CORES CORES Governance Frameworks & Risk Appetite 2 — Questions and Answers
Question 1: Which of the following best describes an Operational Risk Policy?
- A document that sets out principles, responsibilities, and minimum standards for managing operational risk (Correct answer)
- A list of approved vendors for risk software
- A summary of recent operational loss events
- A marketing document for regulators
Correct answer: A document that sets out principles, responsibilities, and minimum standards for managing operational risk
An operational risk policy establishes the overarching principles, roles, responsibilities, and minimum standards that all business units must follow.
Question 2: When embedding operational risk governance into new product approval, what is the key objective?
- To identify and mitigate operational risks before a product or service is launched (Correct answer)
- To ensure the product generates maximum revenue
- To delay product launches for thorough regulatory review
- To transfer all product risk to the customer
Correct answer: To identify and mitigate operational risks before a product or service is launched
New product approval processes embed operational risk review so that risks are identified and controls are established before launch, not after incidents occur.
Question 3: A firm's risk committee charter should include which of the following elements?
- Membership, mandate, meeting frequency, escalation procedures, and reporting lines (Correct answer)
- A list of all employees and their salaries
- The firm's marketing strategy
- Detailed IT system architecture
Correct answer: Membership, mandate, meeting frequency, escalation procedures, and reporting lines
A risk committee charter formalizes the committee's purpose, membership, operating procedures, and how it escalates issues and reports to the board.
Question 4: The concept of 'risk ownership' in operational risk governance means:
- Business unit managers are accountable for managing the risks within their areas (Correct answer)
- The risk department owns all risks enterprise-wide
- Risk ownership rotates annually among executives
- External auditors own risk findings until resolved
Correct answer: Business unit managers are accountable for managing the risks within their areas
Risk ownership assigns accountability to business unit managers, ensuring that those closest to the risk have responsibility for managing and monitoring it.
Question 5: Which metric is most directly used to monitor whether a firm is operating within its stated risk appetite?
- Key Risk Indicators (KRIs) linked to risk appetite thresholds (Correct answer)
- Total revenue growth rate
- Number of employees trained on compliance
- Credit default swap spreads
Correct answer: Key Risk Indicators (KRIs) linked to risk appetite thresholds
KRIs are calibrated to risk appetite thresholds so that breaches signal when the firm is approaching or exceeding acceptable risk levels.
Question 6: Under sound operational risk governance, how often should the risk appetite statement typically be reviewed?
- At least annually and after significant business or risk profile changes (Correct answer)
- Every five years on a fixed schedule
- Only when a major loss event occurs
- Whenever the CFO requests a review
Correct answer: At least annually and after significant business or risk profile changes
Best practice requires annual review of the RAS at minimum, with ad hoc updates triggered by material changes in strategy, operations, or risk environment.
Which of the following best describes an Operational Risk Policy?