CORES Certified Operational Risk Executive Specialist — Questions and Answers
Question 1: How should CORES professionals handle confidential information related to process mapping & control assessment?
- Delete all records after project completion
- Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations (Correct answer)
- Share freely with all colleagues for transparency
- Store information without any security measures
Correct answer: Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations
Confidential information must be handled according to established protocols, regulatory requirements, and professional ethics standards, including proper access control and disclosure procedures.
Question 2: When rating audit findings, a 'high' or 'critical' severity classification typically indicates:
- A theoretical risk with no current evidence of occurrence
- A minor process improvement opportunity with limited financial impact
- A finding that management has already remediated
- A significant control gap exposing the organization to material risk or regulatory breach (Correct answer)
Correct answer: A significant control gap exposing the organization to material risk or regulatory breach
High/critical findings represent material control failures that could result in significant financial loss, regulatory sanction, or reputational damage requiring urgent remediation.
Question 3: Which element is essential for making operational risk reports 'actionable'?
- Technical jargon that demonstrates analytical rigor
- Historical benchmarks from 10+ years ago
- Lengthy narrative descriptions of industry trends
- Recommendations or suggested actions tied to each identified risk or control gap (Correct answer)
Correct answer: Recommendations or suggested actions tied to each identified risk or control gap
Actionable reports pair each finding with specific recommendations, enabling business lines and management to take concrete steps to address identified risks or gaps.
Question 4: What is a key benefit of having a business continuity strategy?
- It eliminates all risks permanently.
- It guarantees profits regardless of incidents.
- It decreases market reputation.
- It allows operations to continue during crises (Correct answer)
Correct answer: It allows operations to continue during crises
A key benefit of having a business continuity strategy is its ability to enable an organization to maintain essential functions and services during significant crises. By planning for disruptions like natural disasters or cyberattacks, businesses can minimize downtime, protect assets, and sustain critical operations. This reduces financial losses and preserves market reputation.
Question 5: Which practice BEST supports the integrity of the audit follow-up process for operational risk findings?
- Independently testing and validating that remediation actions have been effectively implemented (Correct answer)
- Accepting management's assertion that a finding is remediated without validation
- Closing all findings at the end of each fiscal year regardless of status
- Allowing the first line to self-certify remediation with no second or third line review
Correct answer: Independently testing and validating that remediation actions have been effectively implemented
Effective follow-up requires internal audit to independently verify that management's corrective actions have been implemented and are operating effectively, not merely relying on management assertions.
Question 6: Under the IIA's Three Lines Model (2020 update), which body is positioned OUTSIDE the three lines and provides governing oversight?
- External auditors
- Chief Risk Officer
- Compliance function
- Governing body (Board) (Correct answer)
Correct answer: Governing body (Board)
The 2020 IIA model places the governing body (board) outside and above the three lines, accountable to stakeholders and responsible for overseeing the entire governance structure.
Question 7: A firm is assessing the cyber risk of a newly acquired subsidiary. Which approach BEST reflects sound operational risk management practice?
- Immediately migrate all subsidiary systems to the parent's cloud environment to apply enterprise controls
- Conduct a pre-integration cyber risk assessment to identify gaps before system integration (Correct answer)
- Require the subsidiary to achieve ISO 27001 certification within 30 days of acquisition
- Assume the subsidiary's controls match the parent's standards and proceed with integration
Correct answer: Conduct a pre-integration cyber risk assessment to identify gaps before system integration
A pre-integration assessment identifies inherited vulnerabilities and control gaps before connecting systems, preventing the parent from absorbing unknown cyber risks.
Question 8: Which element is MOST critical when designing a risk mitigation control to ensure it remains effective over time?
- One-time implementation cost
- Built-in monitoring and periodic review mechanisms (Correct answer)
- Alignment with competitor practices
- Number of employees who approve the control
Correct answer: Built-in monitoring and periodic review mechanisms
Controls must include monitoring and review mechanisms because risk environments evolve, and a static control can become ineffective.
Question 9: In the context of CORES certification, what is the most important consideration when implementing loss data collection & analysis?
- Delegating all responsibilities to junior staff
- Completing implementation as quickly as possible regardless of quality
- Ensuring alignment with established standards, stakeholder needs, and best practices (Correct answer)
- Minimizing documentation to save time
Correct answer: Ensuring alignment with established standards, stakeholder needs, and best practices
When implementing loss data collection & analysis, CORES professionals must ensure alignment with industry standards and stakeholder needs. Hasty implementation without proper planning often leads to compliance issues and suboptimal outcomes.
Question 10: A bank's core banking system experiences a zero-day vulnerability exploited before a patch is available. What is the MOST appropriate immediate response?
- Apply compensating controls such as network segmentation and enhanced monitoring (Correct answer)
- Shut down all banking operations until patched
- Disclose the vulnerability publicly to get community help
- Wait for the vendor to release an official patch before taking action
Correct answer: Apply compensating controls such as network segmentation and enhanced monitoring
Compensating controls like network segmentation and enhanced monitoring reduce exposure while a formal patch is developed, balancing security with operational continuity.
Question 11: In the context of operational risk reporting, what is meant by 'forward-looking indicators'?
- Lagging indicators based on completed loss events
- Metrics that signal potential future risk deterioration before losses occur (Correct answer)
- Projections of next quarter's financial revenue
- Audit scores from the prior year's examination
Correct answer: Metrics that signal potential future risk deterioration before losses occur
Forward-looking indicators (a subset of KRIs) detect emerging risk trends or control weaknesses before they materialize into actual loss events, enabling proactive intervention.
Question 12: What role does continuous improvement play in process mapping & control assessment for CORES certified professionals?
- It is optional and only necessary during certification renewal
- It applies only to new professionals in their first year
- It focuses exclusively on cost reduction
- It drives ongoing enhancement of practices, processes, and outcomes through systematic evaluation (Correct answer)
Correct answer: It drives ongoing enhancement of practices, processes, and outcomes through systematic evaluation
Continuous improvement is fundamental to professional practice in process mapping & control assessment, involving regular evaluation, feedback integration, and process enhancement to maintain high standards.
Question 13: Which of the following best describes a key competency required for loss data collection & analysis in CORES practice?
- Memorization of all relevant regulations without understanding context
- Strong analytical skills combined with effective communication and ethical judgment (Correct answer)
- The ability to work independently without any oversight
- Reliance on a single methodology for all situations
Correct answer: Strong analytical skills combined with effective communication and ethical judgment
CORES professionals working in loss data collection & analysis need analytical skills to assess situations, communication skills to convey findings, and ethical judgment to make sound decisions.
Question 14: Which reporting failure contributed to many high-profile operational risk events at financial institutions?
- Siloed reporting that prevented senior management from seeing the aggregate risk picture across business lines (Correct answer)
- Excessive use of quantitative metrics without qualitative context
- Reporting that was too forward-looking and lacked historical grounding
- Over-reporting of minor events that distracted management attention
Correct answer: Siloed reporting that prevented senior management from seeing the aggregate risk picture across business lines
Siloed reporting allowed significant risks to build undetected in one business line while senior management lacked the aggregated view needed to recognize the emerging enterprise-wide threat.
Question 15: Which control is MOST effective at preventing loss events from being misclassified into the wrong Basel II Level 1 event type?
- Annual training on Basel event type definitions for all staff
- Automated system flags based on transaction amount
- Mandatory second-line-of-defense review of event type assignments (Correct answer)
- Requiring business lines to self-certify the event type
Correct answer: Mandatory second-line-of-defense review of event type assignments
Independent second-line review ensures business line self-reporting does not introduce systematic classification bias driven by incentives or misunderstanding.
Question 16: When building a loss distribution for AMA capital calculation, which statistical technique is commonly applied to model the frequency of operational loss events?
- Weibull distribution
- Poisson distribution (Correct answer)
- Gumbel distribution
- Lognormal distribution
Correct answer: Poisson distribution
Poisson distribution is the standard choice for modeling the count of discrete loss events per period in operational risk frameworks.
Question 17: Which data element in a loss database is MOST useful for identifying whether a loss event resulted from a control failure versus an inherent process flaw?
- Root cause classification (Correct answer)
- Basel II event type
- Recovery source
- Gross loss amount
Correct answer: Root cause classification
Root cause classification distinguishes whether the loss occurred because a control was absent, failed, or bypassed versus because the process itself is inherently risky.
Question 18: Under GDPR, which role is responsible for ensuring that personal data processing activities comply with data protection law within an organization?
- Data Protection Officer (DPO) (Correct answer)
- Chief Compliance Officer (CCO)
- Chief Risk Officer (CRO)
- Chief Information Security Officer (CISO)
Correct answer: Data Protection Officer (DPO)
The Data Protection Officer (DPO) is the designated role under GDPR responsible for advising on compliance and acting as a contact for supervisory authorities.
Question 19: A risk mitigation plan should include a 'risk owner.' What is the PRIMARY responsibility of a risk owner?
- Approving the annual risk budget
- Accountable for implementing and monitoring controls for an assigned risk (Correct answer)
- Auditing all controls across the organization
- Reporting risks directly to external regulators
Correct answer: Accountable for implementing and monitoring controls for an assigned risk
The risk owner is accountable for ensuring that specific risks are properly controlled and that mitigation actions are executed and tracked.
Question 20: A 'compensating control' is BEST defined as:
- A control that pays employees for reporting risk events
- A control that compensates for insurance coverage gaps
- A secondary approval layer added to all financial transactions
- An alternative control that mitigates risk when a primary control cannot be implemented (Correct answer)
Correct answer: An alternative control that mitigates risk when a primary control cannot be implemented
Compensating controls are substitutes deployed when the ideal primary control is not feasible, providing an alternative risk mitigation mechanism.
Question 21: How does psychological safety contribute to operational risk culture?
- It ensures employees feel physically secure in the workplace
- It enables employees to speak up about risks and errors without fear of punishment (Correct answer)
- It is a legal requirement under OSHA regulations
- It reduces the need for formal risk controls
Correct answer: It enables employees to speak up about risks and errors without fear of punishment
Psychological safety creates an environment where employees voluntarily disclose risks, near-misses, and errors, which is foundational to an effective risk-aware culture.
Question 22: When designing an operational risk report for the audit committee, what level of detail is most appropriate?
- Only positive outcomes to maintain board confidence
- Detailed coding of every individual risk event
- Full transaction logs and raw data exports
- Summarized findings with key themes, control gaps, and management responses rather than transaction-level detail (Correct answer)
Correct answer: Summarized findings with key themes, control gaps, and management responses rather than transaction-level detail
Audit committees require summarized, theme-based reporting that highlights control gaps and management actions, enabling oversight without overwhelming with operational granularity.
Question 23: Which concept describes the risk that internal controls fail to prevent or detect material errors or fraud, often assessed during operational risk reviews?
- Systemic risk
- Residual risk
- Inherent risk
- Control risk (Correct answer)
Correct answer: Control risk
Control risk is the probability that a material misstatement or failure will not be prevented or detected by the entity's internal control system.
Question 24: A financial institution's operational loss database shows a high frequency of low-severity losses but very few high-severity losses. Which statistical distribution property does this most likely indicate?
- Symmetric normal distribution of loss severity
- Uniform distribution of loss events
- Heavy-tailed (leptokurtic) severity distribution (Correct answer)
- Thin-tailed (platykurtic) severity distribution
Correct answer: Heavy-tailed (leptokurtic) severity distribution
Operational risk severity distributions are typically heavy-tailed, meaning severe events are rarer but far larger than a normal distribution would predict.
Question 25: A process that involves high-volume, repetitive transactions with low individual values MOST warrants which type of control approach?
- Automated system controls with exception-based human review (Correct answer)
- Manual, judgment-based approval for each transaction
- Quarterly management attestation covering the entire period
- Detective controls only, given the low individual transaction value
Correct answer: Automated system controls with exception-based human review
High-volume, low-value repetitive processes are best controlled through automation with exception reporting, since manual review of every transaction is impractical.
Question 26: Which metric BEST reflects the effectiveness of the audit follow-up process in reducing operational risk exposure?
- Average duration of individual audit engagements
- Number of external assessment ratings received by internal audit
- Percentage of high/critical findings remediated within agreed target dates (Correct answer)
- Total number of audit reports issued per year
Correct answer: Percentage of high/critical findings remediated within agreed target dates
Timely remediation of high/critical findings directly reduces operational risk exposure, making on-time closure rates the most meaningful indicator of audit follow-up effectiveness.
Question 27: When classifying a data breach under operational risk loss event categories (Basel II/III), which category would typically apply?
- Internal Fraud
- Execution, Delivery & Process Management
- External Fraud (Correct answer)
- Clients, Products & Business Practices
Correct answer: External Fraud
Under Basel II/III taxonomy, cyber attacks by external actors resulting in unauthorized data access are classified under External Fraud.
Question 28: Which process mapping symbol conventionally represents a decision point where alternative process paths diverge?
- Parallelogram
- Diamond (Correct answer)
- Oval
- Rectangle
Correct answer: Diamond
The diamond shape in standard flowcharting conventions denotes a decision point with branching outcomes (yes/no or alternative conditions).
Question 29: During a control assessment, a detective control is found to have a 30-day detection lag for fraud events. The BEST immediate response is to:
- Implement a compensating preventive control to reduce exposure during the lag (Correct answer)
- Remove the detective control and rely on corrective controls only
- Accept the risk because detective controls are inherently delayed
- Increase the control frequency to daily execution
Correct answer: Implement a compensating preventive control to reduce exposure during the lag
A 30-day detection lag creates significant undetected exposure, so a preventive compensating control reduces the window of vulnerability.
Question 30: What is the risk of reporting only losses above a specific threshold (i.e., applying a collection threshold)?
- High-frequency, low-severity events that signal systemic issues may be missed (Correct answer)
- KRIs will be calibrated too conservatively
- Regulatory capital calculations will be overstated
- The board will receive too much data
Correct answer: High-frequency, low-severity events that signal systemic issues may be missed
Threshold-based collection can exclude small but frequent losses that, in aggregate, indicate deeper systemic control failures or deteriorating risk culture.
Question 31: In control design assessment, 'frequency of operation' is evaluated to determine whether:
- The control is automated or manual in nature
- The control operates often enough to detect or prevent risk within an acceptable timeframe (Correct answer)
- The control testing budget is appropriately allocated
- The control owner has adequate capacity to perform their duties
Correct answer: The control operates often enough to detect or prevent risk within an acceptable timeframe
Frequency assessment ensures the control operates at intervals that match the speed at which the risk can materialize and cause harm.
CORES Certified Operational Risk Executive Specialist
The CORES certification validates advanced expertise in operational risk management for senior professionals, covering governance frameworks, risk identification and control assessment, loss data analysis, reporting, and internal audit methodologies.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds