Certified Risk Analyst (CRA) — Questions and Answers
Question 1: The Bank Secrecy Act (BSA) requires financial institutions to file a Suspicious Activity Report (SAR) within how many calendar days of detecting a suspicious transaction?
- 30 days (Correct answer)
- 60 days
- 15 days
- 45 days
Correct answer: 30 days
Under BSA regulations, financial institutions must file a SAR within 30 calendar days of the initial detection of the suspicious activity.
Question 2: The Overseas Private Investment Corporation (OPIC), now part of the U.S. International Development Finance Corporation (DFC), primarily helps U.S. businesses manage which type of risk?
- Domestic regulatory compliance risk
- Commodity price risk
- Currency transaction risk in OECD countries
- Political risk in developing markets (Correct answer)
Correct answer: Political risk in developing markets
DFC (formerly OPIC) provides political risk insurance and financing to U.S. businesses investing in developing and emerging markets, covering risks like expropriation, currency inconvertibility, and political violence.
Question 3: What is the primary purpose of a Risk Management Information System (RMIS) in stakeholder communication?
- To aggregate, store, and distribute risk data consistently across the organization for informed decision-making (Correct answer)
- To limit risk data access to senior management only
- To automate the payment of insurance claims
- To replace human judgment in risk decisions
Correct answer: To aggregate, store, and distribute risk data consistently across the organization for informed decision-making
An RMIS centralizes risk data collection, analysis, and reporting, enabling timely and consistent risk information sharing across all organizational levels and stakeholders.
Question 4: Which concept describes the legal principle that holds a parent company liable for the regulatory violations of its subsidiary?
- Successor liability
- Vicarious liability
- Enterprise liability (Correct answer)
- Piercing the corporate veil
Correct answer: Enterprise liability
Enterprise liability theory can hold a parent corporation responsible for a subsidiary's violations when the parent controls or directs the wrongful conduct.
Question 5: In the context of risk culture assessment, which indicator would suggest a weak risk culture?
- High near-miss reporting rates
- Active participation in risk training programs
- Frequent voluntary escalation of limit breaches
- Repeated findings of the same control deficiency across multiple audit cycles (Correct answer)
Correct answer: Repeated findings of the same control deficiency across multiple audit cycles
Recurring audit findings of the same deficiency indicate that risk issues are not being genuinely remediated, reflecting a culture where risk management is treated as a compliance exercise rather than a core value.
Question 6: In Monte Carlo VaR, which distribution assumption is most commonly used to model daily equity returns as a starting point?
- Exponential distribution
- Uniform distribution
- Poisson distribution
- Lognormal distribution (Correct answer)
Correct answer: Lognormal distribution
Equity prices are typically modeled as lognormal, meaning daily log-returns follow a normal distribution, which is the standard starting point in Monte Carlo equity VaR models.
Question 7: The term 'gray rhino' in geopolitical risk analysis refers to:
- A demographic-driven economic slowdown
- An unpredictable black swan event
- A covert state-sponsored cyber attack
- A highly probable but neglected large-scale threat (Correct answer)
Correct answer: A highly probable but neglected large-scale threat
A 'gray rhino' is a high-probability, high-impact threat that is visible and well-known yet tends to be ignored or underestimated until it charges.
Question 8: Which risk identification method involves reviewing historical incidents, near-misses, and audit findings to identify patterns?
- Prospective risk identification
- Horizon scanning
- Delphi elicitation
- Retrospective risk identification (Correct answer)
Correct answer: Retrospective risk identification
Retrospective risk identification mines past incidents, near-misses, and findings to detect patterns and recurring risks that may materialize again.
Question 9: The COSO 2013 Internal Control framework requires that the five components and 17 principles be:
- Assessed only at the entity level, not at the transaction level
- Documented in a single enterprise risk policy
- Applied only to publicly traded companies
- Present and functioning for an effective system of internal control (Correct answer)
Correct answer: Present and functioning for an effective system of internal control
All five components and 17 principles must be present and functioning together for internal control to be deemed effective under COSO 2013.
Question 10: A 'tone at the top' in corporate governance primarily refers to:
- The ethical culture and commitment to compliance demonstrated by senior leadership (Correct answer)
- The volume of compliance policies issued by the legal department
- The severity of penalties for policy violations
- The number of training sessions conducted annually
Correct answer: The ethical culture and commitment to compliance demonstrated by senior leadership
Tone at the top reflects senior leadership's visible commitment to ethical conduct and compliance, which shapes overall organizational culture.
Question 11: Which BCP document serves as the primary reference during an actual disaster, containing step-by-step recovery procedures for operations staff?
- Business continuity policy
- Disaster recovery runbook (Correct answer)
- Crisis management plan
- Business impact analysis report
Correct answer: Disaster recovery runbook
A disaster recovery runbook contains detailed, actionable step-by-step instructions for operations teams to execute during an actual recovery event.
Question 12: Which numerical technique is best suited for pricing path-dependent options (e.g., Asian options) where closed-form solutions do not exist?
- Monte Carlo simulation (Correct answer)
- Black-Scholes closed-form formula
- Delta-normal approximation
- Binomial tree model
Correct answer: Monte Carlo simulation
Monte Carlo simulation generates thousands of asset price paths and averages payoffs, making it ideal for path-dependent products whose payoff depends on the entire price trajectory.
Question 13: Which risk identification source is most useful for identifying emerging risks that haven't yet materialized in historical data?
- Industry benchmarks
- Prior incident logs
- Horizon scanning and environmental monitoring (Correct answer)
- Internal audit reports
Correct answer: Horizon scanning and environmental monitoring
Horizon scanning monitors trends, weak signals, and external environments to detect emerging risks before they appear in historical loss data.
Question 14: A Certified Risk Analyst evaluating emerging market debt should consider 'debt distress' indicators, which include all of the following EXCEPT:
- A country's bond yield spreads widening significantly
- External debt-to-GDP ratio above 60%
- Rising debt service-to-export ratio
- A positive current account surplus with strong reserve coverage (Correct answer)
Correct answer: A positive current account surplus with strong reserve coverage
A positive current account surplus and strong reserve coverage are signs of financial resilience, not distress indicators—the other options are classic warning signs of emerging market debt vulnerability.
Question 15: A risk analyst identifies that a foreign government has a history of renegotiating contracts after elections. This most directly represents:
- Macro-financial risk
- Environmental transition risk
- Corruption and bribery risk
- Political interference and regulatory risk (Correct answer)
Correct answer: Political interference and regulatory risk
Governments unilaterally renegotiating contracts post-election reflects political interference and regulatory risk, where the enforceability of legal agreements depends on political continuity.
Question 16: Which of the following BEST describes the concept of 'risk interdependency' in a portfolio context?
- Each risk is managed independently with separate controls
- Risks in a portfolio always have negative correlation, providing natural hedges
- The occurrence of one risk event may increase the likelihood or severity of other risks (Correct answer)
- Risk mitigation in one area automatically reduces all related risks
Correct answer: The occurrence of one risk event may increase the likelihood or severity of other risks
Risk interdependency (or contagion) means that risks are not independent; a triggering event can cascade and amplify other exposures, requiring portfolio-level thinking.
Question 17: Under the advanced measurement approach (AMA) for operational risk, banks must capture losses at a confidence level of:
- 99% over a one-year horizon
- 95% over a one-year horizon
- 99.9% over a one-year horizon (Correct answer)
- 99.99% over a one-year horizon
Correct answer: 99.9% over a one-year horizon
The AMA requires banks to estimate operational risk capital at a 99.9% confidence level over a one-year holding period.
Question 18: Economic sanctions imposed by a major power can create secondary risk for third-party companies through 'secondary sanctions,' which means:
- Multinational subsidiaries in third countries are exempt from parent-company sanctions
- Non-sanctioning country firms face penalties for doing business with sanctioned entities (Correct answer)
- The sanctioned country retaliates with counter-sanctions on the imposing country
- Sanctions automatically expire after a secondary review period
Correct answer: Non-sanctioning country firms face penalties for doing business with sanctioned entities
Secondary sanctions target companies from non-sanctioning countries that continue to do business with sanctioned entities, effectively coercing third parties to comply with the sanctioning country's policy.
Question 19: A Chief Risk Officer presents a heat map showing 12 risks mapped by likelihood and impact. Which limitation of heat maps should the board be most aware of?
- They are only valid for financial risks
- They may obscure the aggregate correlation between risks (Correct answer)
- They require quantitative probability distributions for every risk
- Heat maps cannot show more than five risks simultaneously
Correct answer: They may obscure the aggregate correlation between risks
Heat maps display individual risks but do not inherently capture how correlated risks can amplify each other when occurring together.
Question 20: A manufacturing firm installs fire sprinklers and trains staff in evacuation procedures. In risk management terminology, sprinklers are BEST classified as a ________ control, while evacuation training is a ________ control.
- Detective; preventive
- Compensating; directive
- Corrective; detective
- Preventive; corrective (Correct answer)
Correct answer: Preventive; corrective
Sprinklers mitigate the impact of a fire once it starts (corrective/mitigating), while evacuation training addresses response after the event—however, standard classification treats sprinklers as preventive (limit spread) and evacuation as corrective response; the best-fit pairing here is preventive for sprinklers and corrective for evacuation.
Question 21: A risk analyst is building a risk appetite framework for a fintech startup. Which element is MOST critical to establish first?
- Quantitative risk limits for each business unit
- Risk reporting templates and dashboards
- Board-approved overarching risk appetite statement (Correct answer)
- Operational risk tolerance thresholds
Correct answer: Board-approved overarching risk appetite statement
The board-approved overarching risk appetite statement provides strategic direction that all subsequent quantitative limits and thresholds must flow from.
Question 22: A financial institution uses stress testing to evaluate portfolio resilience. The MAIN limitation of historical stress scenarios (using past crisis data) is:
- They are too expensive to compute with modern systems
- Regulators prohibit historical data in stress testing
- They may not capture novel risks or combinations of factors not seen in historical data (Correct answer)
- They always overestimate potential losses
Correct answer: They may not capture novel risks or combinations of factors not seen in historical data
Historical stress scenarios are limited by the assumption that future crises will resemble past ones, missing new risk combinations, structural changes, or unprecedented events.
Question 23: What is the purpose of a contingency plan?
- To respond to risk events quickly (Correct answer)
- To increase meetings
- To delay action
- To outsource tasks
Correct answer: To respond to risk events quickly
The primary purpose of a contingency plan is to provide a pre-defined course of action to be followed when a specific risk event occurs. This allows an organization to respond quickly and effectively to unforeseen circumstances or crises. By having a plan in place, potential damage and disruption can be minimized, ensuring business continuity.
Question 24: Risk escalation protocols are designed to ensure that:
- Significant risk events and emerging threats are promptly communicated to appropriate decision-makers (Correct answer)
- Risk responsibilities are transferred to external consultants
- All risk data is consolidated into a single annual report
- Only the CEO makes final risk decisions
Correct answer: Significant risk events and emerging threats are promptly communicated to appropriate decision-makers
Escalation protocols define clear pathways for reporting material risks upward through the organization so that timely, informed decisions can be made.
Question 25: Which of the following best describes 'regulatory capital' as it applies to banks under Basel III?
- The total assets on a bank's balance sheet
- Cash held in vault to meet daily withdrawal demands
- Minimum equity and other qualifying capital that banks must hold relative to risk-weighted assets (Correct answer)
- Risk-weighted assets calculated for stress testing purposes
Correct answer: Minimum equity and other qualifying capital that banks must hold relative to risk-weighted assets
Under Basel III, regulatory capital is the minimum level of loss-absorbing capital (primarily common equity) banks must maintain relative to their risk-weighted assets.
Question 26: A company's risk committee reviews a project with a positive NPV but a tail risk scenario that could cause insolvency. The committee rejects the project. This decision BEST reflects:
- Ignoring shareholder return requirements
- Applying a risk constraint that protects organizational survival over pure expected-value optimization (Correct answer)
- Over-application of the precautionary principle in a low-stakes context
- Maximizing expected monetary value
Correct answer: Applying a risk constraint that protects organizational survival over pure expected-value optimization
Protecting the firm from ruin risk means accepting a lower expected return to avoid scenarios that threaten solvency, a principle central to enterprise risk management.
Question 27: A manufacturing company's ERM team identifies that a key supplier has a single point of failure. This is an example of which risk category?
- Market risk
- Operational/supply chain risk (Correct answer)
- Liquidity risk
- Reputational risk
Correct answer: Operational/supply chain risk
Single-supplier dependence is a concentration within supply chain operations, which falls under operational risk.
Question 28: An insurance company's risk appetite framework sets a maximum probability of ruin of 0.5% over a one-year horizon. This is an example of which type of risk appetite expression?
- Value-at-risk floor
- Probabilistic risk tolerance threshold (Correct answer)
- Economic capital constraint
- Earnings-at-risk limit
Correct answer: Probabilistic risk tolerance threshold
Expressing risk appetite as a maximum acceptable probability of ruin is a probabilistic threshold approach, defining how likely the organization can tolerate catastrophic loss.
Question 29: Which practice helps embed risk awareness into day-to-day decision making at the frontline employee level?
- Restricting risk training to the risk management department only
- Integrating risk considerations into performance reviews, onboarding, and operational processes (Correct answer)
- Issuing risk policies only in dense technical language
- Delegating all risk decisions to senior management
Correct answer: Integrating risk considerations into performance reviews, onboarding, and operational processes
Embedding risk awareness into everyday processes — such as performance incentives, onboarding training, and operational checklists — ensures that frontline employees consider risk in routine decisions.
Question 30: A risk analyst presenting findings to regulators should prioritize which communication approach?
- Withholding model assumptions to protect proprietary methodologies
- Providing transparent, accurate, and complete risk disclosures including limitations and uncertainties (Correct answer)
- Emphasizing only positive risk outcomes to maintain confidence
- Presenting only data that supports the desired regulatory outcome
Correct answer: Providing transparent, accurate, and complete risk disclosures including limitations and uncertainties
Regulatory communications require full transparency, including disclosure of model limitations, data gaps, and uncertainties, to maintain regulatory trust and compliance.
Certified Risk Analyst (CRA)
The AIBM Certified Risk Analyst (CRA) credential validates expertise in risk analysis principles, assessment methodologies, and mitigation strategies. It covers regulatory compliance, decision support, and emerging trends across enterprise risk management frameworks.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds