Risk Identification & Assessment Techniques Flashcards
7 cards from real CRA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Identification & Assessment Techniques flashcards as text
In quantitative risk assessment, Value at Risk (VaR) at the 95% confidence level means:
Answer: There is a 5% chance losses will exceed the VaR amount
VaR at 95% confidence means there is a 5% probability that losses will exceed the stated VaR figure over the specified time horizon.
Which approach to risk identification works backward from a potential undesired outcome to identify all contributing causes?
Answer: Fault Tree Analysis (FTA)
Fault Tree Analysis starts with a top-level undesired event and uses Boolean logic to trace all possible contributing fault combinations backward to root causes.
A technology firm identifies that rapid AI regulatory changes could affect product compliance within 18 months. How should this risk primarily be classified?
Answer: Strategic risk
Regulatory changes affecting long-term product strategy and market positioning are classified as strategic risks because they threaten the organization's strategic objectives.
During risk assessment, 'risk aggregation' involves:
Answer: Combining individual risk exposures to understand total portfolio-level risk
Risk aggregation combines individual risk exposures across the portfolio to assess cumulative and correlated risk, which may differ significantly from the sum of individual risks.
Which risk identification method involves reviewing historical incidents, near-misses, and audit findings to identify patterns?
Answer: Retrospective risk identification
Retrospective risk identification mines past incidents, near-misses, and findings to detect patterns and recurring risks that may materialize again.
A Key Risk Indicator (KRI) differs from a Key Performance Indicator (KPI) in that a KRI:
Answer: Provides early warning signals of increasing risk exposure
KRIs serve as leading indicators that signal rising risk levels before a risk event occurs, unlike KPIs which typically measure historical performance outcomes.
In the context of risk assessment, 'risk appetite' is best defined as:
Answer: The amount and type of risk an organization is willing to accept in pursuit of its objectives
Risk appetite is the board-level declaration of how much and what kinds of risk the organization is willing to take in order to achieve its strategic goals.