A distribution company's board asks internal audit one question: "How exposed are we?" The honest answer depends on which risk you mean and whether you are counting the controls that already exist.
Risk is the effect of uncertainty on the achievement of objectives. Two features of that definition drive every exam question here. First, risk attaches to an objective, so a "risk" with no objective behind it is just an event. Second, the effect runs both directions: risk includes upside variation, though the CIA exam concentrates on downside exposure.
Strategic, operational, financial, compliance, reputational, and environmental or sustainability risk are classification labels. They exist so the board can assign ownership, so management can aggregate exposure by category, and so internal audit can build a risk-based plan that covers all categories rather than the two it finds easiest to test.
- Strategic risk: Exposure from the choice of objectives and the business model itself. Entering a new market, an acquisition that fails to integrate, a competitor's technology making your product obsolete...
- Operational risk: Exposure from failed or inadequate internal processes, people, and systems, or from external events.
Common mistakes
- Classifying by consequence instead of source. A supplier's factory fire that halts your production is operational (external event), not financial, even though the loss is measured in dollars.
- Calling everything reputational. Public embarrassment appears in most vignettes. Reputational is the primary type only when stakeholder trust is the exposure itself, as in a false advertising claim.
- Treating a reserve or insurance as reducing inherent risk to a lower residual likelihood. Funding transfers who pays; in Example 2 residual stayed at $1,300,000, identical to inherent.
Bottom line
- Risk is the effect of uncertainty on objectives; classify by the source of the exposure, not by where the loss lands.
- Strategic risk comes from business model and objective-setting choices, owned by the board and senior management.
- Operational risk comes from failed internal processes, people, systems, or external events.
- Financial risk covers credit, liquidity, market (rate, currency, commodity), and misstatement exposure.
Exam shortcut
Work the stem in two passes. First pass: underline the objective that is threatened and ask what failed. That names the type. Second pass: check whether the stem describes controls. If the phrase is "assuming no controls," "before considering," or "absent management action," the number wanted is inherent. If the phrase is "after controls," "remaining," "net," or "currently faces," the number wanted is residual.
The full lesson (about 2,287 words, 15 min read) adds 2 worked examples, all 6 common mistakes, a self-check, free in the app.
Learning objectives
- 4
Browse all free CIA Part 1 lessons or jump into free CIA Part 1 practice questions.