CORES Study Guide 2026

Everything you need to pass the CORES exam in one place: the exam format, every topic to study, real practice questions with explanations, flashcards, and full-length practice tests. Free, no sign-up needed.

📋 CORES Exam Format at a Glance

100
Questions
90 min
Time Limit
70.00%
Passing Score

📚 CORES Topics to Study (75)

Incident Management & Business Continuity Planning · 9 cardsOperational Risk Identification & Assessment · 9 cardsRegulatory Compliance & Industry Standards · 9 cardsRisk Control Strategies & Mitigation Planning · 9 cardsBasel Framework & Capital Requirements · 7 cardsBasel Framework & Capital Requirements · 7 cardsBasel Framework & Capital Requirements · 7 cardsBasel Framework & Capital Requirements · 7 cardsIncident Management & Business Continuity Planning · 7 cardsIncident Management & Business Continuity Planning · 7 cardsIncident Management & Business Continuity Planning · 7 cardsIncident Management & Business Continuity Planning · 7 cardsInternal Audit & Three Lines of Defense · 7 cardsInternal Audit & Three Lines of Defense · 7 cardsInternal Audit & Three Lines of Defense · 7 cardsKey Risk Indicator Development · 7 cardsKey Risk Indicator Development · 7 cardsKey Risk Indicator Development · 7 cardsKey Risk Indicator Development · 7 cardsLoss Data Collection & Analysis · 7 cardsLoss Data Collection & Analysis · 7 cardsLoss Data Collection & Analysis · 7 cardsLoss Data Collection & Analysis · 7 cardsOperational Risk Identification & Assessment · 7 cardsOperational Risk Identification & Assessment · 7 cardsOperational Risk Identification & Assessment · 7 cardsOperational Risk Identification & Assessment · 7 cardsProcess Mapping & Control Assessment · 7 cardsProcess Mapping & Control Assessment · 7 cardsProcess Mapping & Control Assessment · 7 cards

✍️ Sample CORES Questions & Answers

1. The primary purpose of maintaining a detailed incident log throughout an event is to:
Provide a chronological record that supports decision-making, lessons learned, and potential legal proceedings

A contemporaneous incident log captures the timeline, decisions, and actions in real time, supporting both immediate situational awareness and subsequent review, legal, and regulatory purposes.

2. An organization's vendor risk committee is reviewing a high-risk vendor that has consistently failed to remediate identified control gaps. What is the MOST appropriate escalation action?
Escalate to senior leadership and consider compensating controls, enhanced monitoring, or contract termination

Persistent control failures by a high-risk vendor require escalation to leadership and consideration of corrective actions up to and including termination.

3. Which approach is used when a risk cannot be eliminated?
Risk transfer

When a risk cannot be eliminated or sufficiently reduced through other controls, risk transfer is an approach used to shift the financial consequences of the risk to another party. This is typically achieved through mechanisms like insurance, outsourcing, or contractual agreements. While the risk itself may still exist, the financial burden is transferred.

4. When scaling external loss data to fit an institution's risk profile, which size proxy is most commonly used?
Gross income

Gross income is the standard scaling factor for adjusting external loss data, aligning with the Basel Standardized Approach's use of gross income as a risk proxy.

5. A risk manager notices that a KRI for transaction error rate has been in the green zone for 12 consecutive months without any threshold changes. What action is MOST appropriate?
Review whether the threshold is set too loosely and lacks discriminating power

A KRI that never leaves the green zone may have a threshold that is too generous to detect meaningful risk changes, requiring recalibration to remain useful.

6. A vendor serving a community bank is acquired by a foreign company in a country with weak data privacy laws. What is the MOST significant risk this creates?
Data sovereignty and regulatory compliance risk due to potential foreign government access to customer data

Foreign acquisitions can expose customer data to the jurisdiction of countries with weaker privacy protections or government surveillance powers, creating regulatory and reputational risk.

🎯 Free CORES Practice Tests

📖 CORES Guides & Articles

Your CORES Study Path
1. Learn with Flashcards → 2. Drill Practice Tests → 3. Take the Full Exam Simulation
Was this helpful?