CORES CORES Operational Risk Governance & Framework Design 1 — Questions and Answers
Question 1: Which body is primarily responsible for setting the overall tone and oversight of operational risk governance at the enterprise level?
- The internal audit department
- The board of directors (Correct answer)
- The compliance team
- The IT security division
Correct answer: The board of directors
The board of directors bears ultimate responsibility for setting the risk appetite and overseeing the operational risk governance framework.
Question 2: In the three lines of defense model, which line is responsible for owning and managing operational risk in day-to-day business activities?
- Third line — internal audit
- Second line — risk management function
- First line — business units (Correct answer)
- External auditors
Correct answer: First line — business units
The first line of defense consists of business unit managers and staff who own and manage risks in their daily operations.
Question 3: What is the primary purpose of a Risk Appetite Statement (RAS) in an operational risk framework?
- To list all past operational losses
- To define the amount and type of risk the organization is willing to accept (Correct answer)
- To assign liability for risk events to specific employees
- To replace the need for internal controls
Correct answer: To define the amount and type of risk the organization is willing to accept
A Risk Appetite Statement articulates the level and types of risk an organization is willing to tolerate in pursuit of its strategic objectives.
Question 4: Which operational risk framework component ensures that risk management policies are consistently applied across all business lines?
- Loss event database
- Risk governance structure (Correct answer)
- Capital adequacy ratio
- Stress testing model
Correct answer: Risk governance structure
A robust risk governance structure—with clear roles, policies, and escalation paths—ensures consistent application of risk management practices enterprise-wide.
Question 5: Under the CORES framework, what distinguishes a 'risk owner' from a 'risk manager'?
- Risk owners set capital buffers; risk managers approve them
- Risk owners are accountable for the risk outcome; risk managers provide oversight and tools (Correct answer)
- Risk owners report to external regulators; risk managers report internally
- Risk owners handle cyber risk only; risk managers handle all other risks
Correct answer: Risk owners are accountable for the risk outcome; risk managers provide oversight and tools
Risk owners are accountable for outcomes within their business area, while risk managers in the second line provide frameworks, tools, and oversight.
Question 6: Which governance document formally defines the scope, objectives, and methodology of an organization's operational risk management program?
- Business continuity plan
- Operational risk management policy (Correct answer)
- Annual report
- IT disaster recovery plan
Correct answer: Operational risk management policy
The operational risk management policy formally establishes the program's scope, objectives, roles, methodologies, and accountability structures.
Which body is primarily responsible for setting the overall tone and oversight of operational risk governance at the enterprise level?