CORES Key Risk Indicator Development 5 — Questions and Answers
Question 1: Which of the following represents the BEST example of a KRI with strong predictive validity for cybersecurity operational risk?
- Total number of security policies in the policy library
- Percentage of critical systems with overdue patch remediation (Correct answer)
- Annual IT budget allocated to cybersecurity tools
- Number of cybersecurity staff employed last year
Correct answer: Percentage of critical systems with overdue patch remediation
Unpatched critical systems directly increase the attack surface and have a documented statistical relationship with successful breaches, giving this KRI strong predictive validity.
Question 2: A risk manager notices that a KRI for transaction error rate has been in the green zone for 12 consecutive months without any threshold changes. What action is MOST appropriate?
- No action needed — green status confirms the risk is well-managed
- Review whether the threshold is set too loosely and lacks discriminating power (Correct answer)
- Retire the KRI since it has never triggered
- Escalate to the board as an indicator of under-reporting
Correct answer: Review whether the threshold is set too loosely and lacks discriminating power
A KRI that never leaves the green zone may have a threshold that is too generous to detect meaningful risk changes, requiring recalibration to remain useful.
Question 3: Under Basel II/III operational risk guidance, how do KRIs relate to the Advanced Measurement Approach (AMA)?
- KRIs replace loss data as the primary input for capital calculation
- KRIs serve as a qualitative/forward-looking component alongside internal and external loss data (Correct answer)
- KRIs are not recognized under Basel frameworks
- KRIs determine the minimum capital floor for operational risk
Correct answer: KRIs serve as a qualitative/forward-looking component alongside internal and external loss data
Under AMA, KRIs form part of the four-data-element framework alongside internal losses, external losses, and scenario analysis to produce a comprehensive risk capital estimate.
Question 4: When performing a KRI gap analysis for a newly acquired subsidiary, what is the PRIMARY output expected?
- A ranked list of the subsidiary's top 10 historical losses
- A list of material risks in the subsidiary that lack adequate KRI coverage (Correct answer)
- A revised org chart showing new risk ownership assignments
- An updated risk appetite statement for the consolidated entity
Correct answer: A list of material risks in the subsidiary that lack adequate KRI coverage
A KRI gap analysis identifies material risks that are not yet monitored by any indicator, enabling the organization to build out monitoring coverage before losses occur.
Question 5: Which approach BEST ensures KRI thresholds remain relevant as the business environment changes?
- Setting thresholds once at program inception and documenting the rationale
- Embedding a periodic review cycle (e.g., annual or after major risk events) into the governance framework (Correct answer)
- Delegating threshold updates to individual KRI owners without formal approval
- Benchmarking thresholds against competitor public disclosures quarterly
Correct answer: Embedding a periodic review cycle (e.g., annual or after major risk events) into the governance framework
A structured periodic review tied to governance ensures thresholds are updated systematically in response to business changes, not left to drift or be changed ad hoc.
Question 6: A KRI owner submits data that consistently rounds figures to reduce apparent risk exposure. This behavior is BEST addressed through which control?
- Requiring more frequent data submissions
- Independent data validation by a second-line or internal audit function (Correct answer)
- Publishing KRI results to all employees to create peer pressure
- Replacing the KRI with an automated system feed
Correct answer: Independent data validation by a second-line or internal audit function
Independent validation by a function separate from the data owner detects manipulation or bias in KRI reporting and preserves the integrity of the risk monitoring framework.
Question 7: In developing a KRI for outsourcing/vendor risk, which metric is generally considered the MOST forward-looking?
- Dollar value of losses from vendor failures in the past year
- Percentage of critical vendors that have completed current business continuity testing (Correct answer)
- Number of vendor contracts renewed in the past quarter
- Average tenure of vendor relationship managers
Correct answer: Percentage of critical vendors that have completed current business continuity testing
BCP testing completion rate signals whether vendors are prepared for disruptions before any failure occurs, making it a predictive rather than retrospective measure.
Which of the following represents the BEST example of a KRI with strong predictive validity for cybersecurity operational risk?