CORES Process Mapping & Control Assessment 2 — Questions and Answers
Question 1: When applying a SIPOC diagram to operational risk analysis, what does the 'S' component primarily help identify?
- Suppliers whose failures could introduce input risk into a process (Correct answer)
- Systems used to automate control execution
- Supervisors accountable for control ownership
- Standards governing regulatory compliance
Correct answer: Suppliers whose failures could introduce input risk into a process
SIPOC's 'Suppliers' component reveals upstream dependency risks where third-party or internal provider failures propagate into the process.
Question 2: A swim lane diagram is most useful in operational risk process mapping because it explicitly shows:
- Data volumes flowing through each process step
- Handoff points between departments where errors commonly occur (Correct answer)
- The financial cost of each control activity
- IT system latency at each processing node
Correct answer: Handoff points between departments where errors commonly occur
Swim lane diagrams visualize cross-functional handoffs, which are prime locations for miscommunication and operational errors.
Question 3: During a control assessment, a detective control is found to have a 30-day detection lag for fraud events. The BEST immediate response is to:
- Accept the risk because detective controls are inherently delayed
- Implement a compensating preventive control to reduce exposure during the lag (Correct answer)
- Remove the detective control and rely on corrective controls only
- Increase the control frequency to daily execution
Correct answer: Implement a compensating preventive control to reduce exposure during the lag
A 30-day detection lag creates significant undetected exposure, so a preventive compensating control reduces the window of vulnerability.
Question 4: Which process mapping element is MOST critical for identifying single points of failure in an operational workflow?
- Decision diamonds showing conditional logic
- Resource annotations on each task box
- Sequential dependency links between process steps (Correct answer)
- Audit trail notations on data stores
Correct answer: Sequential dependency links between process steps
Sequential dependency links reveal which steps have no parallel path or bypass, exposing single points of failure that halt the entire process.
Question 5: A risk and control self-assessment (RCSA) workshop reveals that process owners routinely override a key authorization control. This pattern MOST likely indicates:
- The control is appropriately calibrated for risk tolerance
- A control design deficiency that creates excessive friction in the process (Correct answer)
- Evidence that the risk is fully mitigated by other controls
- Adequate compensating controls exist to absorb the override risk
Correct answer: A control design deficiency that creates excessive friction in the process
Systematic overrides signal that the control is too burdensome relative to the process flow, indicating a design flaw that must be corrected.
Question 6: In operational risk terminology, a 'key control' is distinguished from a general control primarily by its:
- Lower implementation cost and simpler testing procedures
- Direct mitigation of a significant identified risk within a critical process (Correct answer)
- Regulatory mandate requiring annual attestation
- Automated execution without human intervention
Correct answer: Direct mitigation of a significant identified risk within a critical process
A key control directly addresses a material risk in a critical process; its failure would result in significant risk materialization.
Question 7: When mapping end-to-end processes for operational risk purposes, which document type provides the MOST authoritative baseline for 'as-designed' process flows?
- Interview transcripts from frontline staff
- Procedure manuals and standard operating procedures (SOPs) (Correct answer)
- Audit findings from the prior year's review
- Management self-certifications submitted quarterly
Correct answer: Procedure manuals and standard operating procedures (SOPs)
SOPs and procedure manuals represent the formally approved 'as-designed' process, providing the baseline against which 'as-operated' gaps are measured.
When applying a SIPOC diagram to operational risk analysis, what does the 'S' component primarily help identify?