CORES Process Mapping & Control Assessment 5 — Questions and Answers
Question 1: A 'control owner' in operational risk governance is BEST defined as the individual who:
- Designed the control during the initial implementation project
- Is accountable for the ongoing performance and effectiveness of the control (Correct answer)
- Approves the risk acceptance when the control is deemed insufficient
- Conducts independent testing of the control on behalf of internal audit
Correct answer: Is accountable for the ongoing performance and effectiveness of the control
The control owner bears ongoing accountability for ensuring the control continues to operate effectively, not merely the person who created it.
Question 2: A process that involves high-volume, repetitive transactions with low individual values MOST warrants which type of control approach?
- Manual, judgment-based approval for each transaction
- Automated system controls with exception-based human review (Correct answer)
- Quarterly management attestation covering the entire period
- Detective controls only, given the low individual transaction value
Correct answer: Automated system controls with exception-based human review
High-volume, low-value repetitive processes are best controlled through automation with exception reporting, since manual review of every transaction is impractical.
Question 3: When conducting a process walkthrough, the operational risk practitioner discovers that staff follow an undocumented shortcut that bypasses a reconciliation step. The MOST appropriate immediate action is to:
- Report the deviation to law enforcement as potential fraud
- Document the undocumented practice and assess the associated risk increase (Correct answer)
- Immediately halt all processing until the procedure is followed
- Accept the workaround as a de facto process change without further review
Correct answer: Document the undocumented practice and assess the associated risk increase
The practitioner must first document what is actually happening and evaluate the risk implications before escalating or deciding on corrective action.
Question 4: A 'control rationalization' initiative in process mapping aims to:
- Increase the total number of controls to provide maximum redundancy
- Eliminate redundant, overlapping, or ineffective controls to improve efficiency without increasing risk (Correct answer)
- Transfer control responsibilities from business lines to the risk function
- Automate all manual controls regardless of cost-benefit considerations
Correct answer: Eliminate redundant, overlapping, or ineffective controls to improve efficiency without increasing risk
Control rationalization removes unnecessary or duplicative controls, reducing compliance burden while ensuring the remaining controls provide adequate risk coverage.
Question 5: In end-to-end process mapping, identifying 'value-added' versus 'non-value-added' steps helps operational risk practitioners because non-value-added steps often:
- Automatically qualify for removal from the process without further analysis
- Represent unnecessary complexity that increases error risk without business benefit (Correct answer)
- Are the only steps where automated controls can be implemented
- Require the highest level of management authorization to perform
Correct answer: Represent unnecessary complexity that increases error risk without business benefit
Non-value-added steps add process complexity and error opportunity without contributing to the business outcome, making them prime targets for elimination or simplification.
Question 6: Which condition MOST strongly suggests that a control should be re-rated from 'effective' to 'needs improvement' during a periodic assessment?
- The control was implemented more than three years ago
- A control test sample reveals a deviation rate exceeding the established tolerance threshold (Correct answer)
- The process the control covers has not generated a loss event in the current year
- A new risk manager has taken responsibility for the control's oversight
Correct answer: A control test sample reveals a deviation rate exceeding the established tolerance threshold
A deviation rate exceeding the tolerance threshold is objective evidence that the control is not performing as required, warranting a lower effectiveness rating.
Question 7: In the context of process mapping for operational risk, 'critical path analysis' is MOST valuable for identifying:
- The process steps with the highest staffing costs
- The sequence of steps that determines the minimum time to complete the process and where delays cascade (Correct answer)
- Regulatory reporting deadlines embedded within the workflow
- The automation opportunities that yield the greatest cost savings
Correct answer: The sequence of steps that determines the minimum time to complete the process and where delays cascade
Critical path analysis identifies the irreducible sequence where any delay or failure propagates to the entire process outcome, highlighting the highest-risk dependency chain.
A 'control owner' in operational risk governance is BEST defined as the individual who: