CORES Cheat Sheet 2026

The 30 highest-yield CORES facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.

100 questions
90 min time limit
70.00% to pass
  1. Which governance principle ensures that individuals cannot both authorize and execute a transaction without a separate review? Segregation of duties
  2. A firm's loss database shows clustering of events at the end of each quarter. What data quality issue does this most likely indicate? Delayed booking or reporting bias distorting event dates
  3. Which document outlines steps to recover operations after a disaster? Business Continuity Plan (BCP)
  4. Which BCP component specifically addresses continuity of critical operations when key personnel are unavailable? Succession planning and cross-training program
  5. Basel II introduced the Three Pillars framework. Which pillar specifically covers market discipline through public disclosure requirements? Pillar 3
  6. In the context of CORES certification, what is the most important consideration when implementing vendor & third-party risk oversight? Ensuring alignment with established standards, stakeholder needs, and best practices
  7. Which of the following is an example of an operational risk event? IT system outage
  8. A firm maps its loan origination process and finds that the same employee approves and books a loan. This represents which fundamental control weakness? Lack of segregation of duties (SoD)
  9. Which body is primarily responsible for approving a firm's operational risk appetite statement? The Board of Directors
  10. What is the recommended maximum number of KRIs per risk category according to most operational risk best-practice frameworks? Typically 3–7 high-quality KRIs per category to maintain focus and actionability
  11. Which of the following is a compliance-related law in finance? Sarbanes-Oxley Act (SOX)
  12. When a process map reveals that a high-risk step has no associated preventive control, the risk practitioner should FIRST: Assess whether compensating detective or corrective controls provide sufficient coverage
  13. In a process risk assessment, 'inherent complexity' of a process step is considered because higher complexity typically: Increases the likelihood of human error and the need for stronger controls
  14. Which attack technique involves embedding malicious code in a legitimate website visited by targeted employees to deliver malware without direct interaction? Watering hole attack
  15. Which approach is used when a risk cannot be eliminated? Risk transfer
  16. Why is it important to test the business continuity plan regularly? To ensure the plan works during an actual event
  17. Under U.S. banking regulation, which guidance specifically articulates supervisory expectations for internal audit functions at large financial institutions? SR 03-5: Amended Interagency Guidance on the Internal Audit Function
  18. What is the primary purpose of a Risk Appetite Statement (RAS) in an operational risk framework? To define the amount and type of risk the organization is willing to accept
  19. The expected loss (EL) in operational risk is calculated as: Probability of Loss × Severity of Loss
  20. Which of the following best describes a key competency required for scenario analysis & stress testing in CORES practice? Strong analytical skills combined with effective communication and ethical judgment
  21. What is the minimum Basel III Leverage Ratio requirement for internationally active banks? 3%
  22. A firm conducts a geopolitical stress test assuming a major trade war. Which operational risk sub-category is MOST directly activated? Business disruption and system failures through supply chain impacts
  23. What is the primary purpose of a cyber tabletop exercise in an operational risk program? To test response coordination and decision-making without real operational impact
  24. In the Three Lines of Defense model, which line is primarily responsible for owning and managing operational risks on a day-to-day basis? Business units and operational management
  25. Which method is used to combine internal loss data with external loss data to address the scarcity of high-severity tail events in internal databases? Scaled external data integration
  26. Under NIST SP 800-53, which control family specifically addresses incident response planning for IT systems? Incident Response (IR)
  27. In the context of CORES certification, what is the most important consideration when implementing loss data collection & analysis? Ensuring alignment with established standards, stakeholder needs, and best practices
  28. Which Basel I concept was criticized for allowing significant regulatory capital arbitrage through securitization? The bucket-based risk weight system with limited differentiation within credit categories
  29. Under the DFAST (Dodd-Frank Act Stress Testing) framework, what is the minimum capital ratio that must be maintained throughout the stress test horizon? Common Equity Tier 1 ratio of 4.5%
  30. Under sound operational risk governance, how often should the risk appetite statement typically be reviewed? At least annually and after significant business or risk profile changes
Turn these facts into recall:
Was this helpful?