CORES Operational Risk Identification & Assessment 2 — Questions and Answers
Question 1: Which technique involves creating a visual map of all processes, inputs, outputs, and risk points within a business unit?
- Control self-assessment
- Process flow mapping (Correct answer)
- Bow-tie analysis
- SWOT analysis
Correct answer: Process flow mapping
Process flow mapping visually documents each step, handoff, and potential failure point within a business process to surface operational risks.
Question 2: A bank's operational risk team notices that the same data entry error type recurs monthly. Which risk identification approach is BEST suited to uncover the root cause?
- Horizon scanning
- Key Risk Indicator trending
- Loss event analysis with fishbone diagrams (Correct answer)
- Scenario analysis
Correct answer: Loss event analysis with fishbone diagrams
Loss event analysis combined with fishbone (Ishikawa) diagrams systematically traces recurring errors back to their root causes.
Question 3: In the Basel II/III operational risk framework, which of the following is NOT one of the seven Basel event-type categories?
- Execution, Delivery & Process Management
- Clients, Products & Business Practices
- Market Liquidity Disruption (Correct answer)
- Internal Fraud
Correct answer: Market Liquidity Disruption
Market Liquidity Disruption is a market risk concept; the seven Basel operational risk event types do not include it.
Question 4: When scoring risks on a heat map, 'velocity' refers to:
- The frequency with which a risk is reviewed
- How quickly a risk can escalate from onset to significant impact (Correct answer)
- The speed at which a control is implemented
- The rate of change in the risk appetite statement
Correct answer: How quickly a risk can escalate from onset to significant impact
Velocity measures how rapidly a risk event can develop and cause harm, which affects response time requirements.
Question 5: Which assessment method asks managers to self-evaluate their unit's controls and risks using structured questionnaires or workshops?
- External audit
- Control Self-Assessment (CSA) (Correct answer)
- Regulatory examination
- Peer benchmarking
Correct answer: Control Self-Assessment (CSA)
Control Self-Assessment (CSA) empowers business line managers to identify and evaluate their own risks and controls without waiting for external review.
Question 6: A firm uses a 5×5 risk matrix where likelihood is rated 1–5 and impact is rated 1–5. A risk scored 4×4 falls into the same heat-map zone as a risk scored:
- 2×8
- 8×2
- 2×5 and 5×2
- Any pair whose product equals 16 (Correct answer)
Correct answer: Any pair whose product equals 16
On a multiplicative risk matrix, any likelihood-impact pair whose product equals 16 produces the same inherent risk score.
Question 7: The 'emerging risk' identification process primarily differs from standard risk identification because it focuses on:
- Quantifying losses from past events
- Detecting novel threats before they fully materialize (Correct answer)
- Assigning residual risk scores to existing controls
- Reporting known risks to senior management
Correct answer: Detecting novel threats before they fully materialize
Emerging risk identification uses horizon scanning and expert judgment to spot threats that have not yet caused losses but could in the future.
Which technique involves creating a visual map of all processes, inputs, outputs, and risk points within a business unit?