CIA-1 - Governance, Risk Management, and Control - Section C.4

Interpret fundamental concepts of risk type, differentiating strategic, operational, financial, compliance, reputational, and environmental, social, and governance risks, and comparing inherent and residual risk.

Differentiate the major categories of risk, including strategic, operational, financial, compliance, reputational, and environmental, social, and governance risk, and recognise how each threatens different objectives. Compare inherent risk, the exposure before any controls are applied, with residual risk, the exposure that remains after management's responses, and explain why the gap between them reflects control effectiveness.

Inherent riskResidual riskRisk categoriesESG risk

Practice question for this objective

Free sampleGovernance, Risk Management, and Controlmedium

A trainee at Halden Group keeps confusing inherent risk with residual risk. Which statement correctly describes inherent risk?

  • AThe risk to an objective before management takes any action to change its likelihood or impact. Correct
  • BThe risk to an objective that remains once management's controls and responses are in place.
  • CThe maximum amount of risk the organisation's board is prepared to accept in total overall.
  • DThe variation around a target that management will accept before taking any further action.
Inherent risk is the exposure before any management action, whereas residual risk is what remains after controls operate. Inherent risk is assessed before controls so their effect can be judged; measuring after controls gives residual risk, which is why the pre-action definition is inherent.

Why A is correct: Inherent risk is the exposure to an objective before management acts to change its likelihood or impact, which is precisely what this option states.

Why B is wrong: This describes residual risk, the exposure left after controls operate, so a candidate who swaps the two terms is drawn here; it is not inherent risk.

Why C is wrong: This describes risk appetite or capacity, the total risk the board will accept, which is a chosen boundary rather than the pre-control exposure, so it is wrong.

Why D is wrong: This describes risk tolerance, the accepted variation around a target, which is a threshold and not the exposure measured before any controls, so it is wrong.

See more CIA-1 practice questions, answers explained.

More in this domain

Back to all Governance, Risk Management, and Control objectives, or the CIA-1 cert hub.

Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. Original, blueprint-aligned practice material only.