CORES Risk Control Strategies & Mitigation Planning 5 — Questions and Answers
Question 1: A risk manager is evaluating two controls for the same risk: Control A reduces likelihood by 70% at a cost of $50K; Control B reduces impact by 80% at a cost of $200K. Which factor should MOST influence the selection?
- Always choose the control with the highest percentage reduction
- The nature of the risk — whether preventing occurrence or limiting damage is more valuable (Correct answer)
- Regulatory preference for likelihood-based controls
- The number of employees who will interact with each control
Correct answer: The nature of the risk — whether preventing occurrence or limiting damage is more valuable
The appropriate control depends on whether the risk profile benefits more from frequency reduction or severity reduction, which is context-specific.
Question 2: In operational risk, 'inherent risk' differs from 'residual risk' in that:
- Inherent risk accounts for all existing controls; residual risk does not
- Inherent risk is the exposure before controls; residual risk is what remains after controls are applied (Correct answer)
- Residual risk is always higher than inherent risk
- Inherent risk is only relevant for market and credit risk categories
Correct answer: Inherent risk is the exposure before controls; residual risk is what remains after controls are applied
Inherent risk is the raw risk exposure without controls; residual risk is what remains after the organization's controls have been applied.
Question 3: When updating a risk mitigation plan after a significant operational loss event, which step should occur FIRST?
- Purchase additional insurance to cover future losses
- Conduct a root-cause analysis to understand why existing controls failed (Correct answer)
- Replace the risk owner with new personnel
- Immediately report the control failure to all regulators
Correct answer: Conduct a root-cause analysis to understand why existing controls failed
Root-cause analysis is essential first because it identifies the specific control failure or gap, informing targeted remediation rather than generic responses.
Question 4: A 'heat map' in risk management is used to prioritize mitigation efforts by plotting risks according to:
- Cost of mitigation versus regulatory priority
- Likelihood and impact, visually highlighting the highest-priority risks (Correct answer)
- Time to implement controls versus number of risks affected
- Risk owner experience level versus control budget
Correct answer: Likelihood and impact, visually highlighting the highest-priority risks
A risk heat map plots likelihood on one axis and impact on the other, enabling visual prioritization of risks requiring the most urgent mitigation.
Question 5: Which scenario represents a failure of the 'defense-in-depth' principle in operational risk control design?
- Using both preventive and detective controls for the same high-risk process
- Relying solely on a single automated system to manage all fraud risks (Correct answer)
- Layering physical, procedural, and technical controls for a critical process
- Requiring management sign-off in addition to automated approval workflows
Correct answer: Relying solely on a single automated system to manage all fraud risks
Defense-in-depth requires multiple independent control layers; relying on a single control creates a single point of failure that violates this principle.
Question 6: A multinational firm's risk mitigation plan must account for geopolitical risk in an overseas operation. Which control strategy is MOST appropriate for this type of risk?
- Ignore the risk as it is uncontrollable
- Use scenario-based contingency planning and operational flexibility to adapt to political changes (Correct answer)
- Transfer all geopolitical risk to a reinsurance company
- Apply the same domestic controls without modification
Correct answer: Use scenario-based contingency planning and operational flexibility to adapt to political changes
Geopolitical risks are difficult to prevent; contingency planning and operational flexibility allow the firm to adapt rapidly when political conditions change.
Question 7: In the context of CORES exam standards, which statement about risk mitigation plans is MOST accurate?
- A mitigation plan is complete once controls are documented
- Mitigation plans must be living documents with defined review cycles, owners, and success metrics (Correct answer)
- Mitigation plans are only required for risks above the organization's risk tolerance
- Only the chief risk officer is responsible for maintaining mitigation plans
Correct answer: Mitigation plans must be living documents with defined review cycles, owners, and success metrics
Effective mitigation plans are dynamic, requiring ongoing ownership, periodic review, and measurable criteria to confirm they remain adequate and effective.
A risk manager is evaluating two controls for the same risk: Control A reduces likelihood by 70% at a cost of $50K; Control B reduces impact by 80% at a cost of $200K.
Which factor should MOST influence the selection?