CIA-1 - Governance, Risk Management, and Control - Section C.6

Describe risk management within organizational processes and functions, including evaluating the design and effectiveness of risk management processes and the purpose and benefit of using a risk management framework.

Describe how risk management is embedded across organisational processes and functions rather than confined to a single team, and evaluate whether those processes are well designed and operating effectively. Explain the purpose and benefit of adopting a recognised risk management framework, such as COSO Enterprise Risk Management or ISO 31000, in giving the organisation a consistent structure for identifying and managing risk.

COSO ERMISO 31000Risk management framework

Practice question for this objective

Free sampleGovernance, Risk Management, and Controlmedium

At Tamarind Foods, a central risk team of three people maintains the corporate risk register, and everyone else treats risk as solely that team's responsibility, with operational managers saying risk is not their concern. The internal auditor is evaluating the design of the risk management process. How should the auditor interpret this arrangement?

  • AThe design is sound because concentrating risk management in one specialist team ensures consistency and gives the board a single accountable point of contact.
  • BThe design is acceptable as long as the central risk team reports functionally to the board rather than to operational management.
  • CThe auditor should personally take ownership of embedding risk management into daily operations so that the identified weakness is corrected.
  • DThe design is flawed because risk management should be embedded across the organisation's processes and functions, with ownership resting with the managers who run each activity. Correct
Effective risk management is embedded across an organisation's processes and functions, not owned by a single central team. Risk management is designed well only when the people who run each process own the risks arising from it; concentrating all responsibility in one small team leaves those risks unmanaged at source and is a design weakness the auditor should report.

Why A is wrong: A dedicated team can aid coordination, which makes this tempting, but concentrating ownership in one small team leaves the people who actually run the activities disengaged from the risks they create, so the design is not sound.

Why B is wrong: Reporting lines matter for a risk function, which makes this plausible, but changing to whom the team reports does nothing to embed risk ownership across operations, so it does not cure the design flaw.

Why C is wrong: Wanting to fix the weakness is understandable, but building and running the risk process is a management responsibility under the Three Lines Model, and taking it on would impair internal audit's independence.

Why D is correct: Effective risk management is embedded throughout the organisation rather than delegated to a single team; the managers who own the processes must own the associated risks, so treating it as one team's job is a genuine design weakness.

See more CIA-1 practice questions, answers explained.

More in this domain

Back to all Governance, Risk Management, and Control objectives, or the CIA-1 cert hub.

Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. Original, blueprint-aligned practice material only.