Which of the following best describes the difference between inherent risk and residual risk?
Correct Answer: C
Comprehensive and Detailed Step-by-Step Explanation:
* Definitions from Risk Management Frameworks (e.g., COSO ERM):
* Inherent Risk: The raw or natural level of risk before any controls or mitigating actions are applied.
* Residual Risk: The remaining level of risk after implementing controls or risk responses.
* Reasoning:
* Option Cis correct because it captures the essence of inherent risk as the baseline risk level and residual risk as the mitigated level after control actions.
* Option Ainaccurately states that residual risk is tied to the completion of a risk assessment process instead of mitigation actions.
* Option Bconfuses inherent risk with risk appetite, which reflects the organization's tolerance for risk.
* Significance of Differentiation:
* Understanding both risk levels helps prioritize resources for managing critical risks and improving controls.