CORES Risk Control Strategies & Mitigation Planning 3 — Questions and Answers
Question 1: A risk mitigation plan should include a 'risk owner.' What is the PRIMARY responsibility of a risk owner?
- Approving the annual risk budget
- Accountable for implementing and monitoring controls for an assigned risk (Correct answer)
- Auditing all controls across the organization
- Reporting risks directly to external regulators
Correct answer: Accountable for implementing and monitoring controls for an assigned risk
The risk owner is accountable for ensuring that specific risks are properly controlled and that mitigation actions are executed and tracked.
Question 2: In the CORES framework, a Key Risk Indicator (KRI) threshold breach should trigger which immediate action?
- Automatic suspension of all related business operations
- Escalation to the designated risk owner and review of the mitigation plan (Correct answer)
- Filing a regulatory report within 24 hours
- Replacing the control with a new strategy immediately
Correct answer: Escalation to the designated risk owner and review of the mitigation plan
A KRI breach signals that risk levels are approaching unacceptable limits, requiring prompt escalation and mitigation plan review.
Question 3: Which type of control is MOST effective at preventing data entry errors in a high-volume transaction environment?
- Post-processing audit trails
- Automated input validation and field constraints (Correct answer)
- Monthly supervisory review of transaction reports
- Annual staff training on data accuracy
Correct answer: Automated input validation and field constraints
Automated input validation prevents errors at the point of entry, making it a highly effective preventive control for high-volume environments.
Question 4: A cost-benefit analysis for a proposed control shows implementation costs exceed expected loss reduction by 3x. What should the risk manager recommend?
- Implement the control because safety always comes first
- Consider alternative, less costly controls or formally accept the risk (Correct answer)
- Transfer the risk through insurance regardless of cost
- Escalate to the board for mandatory implementation
Correct answer: Consider alternative, less costly controls or formally accept the risk
When control costs significantly exceed expected benefits, risk managers should seek cost-effective alternatives or document formal risk acceptance.
Question 5: Scenario planning in risk mitigation is MOST useful for addressing which category of operational risk?
- High-frequency, low-severity events with ample historical data
- Low-frequency, high-severity tail risks with limited historical data (Correct answer)
- Risks already covered by existing insurance policies
- Risks that have been fully transferred to third parties
Correct answer: Low-frequency, high-severity tail risks with limited historical data
Scenario planning helps organizations prepare for rare but catastrophic events where statistical modeling alone is insufficient due to limited data.
Question 6: Which statement BEST describes the relationship between risk appetite and risk mitigation planning?
- Risk appetite is set after mitigation plans are completed
- Mitigation plans are designed to bring residual risk within the board-approved risk appetite (Correct answer)
- Risk appetite determines the number of controls required regardless of risk severity
- Mitigation plans eliminate the need to define risk appetite
Correct answer: Mitigation plans are designed to bring residual risk within the board-approved risk appetite
The goal of mitigation planning is to reduce risk to a level that falls within the organization's board-approved risk appetite statement.
Question 7: A financial firm implements a Business Continuity Plan (BCP) to ensure operations can resume after a system outage. This control is best classified as:
- Preventive
- Corrective (Correct answer)
- Directive
- Detective
Correct answer: Corrective
A BCP is a corrective control because it facilitates recovery and restoration of operations after a disruptive event has already occurred.
A risk mitigation plan should include a 'risk owner.' What is the PRIMARY responsibility of a risk owner?