk arises from the choice and execution of strategy and from shifts in the business environment, such as technological change, competitor actions or changing customer preferences. Operational risk relates to failures of internal processes, people and systems, and credit risk to counterparties failing to pay.

  4. Question 4

    Which statement best distinguishes risk appetite from risk tolerance?

    • A) Risk appetite applies only to financial risks, whereas risk tolerance applies only to operational risks
    • B) Risk appetite is set by front-line managers for individual transactions; risk tolerance is set by the board for the whole organization
    • C) Risk appetite is the broad amount of risk an organization is willing to accept in pursuit of value; risk tolerance is the acceptable variation in performance around specific objectives
    • D) Risk appetite is the risk remaining after controls; risk tolerance is the risk before any controls
    Show answer & explanation

    Answer: C) Risk appetite is the broad amount of risk an organization is willing to accept in pursuit of value; risk tolerance is the acceptable variation in performance around specific objectives

    Risk appetite is a high-level, organization-wide statement, set by management with board oversight, of the types and amount of risk the entity is willing to accept in pursuit of its mission and value. Risk tolerance (the acceptable variation in performance) is more granular and relates to particular objectives or metrics. Risk before and after controls describes inherent and residual risk.

  5. Question 5

    A company purchases a commercial liability insurance policy to cover potential customer injury claims. Which risk response does this represent?

    • A) Accepting the risk
    • B) Exploiting the risk
    • C) Avoiding the risk
    • D) Sharing (transferring) the risk
    Show answer & explanation

    Answer: D) Sharing (transferring) the risk

    Buying insurance shares or transfers the financial consequences of a risk to another party in exchange for a premium. Avoidance means exiting the activity that gives rise to the risk, acceptance means taking no action beyond monitoring, and reduction means using controls to lower likelihood or impact.

  6. Question 6

    A risk assessment rates the risk of unauthorized wire transfers as high before considering controls. After dual authorization and daily bank reconciliations are introduced, the risk is rated low. The low rating is the:

    • A) Risk appetite
    • B) Inherent risk
    • C) Residual risk
    • D) Detection risk
    Show answer & explanation

    Answer: C) Residual risk

    Inherent risk is the risk in the absence of any management actions or controls. Residual risk is the risk that remains after management's responses, such as controls, have been applied. Management compares residual risk with risk appetite to decide whether further action is needed.

  7. Question 7

    Which of the following is NOT one of the five components of the COSO Enterprise Risk Management - Integrating with Strategy and Performance framework?

    • A) Performance
    • B) Review and revision
    • C) Governance and culture
    • D) Control activities
    Show answer & explanation

    Answer: D) Control activities

    The COSO ERM framework (2017) has five components: Governance and Culture; Strategy and Objective-Setting; Performance; Review and Revision; and Information, Communication, and Reporting. Control activities is a component of the separate COSO Internal Control - Integrated Framework.

  8. Question 8

    Ormsby Chemicals estimates a 4% annual probability of an environmental spill that would cost $2,500,000. What is the expected annual loss from this risk?

    • A) $1,000,000
    • B) $2,400,000
    • C) $2,500,000
    • D) $100,000
    Show answer & explanation

    Answer: D) $100,000

    Expected loss = probability x impact = 4% x $2,500,000 = $100,000. Comparing this figure with the annual cost of a risk response (for example an insurance premium) helps decide whether the response is cost-effective.

  9. Question 9

    In a risk heat map that plots likelihood against impact, which risks should generally receive the highest priority for management attention?

    • A) Risks with high likelihood but low impact
    • B) Risks with low likelihood and low impact
    • C) Risks that have already been fully insured
    • D) Risks with both high likelihood and high impact
    Show answer & explanation

    Answer: D) Risks with both high likelihood and high impact

    A heat map shows each risk's assessed likelihood and impact. Those in the high-likelihood, high-impact zone pose the greatest threat to objectives and are prioritized for response. Low-impact frequent risks may be handled through routine controls, while low-likelihood, high-impact risks often call for contingency plans or insurance.

  10. Question 10

    Which of the following is the best example of a key risk indicator (KRI)?

    • A) The historical cost of property, plant and equipment
    • B) The number of shares authorized in the corporate charter
    • C) A rising rate of employee turnover in the IT security team, monitored monthly
    • D) Last year's audited net income
    Show answer & explanation

    Answer: C) A rising rate of employee turnover in the IT security team, monitored monthly

    Key risk indicators are metrics, ideally forward-looking, that provide early warning of increasing exposure to a risk. Rising turnover among security staff may signal greater cybersecurity risk before an incident occurs. Historical results and static balances describe past outcomes rather than changing risk exposure.

  11. Question 11

    As part of its business continuity plan, a bank maintains a fully equipped backup data center with current copies of all systems and data, ready to take over operations within minutes. This backup facility is a:

    • A) Warm site
    • B) Cold site
    • C) Hot site
    • D) Reciprocal agreement
    Show answer & explanation

    Answer: C) Hot site

    A hot site is fully configured with hardware, software and up-to-date data, enabling near-immediate recovery. A cold site provides space and utilities but no equipment, and a warm site has some equipment but needs time and data restoration. A reciprocal agreement relies on another organization's facilities.

  12. Question 12

    Pendle Logistics faces a 10% annual chance of a cyberattack causing a $1,000,000 loss. A security upgrade costing $60,000 per year would reduce the probability to 3%. What is the net annual benefit (cost) of the upgrade based on expected values?

    • A) Net cost of $30,000
    • B) Net cost of $25,000
    • C) Net benefit of $10,000
    • D) Net benefit of $40,000
    Show answer & explanation

    Answer: C) Net benefit of $10,000

    Expected loss without upgrade = 10% x $1,000,000 = $100,000. With upgrade = 3% x $1,000,000 = $30,000. Reduction in expected loss = $70,000. Net benefit = $70,000 - $60,000 = $10,000. Comparing the cost with the full original expected loss ($100,000) overstates the benefit because some risk remains.

  13. Question 13

    Which of the following is an example of operational risk?

    • A) A decline in the value of foreign currency receivables
    • B) A rise in market interest rates on floating-rate debt
    • C) Losses caused by employees repeatedly keying incorrect prices into the billing system
    • D) A competitor launching a superior product
    Show answer & explanation

    Answer: C) Losses caused by employees repeatedly keying incorrect prices into the billing system

    Operational risk is the risk of loss from inadequate or failed internal processes, people and systems, or from external events. Data entry errors are a people and process failure. Currency and interest rate movements are financial (market) risks, and a competitor's product launch is a strategic risk.

  14. Question 14

    A company decides to withdraw entirely from a politically unstable country rather than continue operating there. This risk response is:

    • A) Avoidance
    • B) Acceptance
    • C) Sharing
    • D) Reduction
    Show answer & explanation

    Answer: A) Avoidance

    Avoidance eliminates a risk by exiting or not undertaking the activity that creates it. It is appropriate when no other response brings the risk within the organization's risk appetite at an acceptable cost. Reduction lowers likelihood or impact, sharing transfers part of the risk, and acceptance retains it.

  15. Question 15

    Which of the following is a recognized limitation of value at risk (VaR) as a risk measure?

    • A) It can only be calculated for a single asset, not a portfolio
    • B) It does not indicate how large losses may be in the cases where the VaR threshold is exceeded
    • C) It cannot be expressed in currency terms
    • D) It ignores the probability of losses entirely
    Show answer & explanation

    Answer: B) It does not indicate how large losses may be in the cases where the VaR threshold is exceeded

    VaR states the maximum loss expected at a given confidence level over a set period, in currency terms, and is commonly computed for portfolios. However, it says nothing about the size of losses in the tail beyond the threshold, and it often relies on normal distribution assumptions that understate extreme events. Measures such as conditional VaR (expected shortfall) and stress testing address this gap.

Sponsored slot availableRun a CA academy or hiring firm? Put your name in front of students preparing for this exam.Advertise โ†’