CORES CORES Governance Frameworks & Risk Appetite 1 — Questions and Answers
Question 1: Which body is primarily responsible for approving a firm's operational risk appetite statement?
- The Board of Directors (Correct answer)
- The Chief Risk Officer
- The Internal Audit Committee
- The compliance department
Correct answer: The Board of Directors
The Board of Directors holds ultimate accountability for approving the operational risk appetite statement to ensure alignment with overall corporate strategy.
Question 2: A Risk Appetite Statement (RAS) for operational risk should primarily communicate which of the following?
- The amount and types of operational risk a firm is willing to accept in pursuit of its objectives (Correct answer)
- The specific dollar threshold for individual loss events
- The list of prohibited business activities
- The number of full-time risk staff required
Correct answer: The amount and types of operational risk a firm is willing to accept in pursuit of its objectives
A RAS defines the aggregate level and types of operational risk the firm is willing to accept, linking risk tolerance to strategic goals.
Question 3: Under the Three Lines of Defense model, which line is responsible for day-to-day operational risk management within business units?
- First line (Correct answer)
- Second line
- Third line
- Fourth line
Correct answer: First line
The first line of defense consists of business unit managers and staff who own and manage operational risks in their daily activities.
Question 4: What is the primary purpose of an Operational Risk Management Framework (ORMF)?
- To provide a structured approach for identifying, assessing, monitoring, and mitigating operational risks (Correct answer)
- To eliminate all operational losses
- To assign blame when incidents occur
- To satisfy external auditors exclusively
Correct answer: To provide a structured approach for identifying, assessing, monitoring, and mitigating operational risks
An ORMF establishes the policies, processes, and tools that guide consistent identification, assessment, monitoring, and mitigation of operational risk across the organization.
Question 5: Risk tolerance differs from risk appetite in that risk tolerance refers to:
- The acceptable variation around risk appetite thresholds before escalation is required (Correct answer)
- The maximum possible loss the firm could ever sustain
- The board's preference for low-risk investments
- The minimum capital the firm must hold
Correct answer: The acceptable variation around risk appetite thresholds before escalation is required
Risk tolerance defines the acceptable deviation or buffer around the risk appetite level, triggering escalation or corrective action when breached.
Question 6: Which governance principle ensures that risk management decisions are made by personnel with appropriate authority and expertise?
- Segregation of duties and delegated authority (Correct answer)
- Centralized decision-making
- Profit-center self-governance
- Voluntary compliance programs
Correct answer: Segregation of duties and delegated authority
Segregation of duties and clearly delegated authority matrices ensure that no single individual can approve and execute risk-taking decisions without appropriate oversight.
Which body is primarily responsible for approving a firm's operational risk appetite statement?