01. A customer has one risk assessment methodology for its manufacturing division and another for its financial services division, each agreed by that division's own committee. A supply chain risk is now owned jointly by the two divisions, and both committees will act on the result.
How should the implementer have that risk assessed?
a) Under a third methodology built from the factors of both, for risks that span the two divisions
b) Under whichever methodology belongs to the division that carries the larger share of the exposure, with the choice reviewed each year
c) Under both methodologies, so that each committee reads the risk in the model it agreed
d) Under one of the two, agreed between the committees and recorded on the risk, so one model's meaning attaches to the score
02. A customer's CFO has directed that every risk in the register carry a monetary figure, so the board can rank risks against one another. The risk team can defend a loss and a frequency for their operational and cyber risks. For risks such as loss of public trust after a product recall they have no loss history, and the estimates their reviewers produced differ by two orders of magnitude.
What should the implementer advise?
a) Rate those risks on the configured scales instead, so the board pack shows which risks carry a costed figure and which carry a rating
b) Have the risk team agree one loss figure for each of those risks, so the board pack is consistent
c) Move the whole register to Advanced Risk assessment, where a factor can express reputational damage
d) Record the range the reviewers produced against each of those risks, so the board can see the uncertainty
03. A customer runs one risk framework covering their corporate risks. They now want their manufacturing sites covered, and their risk lead proposes building a second risk framework so that the sites are brought into scope.
How should the implementer respond?
a) Agree, since a second framework is what lets a different set of risk criteria be applied to the manufacturing sites and their risks
b) Advise them to hold the manufacturing statements in an entity class instead, since a class is what carries a population
c) Agree, provided each manufacturing site is added to the new framework so that the statements it holds reach them
d) A second framework changes nothing about coverage; the sites are brought in by the entity type each statement is scoped to
04. A customer's engineers describe likelihood as a frequency: once a month, once a year or once in ten years. The delivered qualitative scale offers Low, Medium and High, and assessors have been picking whichever level feels right, so the same frequency has been rated three different ways across the register.
What should the implementer do?
a) Configure the likelihood levels in the risk criteria so that each level names the frequency band it stands for
b) Widen the thresholds in the risk criteria, so that a difference between assessors stops changing the band
c) Add a frequency factor to a risk assessment methodology, so the engineers' figure is carried into the score
d) Record an annual rate of occurrence on each risk instead, since the engineers are already describing frequency in years rather than levels
05. A customer's manufacturing division judges a risk mainly on safety exposure and lost production. Their financial services division judges the same kind of risk on regulatory penalty and customer attrition. Both divisions are moving to Advanced Risk assessment, and each has a risk committee that will have to defend the scores its own business produces.
How should the implementer configure the scoring?
a) Build a risk assessment methodology for each division, so each is scored on the factors and weights its committee agreed
b) Build one methodology and let each risk owner set the factor weights when they run their assessment
c) Build one methodology and a second risk framework, so each division's risks are organized and scored separately
d) Build one methodology holding all four factors, and have each division answer only the factors that apply to its own business
06. A customer's risk lead reports that the payment platform risk has moved into monitoring. Their compliance lead reports that the controls over the same platform are continuously monitored. The program manager asks whether the two of them are saying the same thing.
What should the implementer explain?
a) They describe one stage of the risk lifecycle, seen from the compliance side and from the risk side
b) They are two ways of saying that the risk's figures are being recalculated as its controls report
c) One says where the risk has reached, the other says how its controls are evidenced
d) They are the same thing, since a risk in monitoring is one whose controls are being tested on a schedule
07. A mitigation has delivered a new quarterly review of privileged access on a governed application, and the response task that implemented it is finished. Two implementers disagree about how the ongoing review should now be represented: one would leave it recorded on the closed response task, the other would set it up as a control on the application entity.
Which position is right, and why?
a) Set it up as a control, but only once the risk has been re-assessed, since a control created earlier would not be credited to it
b) Record it as a new risk statement covering privileged access, since a statement is what makes the review recur across the estate
c) Leave it on the closed response task, since that task is the record of what the mitigation delivered and a control would double-count it
d) Set it up as a control on the entity, since a recurring review is an ongoing measure whose operation has to stay testable long after the project work ends
08. Two risks in a customer's register were assessed on the same day, and the reviewers gave them the same answer on every factor. The two risks are reported with different scores, and the risk manager wants an explanation before the committee meets.
Which two explanations should the implementer check first?
(Choose two.)
a) One risk was generated from a risk statement and the other was raised by hand, which changes the way each one is scored
b) The two assessments were completed by different reviewers, and who responded is part of what an assessment's score is composed from
c) The two assessments ran under different risk assessment methodologies, whose factors carry different weights
d) The two risks have different control results behind them, so the figures being compared are not the assessment answers alone
09. Two risks were generated from one risk statement, one against a payroll application and one against a customer portal. Both carry the same inherent figure. The payroll risk's residual figure is materially lower than the portal's.
What is the most likely explanation?
a) The payroll risk was assessed quantitatively and the portal risk qualitatively
b) Each risk is assessed on its own entity, and the payroll application has the stronger control coverage
c) The risk statement carries different values for the two entities, and each generated risk inherited the pair meant for it
d) The two entities sit in different entity types, and each type carries its own residual expectation for the risks generated into it
10. Six months after go-live, a customer proposes that a risk owner who disagrees with the score their risk received should be able to replace it with the figure they believe is right, leaving a comment for the committee.
Which two objections should the implementer raise?
(Choose two.)
a) A policy exception should be raised instead, so that the deviation is formally approved and time limited
b) A score the owner cannot accept is evidence about the factors or the weighting, and correcting it there repairs every assessment rather than one
c) The risk should be assessed a second time under another methodology, and the owner should keep the score they prefer
d) The register can be ranked only because one model produced all of it, and a replaced figure is no longer a result of that model