CORES Operational Risk Identification & Assessment 4 — Questions and Answers
Question 1: A 'near miss' event in operational risk management is BEST described as:
- A loss event that exceeds the reporting threshold
- An incident that could have caused a loss but did not due to luck or intervention (Correct answer)
- A risk that has been accepted and logged in the risk register
- A control failure with no associated risk event
Correct answer: An incident that could have caused a loss but did not due to luck or intervention
Near-miss events reveal system vulnerabilities without causing actual loss, making them valuable early warning signals when captured and analyzed.
Question 2: When using the bow-tie method for operational risk, the 'barrier' on the left side of the event represents:
- Recovery controls that limit impact after the event
- Preventive controls that reduce the likelihood of the hazard causing the event (Correct answer)
- The risk appetite threshold
- Post-incident reporting requirements
Correct answer: Preventive controls that reduce the likelihood of the hazard causing the event
Left-side barriers (threat barriers) in a bow-tie diagram are preventive controls designed to stop a hazard from escalating into a top event.
Question 3: Which risk assessment dimension evaluates how difficult it would be for the firm to detect an operational risk event once it has occurred?
- Velocity
- Detectability (Correct answer)
- Correlation
- Connectivity
Correct answer: Detectability
Detectability assesses the ease or difficulty of identifying that a risk event has taken place, influencing how quickly the firm can respond.
Question 4: A firm conducts top-down risk identification by having the board and senior executives identify key risks facing the organization. The MAIN limitation of this approach is:
- It tends to miss strategic risks
- It may overlook granular, process-level risks that are visible only at the operational level (Correct answer)
- It produces too many risks for the heat map
- It cannot be used alongside bottom-up approaches
Correct answer: It may overlook granular, process-level risks that are visible only at the operational level
Top-down identification captures high-level risks efficiently but may miss the detailed, day-to-day operational risks that front-line staff encounter.
Question 5: The expected loss (EL) in operational risk is calculated as:
- Probability of Loss × Severity of Loss (Correct answer)
- Value at Risk − Economic Capital
- Gross Loss − Insurance Recovery
- Control Effectiveness Rating × Inherent Risk Score
Correct answer: Probability of Loss × Severity of Loss
Expected Loss equals the probability (likelihood) of an event multiplied by the severity (impact) of the loss if the event occurs.
Question 6: Which of the following is an example of a 'people risk' under the operational risk taxonomy?
- A software system outage caused by a hardware failure
- Unauthorized trading by a rogue employee (Correct answer)
- Flood damage to a branch office
- A vendor failing to deliver contracted services
Correct answer: Unauthorized trading by a rogue employee
Unauthorized trading is a classic people-risk event driven by employee misconduct, falling under the 'Internal Fraud' Basel event-type category.
Question 7: When aggregating risks across business lines for enterprise-level reporting, a key challenge is:
- Ensuring every risk has a unique identifier
- Accounting for risk correlations and avoiding double-counting or under-counting aggregate exposure (Correct answer)
- Selecting a risk appetite statement
- Determining audit frequency
Correct answer: Accounting for risk correlations and avoiding double-counting or under-counting aggregate exposure
Aggregation must account for correlations between risks; simply summing individual risk scores can overstate or understate true enterprise exposure.
A 'near miss' event in operational risk management is BEST described as: