← All CRA Flashcard Decks

Safety Protocols & Risk Management Flashcards

7 cards from real CRA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Safety Protocols & Risk Management flashcards as text
  1. A retailer operating in multiple states must comply with varying state-level break and rest period laws. From a risk management perspective, the BEST approach is to:

    Answer: Apply the most restrictive state's standards chain-wide to ensure universal compliance

    Applying the most restrictive standard universally eliminates compliance gaps across all jurisdictions and simplifies policy administration.

  2. A retail analyst reviewing incident logs notices a spike in 'near-miss' reports following a new store layout implementation. What does this pattern most likely indicate?

    Answer: The new layout introduced unidentified hazards that need immediate assessment

    A spike in near-misses following a physical change is a leading indicator that the new layout created new hazards requiring safety reassessment.

  3. Which retail-specific regulation requires that stores selling firearms maintain detailed acquisition and disposition records (A&D logs)?

    Answer: Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) regulations under the Gun Control Act

    ATF regulations under the Gun Control Act mandate that Federal Firearms Licensees maintain detailed A&D records for every firearm transaction.

  4. A retail loss prevention team is implementing 'exception-based reporting' (EBR). Which operational risk does this technology PRIMARILY address?

    Answer: Point-of-sale fraud and manipulation by employees or cashiers

    EBR analyzes POS transaction data for anomalies — such as excessive voids, refunds, or sweethearting — to detect employee fraud at checkout.

  5. Under the Payment Card Industry Data Security Standard (PCI DSS), a retail store that experiences a data breach must notify acquiring banks within what maximum timeframe?

    Answer: Immediately upon discovering the breach (as soon as possible)

    PCI DSS requires immediate notification to acquiring banks and card brands upon discovery of a suspected breach, with no specific grace period permitted.

  6. Which concept describes the systematic process of identifying which retail business functions must be restored first following a disruptive event?

    Answer: Business Impact Analysis (BIA)

    A Business Impact Analysis identifies critical functions, their recovery time objectives, and interdependencies to prioritize restoration efforts after a disruption.

  7. A retail chain's supply chain risk assessment reveals single-source dependency for a key private-label product manufactured overseas. The recommended risk mitigation strategy is to:

    Answer: Qualify and onboard at least one alternative supplier to reduce concentration risk

    Qualifying an alternative supplier directly addresses single-source concentration risk by creating redundancy without eliminating the product or dramatically inflating inventory costs.