RISK-MANAGER Sample Questions & Answers
Applying the risk management process itself, covering scope, context, criteria and assessment, carries the largest share, alongside the underlying ISO standards and principles, and setting policy within a risk management framework.
Launch the full RISK-MANAGER simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Establishing the risk management framework · Roles, authorities, responsibilities and accountabilities
During the design of a risk management framework for a hospital, the steering committee is debating the roles and responsibilities. One proposal suggests making the IT department the sole 'risk owner' for all cybersecurity threats. Why is this approach inconsistent with the principles of ISO 31000?
Show answer & explanation
Correct answer: C
ISO 31000 advocates for assigning accountability and authority for risk management. A 'risk owner' is the person or entity with the accountability and authority to manage a risk. While the IT department manages cybersecurity controls, the consequences of a breach affect clinical operations, patient data privacy, and medical device functionality. Therefore, the owners of those business processes (e.g., Head of Clinical Services, Chief Medical Officer) are often better positioned as risk owners, with IT acting as a key partner in risk treatment.
- Question 2Beginner
Application of the risk management process · Risk treatment
A university has identified a significant risk of data breach through phishing attacks targeting its faculty. After a risk assessment, the university decides to implement a multi-faceted risk treatment plan. Which of the following actions best exemplifies the 'risk reduction' (or mitigation) treatment option?
Show answer & explanation
Correct answer: C
Risk reduction involves taking actions to lessen the likelihood or consequences of a risk. Implementing MFA makes it harder for stolen credentials to be used, reducing the likelihood of a successful breach. Phishing training also reduces the likelihood of employees falling for attacks. Purchasing insurance is risk sharing/transfer, and accepting the risk is risk retention.
- Question 3Intermediate
Establishing the risk management framework · Allocation of resources
A non-profit organization with a limited budget wants to establish a risk management framework. The board is concerned about the cost. According to ISO 31000, how should the allocation of resources for risk management be approached?
Show answer & explanation
Correct answer: D
ISO 31000 emphasizes that the risk management framework and its components, including resource allocation, should be tailored to the organization's specific internal and external context. There is no prescribed percentage or amount. For a non-profit, this means focusing resources on the most significant risks to its objectives (e.g., funding stability, beneficiary welfare, reputation) in a cost-effective manner, rather than trying to match the spending of a different type of organization.
- Question 4Advanced
Fundamental principles and concepts of risk management · Risk management principles
An organization's risk management framework is technically robust, with detailed processes for assessment and treatment. However, during a major IT outage, departments acted in isolation, leading to conflicting communications to customers and a delayed recovery. An external review concluded that while individual risks were managed, the organization failed to manage risk systemically. Which core ISO 31000 principle was most clearly violated?
Show answer & explanation
Correct answer: B
The 'Integrated' principle states that risk management is an integral part of all organizational activities, including decision-making, strategy, operations, and culture. The scenario describes a situation where risk management was treated as a separate, siloed activity ('technically robust processes') but was not integrated into the organization's incident response and communication structures. This lack of integration led to a systemic failure despite the management of individual technical risks.
- Question 5Intermediate
Application of the risk management process · Recording and reporting
When recording and reporting the results of a risk assessment to the board of directors, what is the primary purpose of this communication according to ISO 31000?
Show answer & explanation
Correct answer: C
ISO 31000 states that reporting should be tailored to different stakeholders. For the board, the primary purpose is not just to list risks, but to provide them with the necessary information to fulfill their governance and oversight responsibilities. This includes making strategic decisions, allocating resources, and gaining assurance that the organization's most significant risks are understood and managed in line with its objectives and risk appetite.
- Question 6Intermediate
Establishing the risk management framework · Evaluation and improvement
A mature organization has been operating a risk management framework for five years. The risk manager wants to evaluate the framework's effectiveness to drive continual improvement. Which activity is most aligned with the 'Evaluation' component of the ISO 31000 framework model?
Show answer & explanation
Correct answer: B
The 'Evaluation' component of the framework specifically involves assessing how well the risk management framework is achieving its objectives. This is a step beyond the day-to-day risk process. It requires periodically stepping back to ask: 'Is our framework, as a whole, fit for purpose? Is it supporting decision-making? Is it helping us achieve our organizational objectives?' This measurement then feeds into the 'Improvement' component.
- Question 7Intermediate
Application of the risk management process · Communication and consultation
A city is planning a major public infrastructure project (e.g., a new light rail system). The project faces risks from technical challenges, funding shortfalls, public opposition, and environmental regulations. According to ISO 31000, why is establishing a 'communication and consultation' plan at the very beginning of the risk management process essential?
Show answer & explanation
Correct answer: B
ISO 31000 presents communication and consultation as a continuous activity that occurs throughout the entire risk management process. Starting it early is crucial because it helps to properly define the context by incorporating the knowledge, views, and perceptions of stakeholders. This leads to more comprehensive risk identification (e.g., the public may identify risks the engineers missed) and helps establish risk criteria (e.g., what level of noise disruption is 'acceptable') that are relevant and supported.
- Question 8Beginner
Establishing the risk management framework · Risk management policy
True or False: According to ISO 31000, a risk management policy must be a lengthy, detailed document that outlines every specific risk management procedure for the organization.
Show answer & explanation
Correct answer: B
False. ISO 31000 recommends that the risk management policy should be a concise statement that articulates the organization's overall intention and direction for risk management. It sets the tone and demonstrates leadership commitment. The detailed procedures, methodologies, and tools are typically documented separately as part of the broader risk management process, not within the high-level policy statement itself.
- Question 9Intermediate
Application of the risk management process · Scope, context and criteria
A risk manager for a food processing company is defining the risk criteria for product contamination. Which of the following is the best example of a well-defined risk criterion?
Show answer & explanation
Correct answer: D
A well-defined risk criterion provides a clear basis for evaluating the significance of a risk and for supporting decision-making. Option D is specific, measurable, and linked to clear consequences (consumer illness, Class I recall). It defines the level of acceptable risk ('unacceptable') and provides a clear principle for treatment (ALARP). The other options are too vague or absolute to be practically useful for decision-making.
- Question 10IntermediateSelect 2
Establishing the risk management framework · Integration
When designing a risk management framework, ISO 31000 emphasizes the need for integration into the organization's processes and structures. Which TWO of the following actions best demonstrate successful integration? (Select TWO)
Show answer & explanation
Correct answers: B, D
The correct answers are B and D. Integration means risk management is not a separate activity but is part of how the organization operates. Making risk assessment a standard part of project approval (B) embeds risk-based thinking into decision-making. Including risk responsibilities in job descriptions and performance reviews (D) integrates risk management into the organization's governance and human resource structures, making it part of everyone's job. A separate department (A) encourages silos, and an annual workshop (C) is an event, not an integrated process.
Ready for the real thing?
The full RISK-MANAGER simulator has every exam-style question, timed mode, and instant scoring.