CORES Process Mapping & Control Assessment 3 — Questions and Answers
Question 1: A control effectiveness rating of 'partially effective' in a RCSA means MOST specifically that:
- The control operates as designed but the risk it covers is immaterial
- The control mitigates some but not all of the targeted risk, leaving residual exposure (Correct answer)
- Testing was inconclusive due to insufficient sample size
- Management has approved a risk acceptance for the full residual risk
Correct answer: The control mitigates some but not all of the targeted risk, leaving residual exposure
'Partially effective' means the control reduces but does not adequately cover the risk, requiring additional mitigation or risk acceptance.
Question 2: Which technique BEST captures the 'as-operated' version of a process when it differs significantly from documented procedures?
- Reviewing approved process maps from the design phase
- Conducting structured walkthroughs with employees who execute the process daily (Correct answer)
- Analyzing the organization chart for role responsibilities
- Reviewing the IT system's technical architecture diagrams
Correct answer: Conducting structured walkthroughs with employees who execute the process daily
Structured walkthroughs with frontline staff reveal actual execution patterns, workarounds, and deviations from documented procedures.
Question 3: In control design assessment, 'frequency of operation' is evaluated to determine whether:
- The control is automated or manual in nature
- The control operates often enough to detect or prevent risk within an acceptable timeframe (Correct answer)
- The control owner has adequate capacity to perform their duties
- The control testing budget is appropriately allocated
Correct answer: The control operates often enough to detect or prevent risk within an acceptable timeframe
Frequency assessment ensures the control operates at intervals that match the speed at which the risk can materialize and cause harm.
Question 4: When a process map reveals that a high-risk step has no associated preventive control, the risk practitioner should FIRST:
- Escalate to the board's audit committee immediately
- Assess whether compensating detective or corrective controls provide sufficient coverage (Correct answer)
- Shut down the process pending control implementation
- Accept the risk without further analysis since the gap is already mapped
Correct answer: Assess whether compensating detective or corrective controls provide sufficient coverage
Before escalation or shutdown, the practitioner evaluates whether existing detective or corrective controls together provide adequate compensating mitigation.
Question 5: The 'coverage ratio' in a control assessment context refers to:
- The percentage of process steps that have at least one associated control (Correct answer)
- The ratio of automated controls to manual controls in the control library
- The proportion of risks that fall within the organization's risk appetite
- The percentage of control tests completed within the audit cycle
Correct answer: The percentage of process steps that have at least one associated control
Coverage ratio measures what fraction of process steps are protected by at least one control, identifying unprotected gaps in the process.
Question 6: A process map for a payment authorization workflow should include which element to satisfy operational risk requirements?
- Salary information for each role executing the process
- Exception handling paths for failed or rejected transactions (Correct answer)
- Marketing approval gates for customer-facing communications
- Historical loss data embedded within each process step
Correct answer: Exception handling paths for failed or rejected transactions
Exception handling paths are critical for operational risk because they define how the process behaves under failure conditions, which is where losses often occur.
Question 7: When performing a control gap analysis, a 'design gap' differs from an 'operating gap' in that a design gap means:
- The control was never tested and its effectiveness is unknown
- The control concept itself is insufficient to address the risk even if executed perfectly (Correct answer)
- Staff lack the training to operate the control as documented
- The control operates less frequently than specified in the procedure
Correct answer: The control concept itself is insufficient to address the risk even if executed perfectly
A design gap exists when the control's structure or logic cannot adequately mitigate the risk regardless of how well it is performed.
A control effectiveness rating of 'partially effective' in a RCSA means MOST specifically that: