Home

Tutoring

Subjects

Live Classes

Study Coach

Essay Review

On-Demand Courses

Colleges

Games


Sign up

Log in

Opening subject page...

Loading your content

Practice

  • All Subjects
  • Algebra Flashcards
  • SAT Math Practice Tests
  • Math Question of the Day
  • Live Classes
  • On-Demand Courses

Varsity Tutors

  • Find a Tutor
  • Test Prep
  • Online Classes
  • K-12 Learning
  • College Search
  • VarsityTutors.com

© 2026 Varsity Tutors. All rights reserved.

← Back to quizzes

CPA Isc Quiz

CPA Isc Quiz: Apply Coso Erm Framework

Practice Apply Coso Erm Framework in CPA Isc with focused quiz questions that help you check what you know, review explanations, and build confidence with test-style prompts.

Question 1 / 20

0 of 20 answered

Under the COSO ERM 2017 framework, which of the following represents the first component?

Select an answer to continue

What this quiz covers

This quiz focuses on Apply Coso Erm Framework, giving you a quick way to practice the rules, question types, and explanations that matter most for CPA Isc.

How to use this quiz

Try each quiz question before looking at the correct answer. Use the explanations to review missed ideas, then come back to similar questions until the pattern feels familiar.

All questions

Question 1

Under the COSO ERM 2017 framework, which of the following represents the first component?

  1. Governance and Culture (correct answer)
  2. Risk Assessment
  3. Control Activities
  4. Information and Communication

Explanation: The COSO ERM 2017 framework has five components. Governance and Culture is the foundational first component, setting oversight responsibilities and cultural expectations around risk. Answer A is correct. Risk Assessment (B) is a term from COSO ICIF. Control Activities (C) and Information and Communication (D) are components of COSO ICIF, not the primary ERM components.

Question 2

In the context of COSO ERM, risk appetite is best defined as:

  1. The maximum financial loss the organization can sustain before becoming insolvent.
  2. The specific risk events that management has identified as possible.
  3. The amount and type of risk an organization is willing to accept in pursuit of its objectives. (correct answer)
  4. The level of risk remaining after controls have been applied.

Explanation: Risk appetite represents the organization's willingness to accept risk in pursuit of value creation. It reflects strategy and guides risk tolerance decisions. Answer C is correct. Maximum financial loss (A) describes risk capacity. Identified risk events (B) describe a risk inventory. Risk after controls (D) describes residual risk.

Question 3

Under the COSO ERM framework, which of the following best describes 'residual risk'?

  1. The risk identified during an initial risk assessment before any analysis.
  2. Risks arising from external environmental factors beyond management's control.
  3. The aggregate of all risks across the organization's business units.
  4. The risk remaining after management has implemented responses to reduce inherent risk. (correct answer)

Explanation: Residual risk is what remains after risk responses have been applied to inherent risk. Answer D is correct. Preliminary identified risk (A) is closer to inherent risk. External environmental factors (B) describe a source of risk. Portfolio-level aggregate risk (C) is a distinct concept.

Question 4

Under COSO ERM, which of the following is an example of a risk transfer response strategy?

  1. Purchasing insurance to shift the financial impact of a potential loss to a third party. (correct answer)
  2. Identifying all risks that could affect the achievement of organizational objectives.
  3. Setting the organization's overall risk appetite.
  4. Reporting risk information to the board of directors.

Explanation: Risk transfer - such as purchasing insurance - is one of the five risk response strategies under COSO ERM 2017 (avoid, accept, reduce, share/transfer, and pursue). Answer A is correct. Identifying risks (B) is part of Risk Assessment. Setting risk appetite (C) is Governance and Culture. Reporting to the board (D) is Information, Communication, and Reporting.

Question 5

A risk that falls within an organization's risk tolerance and requires no immediate action is best described under COSO ERM as:

  1. An inherent risk requiring additional controls.
  2. A key risk indicator requiring escalation.
  3. A risk that must be transferred to a third party.
  4. An accepted risk that is monitored but requires no additional response. (correct answer)

Explanation: Under COSO ERM, 'accept' is a valid risk response for risks within established tolerance. No additional action is required beyond monitoring. Answer D is correct. Inherent risks requiring controls (A) have not been assessed against tolerance. KRI escalation (B) implies the risk is moving outside tolerance. Transfer (C) is an active response.

Question 6

The 'Performance' component of COSO ERM 2017 primarily involves:

  1. Reviewing whether the ERM framework itself is operating effectively.
  2. Setting the organization's mission, vision, and core values.
  3. Identifying, assessing, prioritizing, and responding to risks that affect the achievement of strategy and business objectives. (correct answer)
  4. Communicating risk information to internal and external stakeholders.

Explanation: The Performance component covers the core risk management process: identification, assessment, prioritization, and response. Answer C is correct. ERM effectiveness review (A) is Review and Revision. Mission and values (B) are Governance and Culture. Stakeholder communication (D) is Information, Communication, and Reporting.

Question 7

Under COSO ERM, which of the following best describes 'inherent risk'?

  1. Risk that remains after management implements its risk response strategies.
  2. Risk that arises from the organization's internal audit function.
  3. Risk that is transferred to a third party through insurance or contracts.
  4. The risk level existing before management applies any controls or risk responses. (correct answer)

Explanation: Inherent risk is the raw, uncontrolled risk level absent any management actions. Answer D is correct. Residual risk (A) is what remains after responses. Internal audit is a control function, not a risk source (B). Transferred risk (C) is a specific risk response outcome.

Question 8

A manufacturer qualifies a second supplier to reduce supply chain disruption risk. Under COSO ERM, this response is classified as:

  1. Accept
  2. Reduce (Mitigate) (correct answer)
  3. Avoid
  4. Transfer

Explanation: Qualifying a second supplier reduces the likelihood and/or impact of supply chain disruption - a risk reduction (mitigation) response. Answer B is correct. Accept (A) means taking no action. Avoid (C) would mean exiting the activity entirely. Transfer (D) shifts financial consequences to another party.

Question 9

An organization maintains a risk register with identified risks, likelihood, impact, current controls, and risk owners. In COSO ERM, maintaining this register primarily supports which component?

  1. Performance - specifically risk identification, assessment, and prioritization. (correct answer)
  2. Governance and Culture - by establishing accountability for risks.
  3. Review and Revision - by providing historical data for trend analysis.
  4. Information, Communication, and Reporting - by distributing risk data to stakeholders.

Explanation: A risk register is the primary tool in the Performance component, documenting and prioritizing risks. Answer A is correct. While it may support governance (B), review (C), and reporting (D), its primary purpose is in the Performance component's risk identification and assessment activities.

Question 10

Under COSO ERM, a 'key risk indicator' (KRI) is best described as:

  1. A metric that provides early warning when a risk is increasing or approaching the risk tolerance threshold. (correct answer)
  2. A financial ratio used to assess an organization's solvency.
  3. A control test result indicating whether a specific control is operating effectively.
  4. A benchmark used to compare the organization's risk profile to industry peers.

Explanation: KRIs are forward-looking metrics that signal when risk levels are changing, enabling proactive management before tolerance is breached. Answer A is correct. Solvency ratios (B) are financial metrics. Control test results (C) are key control indicators. Benchmarks (D) are comparative measures, not KRIs.

Question 11

The five components of COSO ERM 2017 in order are:

  1. Control Environment, Risk Assessment, Control Activities, Information & Communication, Monitoring.
  2. Identify, Protect, Detect, Respond, Recover.
  3. Plan, Source, Make, Deliver, Return.
  4. Governance & Culture, Strategy & Objective-Setting, Performance, Review & Revision, Information, Communication & Reporting. (correct answer)

Explanation: The five COSO ERM 2017 components are: Governance and Culture, Strategy and Objective-Setting, Performance, Review and Revision, and Information, Communication, and Reporting. Answer D is correct. Answer A lists COSO ICIF components. Answer B is the NIST Cybersecurity Framework. Answer C is a supply chain framework.

Question 12

A risk has low likelihood but could result in significant reputational damage. Which response is most appropriate under COSO ERM?

  1. Accept the risk without any response since likelihood is low.
  2. Develop a crisis communication plan and monitor the risk given its potential reputational impact. (correct answer)
  3. Avoid the risk by ceasing all related business activities immediately.
  4. Transfer all reputational risk through a contractual indemnification clause.

Explanation: Reputational risks with significant impact warrant contingency planning and monitoring, even at low likelihood, because reputational damage can be severe and difficult to reverse. Answer B is correct. Accepting without response (A) is inappropriate for high-impact risks. Immediately ceasing activities (C) may be disproportionate. Reputational risk cannot be fully transferred (D).

Question 13

A company exits a high-risk market segment entirely to eliminate associated risks. Under COSO ERM, this response is classified as:

  1. Transfer
  2. Reduce
  3. Avoid (correct answer)
  4. Accept

Explanation: Exiting a business activity to eliminate risk exposure is the Avoid response strategy. Answer C is correct. Transfer (A) shifts risk to another party. Reduce (B) lowers likelihood or impact. Accept (D) takes no action.

Question 14

Under COSO ERM, the concept of 'portfolio view of risk' means that:

  1. All risks must be managed within the IT department's project portfolio.
  2. Each business unit manages its own risks independently without enterprise reference.
  3. Only financial risks are included in the enterprise risk portfolio.
  4. Management considers interrelationships among risks across the organization to understand the aggregate risk profile. (correct answer)

Explanation: A portfolio view requires assessing how individual risks interact and combine enterprise-wide, since collectively risks may exceed acceptable levels even when each appears manageable in isolation. Answer D is correct. The view is enterprise-wide, not IT-only (A). It requires cross-unit coordination (B). It encompasses all risk types (C).

Question 15

Under COSO ERM, the 'Information, Communication, and Reporting' component supports the other components primarily by:

  1. Designing and testing the effectiveness of key internal controls.
  2. Ensuring relevant risk information flows to all levels of the organization to enable informed decision-making. (correct answer)
  3. Setting the organization's risk appetite and tolerance thresholds.
  4. Identifying and assessing risks across all business units.

Explanation: The Information, Communication, and Reporting component ensures risk-relevant data is captured and communicated across the organization so stakeholders can fulfill risk management responsibilities. Answer B is correct. Control design and testing (A) is a Control Activities function. Risk appetite (C) is Governance and Culture. Risk identification and assessment (D) is the Performance component.

Question 16

The COSO Enterprise Risk Management (ERM) framework is primarily designed to:

  1. Provide technical standards for encrypting sensitive data.
  2. Help organizations identify, assess, and manage risks that could affect the achievement of strategic and operational objectives. (correct answer)
  3. Define accounting standards for recognizing contingent liabilities.
  4. Establish IT infrastructure standards for cloud computing environments.

Explanation: The COSO ERM framework provides a structured approach for organizations to manage uncertainty and risk in pursuit of their objectives. Answer B is correct. Encryption standards (A), accounting standards (C), and IT infrastructure standards (D) are outside the scope of the COSO ERM framework.

Question 17

An organization's board reviews and approves the risk appetite statement annually. Under COSO ERM, this falls within which component?

  1. Risk Assessment
  2. Governance and Culture (correct answer)
  3. Strategy and Objective-Setting
  4. Review and Revision

Explanation: Board oversight of risk appetite is part of the Governance and Culture component, which addresses board roles, management structure, and cultural expectations around risk. Answer B is correct. Risk Assessment (A) involves analyzing risks. Strategy and Objective-Setting (C) involves applying risk appetite. Review and Revision (D) involves monitoring performance.

Question 18

A risk has very high potential impact but very low likelihood. Under COSO ERM, the most appropriate initial response is typically to:

  1. Immediately implement extensive controls to eliminate the risk entirely.
  2. Transfer the risk to a third party without further analysis.
  3. Monitor the risk and develop contingency plans given the high potential impact. (correct answer)
  4. Remove the risk from the register since low likelihood makes it immaterial.

Explanation: A high-impact, low-likelihood risk warrants monitoring and contingency planning. The high impact means consequences could be severe. Answer C is correct. Extensive controls immediately (A) may not be cost-effective. Automatic transfer (B) ignores needed analysis. Removing from the register (D) is inappropriate for high-impact risks.

Question 19

The COSO ERM 2017 framework introduced which significant enhancement compared to the 2004 version?

  1. Reduced the number of risk response categories from five to two.
  2. Eliminated the role of the board of directors in risk oversight.
  3. Greater emphasis on linking ERM to strategy-setting and the relationship between risk and performance. (correct answer)
  4. Required all organizations to adopt a zero-risk tolerance policy.

Explanation: The 2017 update strengthened the connection between ERM, strategy formulation, and performance management. Answer C is correct. Risk response categories were not reduced (A). Board oversight was retained and strengthened (B). Zero-risk tolerance was not introduced (D).

Question 20

The 'Review and Revision' component of COSO ERM 2017 is primarily concerned with:

  1. Identifying new risks not previously known to the organization.
  2. Setting the organization's risk appetite and tolerance levels.
  3. Designing and implementing controls to reduce identified risks.
  4. Assessing how well ERM is performing and making adjustments in response to changes. (correct answer)

Explanation: Review and Revision involves monitoring ERM performance, assessing changes in business context, and revising the framework to improve effectiveness. Answer D is correct. Identifying new risks (A) is Performance. Setting risk appetite (B) is Governance and Culture. Designing controls (C) is also Performance.