CORES Risk Control Strategies & Mitigation Planning 2 — Questions and Answers
Question 1: A bank discovers that a critical vendor handles 60% of its payment processing. Which risk control strategy best addresses this concentration risk?
- Accept the risk and document it in the risk register
- Diversify across multiple vendors to reduce single-point dependency (Correct answer)
- Transfer the risk entirely through an indemnification clause
- Avoid the risk by terminating all vendor relationships
Correct answer: Diversify across multiple vendors to reduce single-point dependency
Diversification reduces concentration risk by distributing dependency across multiple vendors, limiting exposure if one vendor fails.
Question 2: Which element is MOST critical when designing a risk mitigation control to ensure it remains effective over time?
- One-time implementation cost
- Built-in monitoring and periodic review mechanisms (Correct answer)
- Number of employees who approve the control
- Alignment with competitor practices
Correct answer: Built-in monitoring and periodic review mechanisms
Controls must include monitoring and review mechanisms because risk environments evolve, and a static control can become ineffective.
Question 3: An operational risk manager recommends purchasing cyber insurance for a data breach scenario. This is an example of which risk strategy?
- Risk avoidance
- Risk reduction
- Risk transfer (Correct answer)
- Risk acceptance
Correct answer: Risk transfer
Cyber insurance transfers the financial consequences of a data breach to a third-party insurer, exemplifying risk transfer.
Question 4: Under the Basel operational risk framework, the 'four-eyes principle' is a control primarily designed to mitigate which risk type?
- External fraud
- Internal fraud and processing errors (Correct answer)
- Natural disaster exposure
- Market volatility
Correct answer: Internal fraud and processing errors
The four-eyes principle requires dual approval, directly reducing internal fraud and inadvertent processing errors through segregation of duties.
Question 5: A firm identifies a residual risk that remains after all feasible controls are applied. What is the MOST appropriate next step?
- Implement additional controls regardless of cost
- Document the residual risk and obtain formal management acceptance (Correct answer)
- Escalate immediately to regulators
- Eliminate the business activity generating the risk
Correct answer: Document the residual risk and obtain formal management acceptance
Residual risk that cannot be economically reduced further must be formally accepted by management and documented in the risk framework.
Question 6: Which scenario BEST illustrates a 'detective' control in operational risk management?
- Requiring dual authorization before a wire transfer is initiated
- Conducting daily reconciliation to identify discrepancies after processing (Correct answer)
- Training employees on fraud prevention before they start work
- Encrypting data to prevent unauthorized access
Correct answer: Conducting daily reconciliation to identify discrepancies after processing
Reconciliation identifies errors or fraud after they have occurred, making it a detective control rather than a preventive one.
Question 7: When a financial institution decides to exit a high-risk product line entirely to eliminate associated operational risks, this strategy is known as:
- Risk mitigation
- Risk transfer
- Risk avoidance (Correct answer)
- Risk acceptance
Correct answer: Risk avoidance
Exiting a business activity to eliminate the associated risk is risk avoidance — the firm removes itself from the risk-generating situation.
A bank discovers that a critical vendor handles 60% of its payment processing.
Which risk control strategy best addresses this concentration risk?