Advanced Risk Management Techniques & Enterprise Readiness
CRMC · 100 questions
- A city keeps running a money-losing ice rink that injures skaters nearly every week, citing "tradition," and refuses to shut it down. Which risk treatment is leadership refusing to apply?
- A plant has a leaky chemical storage tank that staff can repair or replace, but leadership only purchases more pollution liability insurance and leaves the tank as-is. What is the main problem with that approach?
- A department labels a blocked fire exit as "accepted risk" because clearing storage is inconvenient this quarter. Why is that use of acceptance incorrect?
- A facilities contract shifts all liability for high-hazard work onto a one-person vendor with no assets or insurance. What does this illustrate about risk transfer?
- Legal reviews a high-hazard contractor agreement and finds no indemnification clause. Why does that matter for risk treatment?
- An event venue requires food vendors to provide certificates of insurance before serving. One vendor delivers a certificate that expired last month. What should the risk control conclusion be?
- A shop installs machine guarding on a press and then documents the remaining, lower exposure as accepted with an owner and review date. Which treatment path does this describe?
- Festival leadership cancels an optional drone light show planned over a dense crowd because the uncertainty and harm potential are too high. Which treatment did they choose?
- An agency buys a cyber insurance policy but skips phishing training and routine patching. What is the sound risk-treatment critique?
- A manufacturer replaces a high-toxicity chemical cleaning step with a mechanical abrasion method that removes the chemical hazard. What treatment does this primarily illustrate?
- A board minutes note says ransomware risk is "accepted," but there is no rationale, risk owner, residual description, or review date. What is missing for valid acceptance?
- A city inserts lease language that "transfers" river-flood risk to riverside residents, even though residents cannot operate or fund the levees. Why is this transfer inappropriate?
- A warehouse installs a sprinkler system and also buys property insurance for fire loss. Which statement best describes this treatment combination?
- A director proposes avoiding all innovation projects so the organization never takes strategic risk. What is the main flaw in that strategy?
- Procurement collected certificates of insurance from contractors at onboarding three years ago and never rechecks them at policy renewal. What control gap does this create?
- A manager claims that because contractors signed indemnification language, "incidents cannot happen on our sites anymore." What misconception should be corrected?
- An administrative office writes into policy that minor theft of low-value office supplies is accepted, with monitoring thresholds and an owner. When is this approach appropriate?
- Organizers move a festival from a cliffside overlook to a flat city park specifically to cut fall exposure for attendees. What treatment idea does this demonstrate?
- Counsel asserts that liability was "transferred," yet the contract only contains a vague "best efforts to be careful" sentence with no clear allocation of loss. What quality problem exists?
- After phishing controls and a cyber policy are in place, leaders accept a small documented residual cyber exposure and attach an incident playbook with an owner. Which path does this follow?
- A draft business impact analysis lists every department as "equally critical" with no ranking of what must recover first. What core BIA purpose is missing?
- During an outage, IT restores email first because complainers are loudest, while wastewater SCADA dependencies identified in planning are left waiting. What BIA lesson was ignored?
- A BIA "report" is a single slide of clip art with no estimates of how impact grows over time if functions stay down. Why is that inadequate?
- Analysts rank citizen permit-counter services using only the org chart and never interview the clerks who run the counters daily. What BIA research weakness does this show?
- Payroll downtime impact is scored only by counting IT help-desk tickets, ignoring employee hardship and statutory pay deadlines. Which BIA improvement is needed?
- A city IT shop runs three 'critical' applications on one shared vendor platform, but the BIA scores each application as if it could fail alone. What shared-dependency gap should the risk manager flag?
- A county copies another city's BIA wholesale and skips localizing peak tourism and storm-season loads. What correction should the risk manager require?
- IT promises same-day restore for a permit system that has never been restored in a drill, and leadership wants that promise written as the RTO. How should BIA-informed recovery needs be set?
- Facilities staff omit the paper records vault from the BIA because 'we're digital now,' yet several permit workflows still depend on those originals. What should the risk manager insist on?
- Leadership wants to buy a hot site immediately and skip the BIA to 'save time.' What sequencing should the risk manager recommend?
- A mid-year BIA snapshot ranks election support systems as low priority because ballots are months away. What time-varying criticality issue should be corrected?
- A utility's BIA lists only first-hour outage costs for the customer portal and ignores how reputational harm grows over days. What stakeholder-impact improvement is needed?
- Emergency operations and cold-storage both rely on one backup generator, but the BIA never notes contention for that resource. What dependency should be documented?
- In a BIA workshop, managers rank the intranet news blog above emergency dispatch radio because the blog is more popular internally. How should criticality be ranked?
- A public-safety support team's 911-adjacent SaaS tools live in a third-party cloud but never appear on BIA dependency maps. What mapping correction is required?
- Finance wants the BIA to report only dollar loss, while operations needs life-safety impact in the same analysis. How should the risk manager structure impact criteria?
- After a major reorganization merges two departments and moves critical workflows, recovery teams still follow last year's BIA. What should happen next?
- BIA reports bury maximum tolerable downtime in jargon and never state it plainly for executives. What communication fix should the risk manager apply?
- A clinic BIA lists appointment software as critical but never mentions vaccine refrigeration as a process dependency. What hidden-dependency practice should improve the analysis?
- Staff treat the BIA workshop like a floor hazard walk-around looking for wet floors and frayed cords. How should the facilitator clarify BIA purpose?
- A flood destroys the only records room, and leadership then asks for the first disaster recovery plan. What timing lesson should the risk manager reinforce?
- The DR binder still lists 2014 phone trees and contains no restoration priorities or recovery steps. What content upgrade is most needed?
- Leadership labels an empty room with no hardware or connectivity as the organization's 'hot site.' What definition correction is required?
- Budget only funds a cold site, yet staff expect instant failover during the next outage. What expectation should the risk manager reset?
- During drills, the team treats a warm site that has only partial equipment and staged data as if it were a hot site. What readiness distinction should be enforced?
- The DR plan describes vendor phone numbers but never names who may declare a disaster and activate the alternate site. What planning element is missing?
- Nightly backups complete successfully, but restore has never been tested at the recovery site. What DR effectiveness gap should leadership address?
- The DR plan lists application failover steps but omits generator fuel, building access badges, and key vendor contacts. What holistic planning correction is needed?
- A mutual-aid cold site three states away has no staff lodging or travel plan, yet leadership counts it as immediately usable. What practicality issue should be raised?
- The only copy of the DR runbook lives in a cloud folder that requires internet, and the plan assumes the network always works to open it. What accessibility fix should be made?
- A city utility discovers during a substation outage that its hot-site contract expired six months earlier and nobody tracked the renewal. What maintenance lesson should leadership take from the lapse?
- Ransomware encrypts a county’s primary data center and an always-connected hot site that mirrors the same network path in real time. What independence issue does this expose?
- A hospital’s disaster recovery plan runs 200 pages, yet responders cannot find the first actions on page one when an outage starts. What structural improvement is most needed?
- A regional bank picks a cold site solely because rent is cheapest, even though the building sits in the same floodplain as headquarters. What site-selection principle is violated?
- After a successful failover to a warm site, a transit agency has no written criteria for when to fail back to the primary facility. What planning gap does this reveal?
- A nonprofit accepts a SaaS vendor’s “full disaster recovery” marketing claim without reading the contract’s RTO clauses. What third-party planning practice should replace that approach?
- A paper disaster recovery plan sits in a locked cabinet, but after staff turnover nobody knows the combination. What access factor has failed?
- An annual drill walks staff through a hot-site script even though the real contract only provides a cold site. What exercise design problem does this create?
- A city’s emergency radio cache is stored only at the primary facility and never appears on recovery-site packing lists. What planning element is missing?
- Executives call any alternate office with Wi-Fi a “hot site.” How should the risk manager correctly distinguish readiness levels?
- A library adds a mezzanine overlook, but nobody reassesses who might be harmed by the new fall edges. What continuous-improvement step was skipped?
- Machine guards installed last year are assumed forever sufficient even though production throughput has doubled. What monitoring practice is missing?
- A supervisor modifies a machine interlock with tape during a rush order and never enters the change in the log. What control-change expectation was violated?
- A wall poster shows a continuous-improvement cycle, but scheduled risk reviews never actually occur. What should leadership prioritize?
- A port authority revisits only catastrophic risks each year while medium risks sit untouched for several cycles. What monitoring-breadth lesson applies?
- A makerspace adds teen volunteers but does not update its who-is-at-risk analysis. What identification update is required?
- A KPI dashboard shows falling incident rates while supervisors quietly discourage hazard reports to protect the numbers. What monitoring integrity issue should leadership address?
- A temporary crowd barrier at a civic arena becomes permanent without anyone verifying code compliance or sight lines. What validation step was skipped?
- After a peer city suffers a crane collapse, a public-works director dismisses the lessons as “not us.” What continuous-improvement response is more appropriate?
- Operators silence noisy sensor alarms instead of tuning detection thresholds. What continuous-improvement choice does this undermine?
- An annual facility review uses the same checklist every year and never flags new lithium battery storage. What identification refresh is needed?
- Corrective actions for a slippery floor are marked closed in the tracker, yet nobody verifies the floor condition actually changed. What closing step is missing?
- Staff propose a better machine-guard design, but the idea dies because “we already complied once.” What continuous-improvement principle counters that stance?
- A who-might-be-harmed analysis covers daytime office staff but forgets maintenance crews entering after hours. What completeness lesson applies?
- Control ownership rotates so often that sufficiency reviews never stick to a responsible person. What monitoring foundation is missing?
- A city risk dashboard highlights insurance premium totals every month but never shows how many known hazards were closed. What metric problem does this create?
- A parks department automates work-order routing, but the old paper sign-off checklist stays in the binder and operators keep arguing which one is required. What continuous-improvement action is missing?
- A community festival expands into a new plaza that has never been included in hazard walks. What should the risk team do first for identification?
- Near-miss trending is reviewed only once a quarter. A sudden burst of forklift near-misses sits unseen for ten weeks. What cadence lesson applies?
- After one kaizen week, management announces that continuous improvement is complete for the year. What misunderstanding is this?
- Each department keeps a private risk list, and leadership has no consolidated enterprise view. What ERM structural goal is missing?
- A supervisor claims enterprise risk management is simply buying enterprise antivirus. What corrects that claim?
- During an ERM discussion about funding loss reserves, the board asks what actuaries contribute. What awareness-level answer fits CRMC depth?
- A council member says the city will be fined next week for violating ISO 31000 as if it were a local ordinance. What clarification is needed?
- Leadership dismisses OSHA as irrelevant because “we’re not a factory,” even though the organization runs warehouse operations. What is the better risk stance?
- An ERM committee catalogs risks but never connects them to strategic objectives. What goal of ERM is missing?
- A manager treats a simple floor hazard walk-through as identical to financial risk modeling for the enterprise. What distinction should CRMC candidates recognize?
- A manager claims adopting ISO 31000 means the organization no longer needs any local procedures. What is wrong with that claim?
- Leadership posts required OSHA notices and then declares the entire ERM program finished. What correction is needed?
- An enterprise threat analysis covers only physical hazards and skips reputation and regulatory dimensions. What breadth issue should be corrected?
- The organization published risk appetite statements, but ERM reports never reference them when escalating issues. What alignment practice is missing?
- Operations leaders ignore actuarial reports because the documents feel mysterious. What ERM practice should replace that avoidance?
- Managers mock ISO 31000 principles as “too abstract,” and the organization never forms a common risk vocabulary. What value is being discarded?
- The enterprise risk register accepts only occupational hazard entries and excludes strategy and fraud risks. What ERM inclusiveness problem exists?
- A nonprofit assumes enterprise risk management applies only to Fortune 500 manufacturers. What is the accurate view?
- The only enterprise risk metric presented to the board is the OSHA injury log summary. What reporting gap should be fixed?
- Two overlapping risk committees dispute ownership and no charter states an ERM mandate. What governance fix is most needed?
- A colleague claims that passing the CRMC exam means the organization is now ISO 31000 certified. What distinction corrects that claim?
- Financial modelers and safety officers never share a common risk taxonomy, so enterprise rollups fail. What ERM integration practice is needed?
- Staff can name ISO 31000 and OSHA but never explain how either should shape program design. What standards-awareness gap remains?