CORES Cheat Sheet 2026
The 30 highest-yield CORES facts, distilled from real exam questions. Print it, save it as a PDF, or study it here — free, no sign-up.
100 questions
90 min time limit
70.00% to pass
- Which governance principle ensures that individuals cannot both authorize and execute a transaction without a separate review? → Segregation of duties
- A firm's loss database shows clustering of events at the end of each quarter. What data quality issue does this most likely indicate? → Delayed booking or reporting bias distorting event dates
- Which document outlines steps to recover operations after a disaster? → Business Continuity Plan (BCP)
- Which BCP component specifically addresses continuity of critical operations when key personnel are unavailable? → Succession planning and cross-training program
- Basel II introduced the Three Pillars framework. Which pillar specifically covers market discipline through public disclosure requirements? → Pillar 3
- In the context of CORES certification, what is the most important consideration when implementing vendor & third-party risk oversight? → Ensuring alignment with established standards, stakeholder needs, and best practices
- Which of the following is an example of an operational risk event? → IT system outage
- A firm maps its loan origination process and finds that the same employee approves and books a loan. This represents which fundamental control weakness? → Lack of segregation of duties (SoD)
- Which body is primarily responsible for approving a firm's operational risk appetite statement? → The Board of Directors
- What is the recommended maximum number of KRIs per risk category according to most operational risk best-practice frameworks? → Typically 3–7 high-quality KRIs per category to maintain focus and actionability
- Which of the following is a compliance-related law in finance? → Sarbanes-Oxley Act (SOX)
- When a process map reveals that a high-risk step has no associated preventive control, the risk practitioner should FIRST: → Assess whether compensating detective or corrective controls provide sufficient coverage
- In a process risk assessment, 'inherent complexity' of a process step is considered because higher complexity typically: → Increases the likelihood of human error and the need for stronger controls
- Which attack technique involves embedding malicious code in a legitimate website visited by targeted employees to deliver malware without direct interaction? → Watering hole attack
- Which approach is used when a risk cannot be eliminated? → Risk transfer
- Why is it important to test the business continuity plan regularly? → To ensure the plan works during an actual event
- Under U.S. banking regulation, which guidance specifically articulates supervisory expectations for internal audit functions at large financial institutions? → SR 03-5: Amended Interagency Guidance on the Internal Audit Function
- What is the primary purpose of a Risk Appetite Statement (RAS) in an operational risk framework? → To define the amount and type of risk the organization is willing to accept
- The expected loss (EL) in operational risk is calculated as: → Probability of Loss × Severity of Loss
- Which of the following best describes a key competency required for scenario analysis & stress testing in CORES practice? → Strong analytical skills combined with effective communication and ethical judgment
- What is the minimum Basel III Leverage Ratio requirement for internationally active banks? → 3%
- A firm conducts a geopolitical stress test assuming a major trade war. Which operational risk sub-category is MOST directly activated? → Business disruption and system failures through supply chain impacts
- What is the primary purpose of a cyber tabletop exercise in an operational risk program? → To test response coordination and decision-making without real operational impact
- In the Three Lines of Defense model, which line is primarily responsible for owning and managing operational risks on a day-to-day basis? → Business units and operational management
- Which method is used to combine internal loss data with external loss data to address the scarcity of high-severity tail events in internal databases? → Scaled external data integration
- Under NIST SP 800-53, which control family specifically addresses incident response planning for IT systems? → Incident Response (IR)
- In the context of CORES certification, what is the most important consideration when implementing loss data collection & analysis? → Ensuring alignment with established standards, stakeholder needs, and best practices
- Which Basel I concept was criticized for allowing significant regulatory capital arbitrage through securitization? → The bucket-based risk weight system with limited differentiation within credit categories
- Under the DFAST (Dodd-Frank Act Stress Testing) framework, what is the minimum capital ratio that must be maintained throughout the stress test horizon? → Common Equity Tier 1 ratio of 4.5%
- Under sound operational risk governance, how often should the risk appetite statement typically be reviewed? → At least annually and after significant business or risk profile changes
Turn these facts into recall:
Was this helpful?