CORES CORES Operational Risk Governance & Framework Design 2 — Questions and Answers
Question 1: What is the key difference between a risk committee and an audit committee in operational risk governance?
- The risk committee focuses on forward-looking risk oversight; the audit committee focuses on backward-looking assurance (Correct answer)
- The audit committee sets risk appetite; the risk committee executes audits
- The risk committee reports to regulators; the audit committee reports to management
- There is no meaningful distinction between the two committees
Correct answer: The risk committee focuses on forward-looking risk oversight; the audit committee focuses on backward-looking assurance
The risk committee is forward-looking, overseeing risk strategy and appetite, while the audit committee provides backward-looking assurance on internal controls and financial reporting.
Question 2: In designing an operational risk framework, what does 'scalability' mean?
- The framework applies only to the largest business units
- The framework can be appropriately adapted to different sizes and complexities of business activities (Correct answer)
- The framework uses automated tools exclusively
- The framework is limited to financial institutions
Correct answer: The framework can be appropriately adapted to different sizes and complexities of business activities
A scalable framework is designed to be proportional and adaptable, so it can be applied consistently across business units of varying size and complexity.
Question 3: Which element is most critical for embedding operational risk governance into strategic decision-making?
- Monthly loss reporting to the CFO
- Integration of risk considerations into business planning and new product approval processes (Correct answer)
- Quarterly IT security patches
- Annual external audit reviews
Correct answer: Integration of risk considerations into business planning and new product approval processes
Embedding risk governance into strategic and business planning—including new product approvals—ensures risk is considered before decisions are made, not after.
Question 4: What role does the Chief Risk Officer (CRO) play in a CORES-aligned operational risk governance structure?
- Approving all individual transactions above a set threshold
- Serving as the head of internal audit
- Leading the enterprise risk management function and reporting to the board on risk matters (Correct answer)
- Managing the IT infrastructure security team
Correct answer: Leading the enterprise risk management function and reporting to the board on risk matters
The CRO leads the enterprise risk management function, ensures the risk framework is effective, and regularly reports risk status and concerns to the board.
Question 5: How does an escalation framework contribute to effective operational risk governance?
- It eliminates the need for management reporting
- It ensures material risk events and limit breaches are quickly surfaced to appropriate decision-makers (Correct answer)
- It replaces the need for a risk appetite statement
- It limits risk reporting to annual cycles
Correct answer: It ensures material risk events and limit breaches are quickly surfaced to appropriate decision-makers
An escalation framework defines thresholds and procedures that ensure significant risk events reach the right decision-makers quickly so appropriate action can be taken.
Question 6: Which of the following best describes the concept of 'risk culture' within an operational risk governance framework?
- The set of automated controls that prevent errors
- The shared values, beliefs, and behaviors that shape how risk is managed across the organization (Correct answer)
- The capital reserve set aside for unexpected losses
- The external regulatory guidelines followed by compliance officers
Correct answer: The shared values, beliefs, and behaviors that shape how risk is managed across the organization
Risk culture encompasses the shared attitudes, values, and norms that influence how employees identify, assess, and manage risk in their daily work.
What is the key difference between a risk committee and an audit committee in operational risk governance?