CIA-1 - Governance, Risk Management, and Control - Section C.5

Interpret fundamental concepts of the risk management process, including risk appetite and risk tolerance, the risk management cycle, and evaluating an organization's responses to identified risks.

Define risk management and interpret the elements of the risk management cycle: identifying, assessing, responding to, and monitoring risk. Distinguish risk appetite, the amount of risk an organisation is willing to accept in pursuit of its objectives, from risk tolerance, the acceptable variation around that appetite, and evaluate whether management's response to a risk (accept, avoid, reduce, or share) is appropriate.

Risk appetiteRisk toleranceRisk responseRisk management cycle

Practice question for this objective

Free sampleGovernance, Risk Management, and Controlmedium

Aster Manufacturing distinguishes its risk appetite, the broad level of risk it will pursue, from its risk tolerance, the acceptable variation around specific objectives. An auditor reviews a plant whose scrap-rate objective is 2 percent with a stated tolerance of plus or minus 0.5 percentage points; the current scrap rate is 3.1 percent and management calls it acceptable. How should the auditor interpret this situation?

  • AThe scrap rate is within tolerance because a single plant's performance is judged against the organisation's overall appetite rather than the objective-level tolerance band.
  • BThe scrap rate of 3.1 percent breaches the stated tolerance band around the objective, so management's claim that it is acceptable warrants a finding and follow-up on the response. Correct
  • CThe scrap rate is acceptable provided management documents a revised objective of 3 percent, which the auditor should draft and recommend to the plant leadership team.
  • DThe scrap rate cannot be assessed because tolerance applies only to financial objectives, leaving an operational metric such as scrap outside any measurable boundary.
Risk tolerance is the acceptable variation around a specific objective, and performance outside that band is an exception regardless of overall appetite. Tolerance sets a measurable band around a specific objective, distinct from the organisation-wide appetite. A metric outside the band is an exception even if broad appetite feels comfortable, so the auditor tests performance against the objective-level tolerance, not against appetite.

Why A is wrong: This confuses appetite with tolerance; tolerance is measured against the specific objective, so judging the plant against broad appetite is the wrong yardstick and produces a false pass.

Why B is correct: Tolerance defines acceptable variation around a specific objective; 3.1 percent sits well outside the 1.5 to 2.5 percent band, so treating it as acceptable is inconsistent with the stated tolerance and correctly raises a finding.

Why C is wrong: Resetting the objective to fit performance is a management decision, and drafting it for them blurs the assurance role; the tolerance breach is not resolved by moving the target, so this is wrong.

Why D is wrong: Tolerance applies to operational as well as financial objectives, so the claim that scrap falls outside any boundary is incorrect and would wrongly excuse the exception from evaluation.

See more CIA-1 practice questions, answers explained.

More in this domain

Back to all Governance, Risk Management, and Control objectives, or the CIA-1 cert hub.

Examworthy is not affiliated with or endorsed by The Institute of Internal Auditors. Original, blueprint-aligned practice material only.