Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Which of the following is the current trend in auditing, risk management and compliance?
According to3, page 6, one of the current trends in auditing, risk management and compliance is ''moving from a back-office function providing lagging indicators about risk (e.g., audit findings) to a front-office function providing leading indicators about risk (e.g., key risk indicators)''.
Which risk is sometimes called 'retained risk.'?
According to ISO/IEC Guide73 (2009), clause B., residual risk is ''the level of remaining after controls have been applied''.It is sometimes called 'retained risk' because it represents the amount of risk that an organization decides to accept or retain after implementing its mitigation strategies3.
An international bank has identified the risks associated with economic changes in the countries in which it operates. Which of the following correctly describes these risks?
According to1, page 15-16, external risks are ''those arising from events outside the organization'' and marketplace risks are ''those arising from changes in market conditions such as customer demand, competition, regulation''. Economic changes in different countries can affect the market conditions for an international bank's operations.
ISO 31000:2018 currently has a tactical and process focus.
The ISO 31000:2018 standard provides a framework for risk management, with a focus on the strategic and integrated aspects of risk management. It outlines principles, a framework, and a process for managing risk in organizations of all kinds. The focus of the standard is on aligning risk management with the organization's context, objectives, and strategy, and on integrating risk management into all aspects of an organization's governance, culture, and performance.
Which type of risk management technique does insurance belongs to?
According to , page 16-17, insurance belongs to sharing technique which is ''a way of transferring some or all financial consequences associated with a particular exposure''. It involves paying a premium in exchange for compensation in case of loss.
100 questions covering all exam domains, starting from $20
Exam domains verified against: Official GAQM ISO-31000-CLA exam guide, last checked September 2026.
Covers fundamental concepts of risk management principles and establishes baseline understanding of risk management in organizational contexts. Learn core concepts including risk appetite, risk tolerance, and how organizations establish a risk-aware culture.
Focuses on integration of risk-based thinking approaches within organizational processes. Emphasizes systematic risk consideration in decision-making and applying risk-based thinking to enhance organizational resilience.
Sample question from this domain above: Q4
Addresses key terminology, fundamental risk concepts, and standardized definitions used in risk management frameworks. Tests ability to distinguish between subtle differences in ISO definitions through case vignettes.
Covers the simplified version of ISO 31000:2018 standard with focus on practical implementation and core principles. Emphasizes the 2018 framework and process flow for real-world application.
Covers core principles that form the foundation of effective risk management practices and their application. Maps each principle to workplace examples for practical understanding.
Addresses the structural framework necessary for implementing and maintaining effective risk management systems within organizations. Provides guidance on the selection and application of risk management frameworks in various contexts.
Covers the systematic approach to risk management including identification, analysis, evaluation, and treatment processes. Focuses on mapping process steps to realistic scenarios and decision points.
Sample question from this domain above: Q2
Focuses on practical tools and methodologies used in risk assessment including qualitative and quantitative techniques. Covers specific topics such as risk identification, risk assessment, and risk treatment approaches.
Explores advanced concepts from ISO 31000:2009 emphasizing enhanced risk management practices and their evolution in modern organizations. Examines the development of risk management strategy accounting for organizational resources and internal support.
Sample question from this domain above: Q3
Common questions about the exam itself