Accounting Information Systems, 2e (Kay/Ovlia)
Chapter 12 The Risk Intelligent Enterprise: Enterprise Risk Management
Objective 1
1) The SEC requires company boards to report in-depth on how their enterprises identify risk, set
risk tolerances, and manage risk/reward trade-offs.
2) Controls are not task driven. Understanding risk is not a prerequisite to the appreciation and
application of control.
3) Enterprise risk management (ERM) goes beyond just security and controls.
4) Identifying, assessing, and mitigating risks has not been shown to produce better business
performance.
5) Risk intelligence involves using risk in a pro active, constructive way to create additional
value for the enterprise.
6) Risk management shifts an enterprise from a pro active approach of anticipating and
mitigating future risks before incidents occur to a reactive approach.
7) A silo approach with separate departments developing separate security programs without
consideration of comprehensive risk management can prove to be very effective.
8) Application controls are controls over IT services, such as networks and database systems.
9) ________ risks have no benefits, only threats to success.
10) ________ risks have the possibility of benefits associated with it.
11) The International Organization for Standardization framework for risk management is
________.
12) At the top management level, ________ IT controls provide IT governance that sets the tone
from the top of the enterprise.
13) ________ are controls embedded in business processes where a majority of security breaches
occur.
14) What percentage of CFOs provide advice on enterprise risk management?
A) 63%
B) 58%
C) 79%
D) 83%
15) Which of the following is NOT part of IT controls?
A) Event controls
B) IT general controls
C) Entity-level controls
D) Application controls
16) The IT control associated with top management is
A) IT general controls
B) Entity-level controls
C) Application controls
D) Event controls
17) The IT control associated with business processes is
A) Entity-level controls
B) IT general controls
C) Application controls
D) Event controls
18) Which of the following titles does NOT refer to someone in the C-Suite?
A) CIO: Chief Information Officer
B) CSO: Chief Sustainability Officer
C) CIA: Certified Internal Auditor
D) CFO: Chief Financial Officer
19) Which of the following is NOT considered part of IT controls?
A) ERM
B) Application controls
C) Entity-level controls
D) IT general controls
20) What is risk intelligence?
21) What is the difference between downside risks and upside risks?
1) The COSO Enterprise Risk Management framework replaces the COSO framework for
internal control.
2) Given the impossibility of foreseeing every conceivable control to address all threats, risk
management uses the approach of assessing risk to determine the probability of risk, its
frequency, and its impact.
3) It is possible for a company to be 100% risk free.
4) ________ is a COSO framework that provides guidance for managing risk.
Match the ERM Objective with the appropriate definition.
A) These objectives relate to the reliability of the enterprise‘s reporting, both internal and
external.
B) These objectives relate to the effective and efficient use of the entity’s resources.
C) These objectives relate to goals that support the entity’s mission.
D) These objectives relate to the entity’s compliance with all applicable laws and regulations.
5) Strategic objectives
Diff: 1
Objective: Q12.2 What’s the COSO ERM cube?
6) Operational objectives
Diff: 1
Objective: Q12.2 What’s the COSO ERM cube?
7) Reporting objectives
Diff: 1
Objective: Q12.2 What’s the COSO ERM cube?
8) Compliance objectives
Diff: 1
Objective: Q12.2 What’s the COSO ERM cube?
Match the ERM component name to the appropriate definition.
A) This is comprised of policies and procedures established and implemented to ensure risk
responses are effective.
B) This involves identifying occurrences that affect an enterprise’s ability to attain its objectives.
C) This involves ensuring relevant data is captured and communicated effectively throughout the
organization to appropriate individuals in a timely manner.
D) This involves watched evaluation and feedback that permits modifications as needed.
E) This ensures that the enterprise has a process for setting goals that are consistent with the
entity’s mission and risk appetite.
F) This involves the risk management philosophy of the enterprise, including the tone set by top
management.
9) Internal Environment
Diff: 2
Objective: Q12.2 What’s the COSO ERM cube?
10) Objective setting
Diff: 2
Objective: Q12.2 What’s the COSO ERM cube?
11) Control activities
Diff: 2
Objective: Q12.2 What’s the COSO ERM cube?
12) Monitoring
Diff: 2
Objective: Q12.2 What’s the COSO ERM cube?
13) Event identification
Diff: 1
Objective: Q12.2 What’s the COSO ERM cube?
14) Information and communication
Diff: 1
Objective: Q12.2 What’s the COSO ERM cube?
15) Which of the following is NOT a dimension in an ERM cube?
A) ERM resources
B) ERM objectives
C) ERM components
D) ERM units
16) Which of the following is part of the ERM units?
A) Internal Environments
B) Entity-level
C) Operations
D) Monitoring
17) Which ERM objective relates to the effective and efficient use of a corporation’s resources?
A) Operational objective
B) Compliance objective
C) Strategic objective
D) Reporting objective
18) Which ERM objective relates to the goals that support a corporation’s mission?
A) Reporting objective
B) Operational objective
C) Strategic objective
D) Compliance objective
19) Which ERM component involves the risk management philosophy of the
enterprise,including the tone set by top management?
A) Control activities
B) Information and communication
C) Internal environment
D) Event identification
20) Which ERM component is comprised of policies and procedures established and
implemented to ensure risk responses are effective?
A) Risk assessment
B) Control activities
C) Information and communication
D) Objective setting
21) List and define the four categories in the ERM framework of an enterprise’s objectives.
22) List and define the eight interrelated ERM components.
23) What is the main limitation in the ERM framework? Why is it a limitation?
1) A well developed and articulated risk management philosophy can provide consistency in risk
attitudes throughout the entire enterprise.
2) In ERM risk assessment, possibility may refer to assessing likelihood using a quantitative
measure, such as percentages.
3) When risk responses are being considered, the costs and benefits of options may play a major
role in the final decision.
4) The integrated enterprise system is unable to provide management with additional data and
information for use in making enterprise risk management assessments and decisions.
5) The ________ relates to the culture of the organization and its risk consciousness.
6) The ________ is also impacted by human resource policies, including hiring practices.
7) ________ forms the basis for operations, reporting, and compliance objectives.
8) ________ is the acceptable level of variation in attaining objectives.
9) ________ is the process of assessing the extent to which events would impact an entity’s
ability to achieve its objectives.
10) The ________ component involves identifying potential events that might affect the entity.
11) In ERM risk assessment, ________ may refer to assessing likelihood using qualitative
measures, such as high, medium, or low.
12) In ERM risk assessment, ________ may refer to assessing likelihood using a quantitative
measure, such as percentages.
13) In the context of enterprise risk management, ________ refers to the process of monitoring
an entity’s enterprise risk management.