Certified Risk Architect (CRA) — Questions and Answers
Question 1: When combining frequency and severity distributions in a loss aggregation model, which mathematical operation is typically used?
- Matrix multiplication of the two distributions
- Division of expected frequency by expected severity
- Convolution of the frequency and severity distributions (Correct answer)
- Subtraction of the severity from the frequency CDF
Correct answer: Convolution of the frequency and severity distributions
Convolution combines the frequency and severity distributions to derive the aggregate loss distribution.
Question 2: Which of the following represents a key weakness in relying solely on insurance as a risk mitigation strategy?
- Insurance is only available for financial institutions
- Insurance does not cover all types of losses and may not compensate for reputational damage (Correct answer)
- Insurance eliminates both financial and reputational consequences of risk events
- Insurance eliminates the need for preventive controls
Correct answer: Insurance does not cover all types of losses and may not compensate for reputational damage
Insurance can offset direct financial losses but cannot fully compensate for reputational harm, regulatory penalties, or operational disruptions from risk events.
Question 3: A construction firm is building in a region known for seismic activity. The firm decides to purchase a comprehensive earthquake insurance policy to cover potential damages to the structure and equipment. This action is an example of:
- Risk Reduction
- Risk Transference (Correct answer)
- Risk Avoidance
- Risk Acceptance
Correct answer: Risk Transference
Risk Transference is a strategy that involves shifting the financial consequences of a particular risk to a third party. By purchasing an insurance policy, the construction firm is transferring the potential financial loss from an earthquake to the insurance company.
Question 4: What is the primary objective of operational risk 'heat mapping'?
- To track IT infrastructure temperature thresholds
- To show geographic distribution of branch offices
- To map regulatory requirements across jurisdictions
- To visually prioritize risks by plotting likelihood against impact severity (Correct answer)
Correct answer: To visually prioritize risks by plotting likelihood against impact severity
A risk heat map plots operational risks on a likelihood-versus-impact matrix to help management visually prioritize which risks require immediate attention.
Question 5: A CRA candidate is evaluating whether to recommend a $2M control implementation to mitigate a risk with an annualized loss expectancy of $500K. What is the most appropriate recommendation?
- Transfer the risk to reduce annual cost
- Accept the risk because control cost exceeds expected loss (Correct answer)
- Implement the control because it eliminates the risk
- Reduce control scope to lower implementation cost
Correct answer: Accept the risk because control cost exceeds expected loss
When control cost ($2M) significantly exceeds annualized loss expectancy ($500K), risk acceptance is the economically rational choice.
Question 6: The 'butterfly effect' concept is most relevant to which quantitative risk challenge?
- Calculating diversification benefits in large portfolios
- Applying regulatory capital multipliers to market risk models
- Non-linear systems where small input changes produce disproportionately large outcomes (Correct answer)
- Estimating normal frequency distributions for routine losses
Correct answer: Non-linear systems where small input changes produce disproportionately large outcomes
The butterfly effect describes sensitive dependence on initial conditions in non-linear systems, which makes long-run quantitative prediction extremely difficult.
Question 7: A risk manager wants to estimate the 99.9% VaR for a portfolio but has only 500 data points. The most appropriate approach is to:
- Report that estimation is impossible with fewer than 10,000 data points
- Fit a parametric extreme value distribution to augment the tail estimate (Correct answer)
- Use the sample mean as the VaR estimate
- Use only the 0.1% worst observation from the data
Correct answer: Fit a parametric extreme value distribution to augment the tail estimate
With limited data, parametric methods like EVT provide more reliable tail estimates than relying on sparse empirical observations at extreme quantiles.
Question 8: Which cognitive bias causes risk identification teams to focus disproportionately on risks that are easily recalled from recent or dramatic events?
- Availability heuristic (Correct answer)
- Confirmation bias
- Optimism bias
- Anchoring bias
Correct answer: Availability heuristic
The availability heuristic leads people to overweight risks that come easily to mind due to recent exposure or emotional salience, distorting comprehensive identification.
Question 9: Which Basel III capital buffer is specifically designed to be built up during periods of excessive credit growth and released during downturns?
- Global Systemically Important Bank Surcharge
- Capital Conservation Buffer
- Leverage Ratio Buffer
- Countercyclical Capital Buffer (Correct answer)
Correct answer: Countercyclical Capital Buffer
The Countercyclical Capital Buffer (CCyB) is activated by national authorities during periods of excessive credit growth to build resilience.
Question 10: What does Recovery Time Objective (RTO) define in business continuity planning?
- The total budget allocated for recovery operations
- The maximum acceptable time to restore a business function after a disruption (Correct answer)
- The minimum number of staff required for recovery operations
- The maximum allowable distance to a backup facility
Correct answer: The maximum acceptable time to restore a business function after a disruption
RTO is the maximum tolerable downtime for a critical business function, defining how quickly it must be restored to avoid unacceptable consequences.
Question 11: In operational risk management, what is the difference between inherent risk and residual risk?
- Inherent risk is financial loss only; residual risk includes reputational loss
- Inherent risk applies to market risk; residual risk applies to credit risk
- Inherent risk is quantified; residual risk is qualitative
- Inherent risk exists before controls; residual risk remains after controls are applied (Correct answer)
Correct answer: Inherent risk exists before controls; residual risk remains after controls are applied
Inherent risk is the gross risk level before any mitigating controls are considered; residual risk is what remains after the effectiveness of controls is accounted for.
Question 12: What is the purpose of a communication call tree in emergency management?
- To maintain a directory of marketing contact information
- To route and manage IT help desk support requests
- To ensure rapid, structured notification of key personnel during a crisis (Correct answer)
- To redirect incoming customer service calls during disruptions
Correct answer: To ensure rapid, structured notification of key personnel during a crisis
A call tree provides a hierarchical, structured method for rapidly notifying and mobilizing the right people during an emergency or business disruption.
Question 13: In assessing the financial stability of its loan portfolio, a commercial bank is primarily concerned with the potential for loss resulting from a borrower's inability to repay their debt obligations. This specific type of financial risk is best defined as:
- Market Risk
- Credit Risk (Correct answer)
- Liquidity Risk
- Operational Risk
Correct answer: Credit Risk
Credit risk is specifically defined as the risk of financial loss arising from a borrower or counterparty failing to meet their contractual obligations to repay a debt. Market risk relates to losses from market price movements, liquidity risk to the inability to meet short-term cash obligations, and operational risk to failures in internal processes, people, and systems.
Question 14: What is ISO 22301 the international standard for?
- Information security management systems
- Business continuity management systems (Correct answer)
- Environmental and sustainability management
- Product and service quality management systems
Correct answer: Business continuity management systems
ISO 22301 is the international standard specifying requirements for a Business Continuity Management System (BCMS) to protect against and recover from disruptions.
Question 15: What is the primary limitation of using ONLY historical loss data for risk identification?
- Loss data analysis requires advanced quantitative expertise unavailable in most organizations
- It cannot identify risks that have not yet manifested in losses, including novel and emerging risks (Correct answer)
- Historical data is too expensive to collect and maintain
- Historical data overestimates the frequency of low-probability events
Correct answer: It cannot identify risks that have not yet manifested in losses, including novel and emerging risks
Historical loss data is inherently backward-looking and cannot surface risks with no prior loss history, such as emerging threats or unprecedented scenarios.
Question 16: What is the primary goal of a pandemic plan within a business continuity framework?
- To ensure business operations can continue when a large portion of the workforce is unavailable (Correct answer)
- To reduce overall organizational healthcare expenses
- To create procedures for permanent office closures
- To establish organizational stockpiles of medical supplies
Correct answer: To ensure business operations can continue when a large portion of the workforce is unavailable
A pandemic plan addresses how the organization maintains critical operations when large numbers of employees are unable to work due to widespread illness.
Question 17: The concept of 'regulatory capital arbitrage' refers to:
- Investing excess regulatory capital in arbitrage strategies
- Allocating economic capital across business lines
- Using regulatory differences across jurisdictions to reduce required capital below the spirit of the rules (Correct answer)
- Issuing capital instruments in foreign markets to lower costs
Correct answer: Using regulatory differences across jurisdictions to reduce required capital below the spirit of the rules
Regulatory capital arbitrage involves structuring transactions or operations to minimize required capital while circumventing the intent of capital adequacy regulations.
Question 18: What is the importance of ensuring compliance with regulatory bodies?
- To enhance financial stability.
- To promote internal policies over laws.
- To delay business decisions.
- To avoid fines and legal penalties (Correct answer)
Correct answer: To avoid fines and legal penalties
Ensuring compliance with regulatory bodies is paramount for organizations to avoid severe financial fines, legal penalties, and potential operational restrictions. Non-compliance can lead to significant reputational damage and loss of public trust, impacting the organization's long-term viability. Therefore, adherence to regulations is a critical risk mitigation strategy to protect the organization's stability and future.
Question 19: Which of the following is a key limitation of using historical data alone for quantitative operational risk modeling?
- Historical data is always too large to process statistically
- Rare tail events may not be represented in the historical record (Correct answer)
- Regulatory frameworks prohibit using historical data for capital models
- Historical data cannot be used to calculate frequency distributions
Correct answer: Rare tail events may not be represented in the historical record
Black swan or low-frequency, high-severity events may simply not appear in historical datasets, causing models to underestimate tail risk.
Question 20: What is the primary purpose of a tabletop exercise in business continuity testing?
- To onboard new employees to standard operating procedures
- To discuss and walk through responses to hypothetical scenarios in a low-stress environment (Correct answer)
- To physically test evacuation and emergency egress procedures
- To audit financial records and controls for accuracy
Correct answer: To discuss and walk through responses to hypothetical scenarios in a low-stress environment
Tabletop exercises allow teams to verbally walk through their response to simulated crisis scenarios, identifying plan gaps without operational disruption.
Question 21: What does supply chain resilience mean in an enterprise risk context?
- The complete elimination of all single-source supplier dependencies
- The capacity to maintain operations when key supply chain disruptions occur (Correct answer)
- The ability to continuously source lower-cost supplier alternatives
- The monitoring of supplier financial statements for solvency risk only
Correct answer: The capacity to maintain operations when key supply chain disruptions occur
Supply chain resilience involves identifying vulnerabilities and implementing strategies to maintain operations when key suppliers, logistics, or inputs are disrupted.
Question 22: Which statistical test is commonly used to assess whether observed loss data fits a hypothesized parametric distribution?
- Mann-Whitney U test
- Kolmogorov-Smirnov (K-S) test (Correct answer)
- F-test for variance equality
- Student's t-test
Correct answer: Kolmogorov-Smirnov (K-S) test
The K-S test compares the empirical cumulative distribution function of the data to the theoretical CDF of the hypothesized distribution.
Question 23: A Certified Risk Architect who discovers a material misstatement in a risk report they previously certified has an ethical obligation to:
- Promptly notify appropriate parties and issue a corrected report (Correct answer)
- Wait until the next reporting cycle to correct it
- Only correct it if a regulator specifically requests a revision
- Treat the matter as confidential to protect the organization
Correct answer: Promptly notify appropriate parties and issue a corrected report
Professional ethics require prompt notification and correction of material misstatements in certified reports, regardless of reputational inconvenience.
Question 24: Which framework specifically provides guidance on designing and evaluating internal controls over financial reporting?
- COBIT 2019
- COSO Internal Control — Integrated Framework (Correct answer)
- ISO 31000
- NIST SP 800-53
Correct answer: COSO Internal Control — Integrated Framework
The COSO Internal Control — Integrated Framework is the globally recognized standard for designing and evaluating internal controls, especially over financial reporting.
Question 25: What does a risk matrix help with?
- Measuring financial losses only.
- Only assessing external risks.
- Setting project timelines.
- Prioritizing risks based on their likelihood and impact (Correct answer)
Correct answer: Prioritizing risks based on their likelihood and impact
A risk matrix is a visual tool used to assess and prioritize risks by plotting their likelihood (probability) against their potential impact (severity). This allows organizations to quickly identify and categorize the most critical risks, enabling them to allocate resources effectively. It provides a clear framework for understanding the relative importance of various risks and guiding mitigation efforts.
Question 26: A risk architect reviewing a third-party vendor agreement notices it lacks a right-to-audit clause. This is MOST concerning because:
- The contract cannot be terminated for convenience
- The vendor may increase fees without notice
- It violates IRS reporting requirements
- The institution cannot independently verify the vendor's compliance and controls (Correct answer)
Correct answer: The institution cannot independently verify the vendor's compliance and controls
A right-to-audit clause is essential for verifying third-party controls; without it, the institution has no independent means to validate vendor compliance.
Question 27: Which of the following items is typically included in a vendor due diligence questionnaire (DDQ)?
- Information on security controls, financial stability, and regulatory compliance posture (Correct answer)
- Vendor's marketing strategy and customer acquisition costs
- The vendor's historical stock price and analyst ratings
- Details about the vendor's executive compensation and bonus structure
Correct answer: Information on security controls, financial stability, and regulatory compliance posture
DDQs gather information on security practices, financial health, and compliance posture to comprehensively assess the risks a vendor introduces.
Question 28: A risk architect reviewing a bank's capital adequacy under Basel III would use the Capital Conservation Buffer (CCB) as an add-on above the minimum CET1 ratio. What is the size of the CCB?
- 1.5%
- 2.5% (Correct answer)
- 3.5%
- 2.0%
Correct answer: 2.5%
Basel III requires a Capital Conservation Buffer of 2.5% of risk-weighted assets above the 4.5% CET1 minimum, bringing the effective minimum to 7%.
Question 29: Which simulation technique reduces variance in Monte Carlo output by ensuring samples are more evenly distributed across the input probability space?
- Markov Chain Monte Carlo
- Latin Hypercube Sampling (LHS) (Correct answer)
- Bootstrap resampling
- Importance sampling
Correct answer: Latin Hypercube Sampling (LHS)
LHS stratifies the input distribution into equal-probability intervals, ensuring better coverage and reducing output variance with fewer iterations.
Question 30: What is a 'warm site' in disaster recovery planning?
- A facility with specialized environmental temperature controls only
- A fully operational backup facility equivalent to the primary site
- A backup facility partially equipped that requires some additional setup before becoming fully operational (Correct answer)
- A remote data center building with no installed equipment
Correct answer: A backup facility partially equipped that requires some additional setup before becoming fully operational
A warm site is partially configured with hardware and connectivity but requires additional setup, offering a middle ground between costly hot sites and slow cold sites.
Question 31: Which strategy best mitigates the risk of vendor lock-in for a critical service?
- Signing longer-term contracts to secure favorable pricing arrangements
- Avoiding customization of vendor products to maintain standardized interfaces
- Designating a single preferred vendor per service category to streamline management
- Diversifying the vendor portfolio and ensuring data portability and interoperability (Correct answer)
Correct answer: Diversifying the vendor portfolio and ensuring data portability and interoperability
Vendor lock-in risk is best mitigated through portfolio diversification, maintaining data portability, and ensuring interoperability with alternative providers.
Question 32: A bank's compliance officer discovers that a third-party vendor processing customer data has experienced a breach. Under GLBA notification requirements, which party must notify affected customers?
- The third-party vendor directly notifies affected customers
- OFAC handles all breach notifications for financial institutions
- The bank notifies affected customers, not the vendor (Correct answer)
- Both the bank and vendor must independently notify each customer
Correct answer: The bank notifies affected customers, not the vendor
GLBA holds the financial institution responsible for safeguarding customer information, so the bank—not its vendor—must notify affected customers of a breach.
Question 33: Which type of risk assessment approach assigns numerical probabilities and monetary values to risk outcomes?
- Inherent risk assessment
- Qualitative risk assessment
- Semi-quantitative risk assessment
- Quantitative risk assessment (Correct answer)
Correct answer: Quantitative risk assessment
Quantitative risk assessment uses numerical probabilities and financial values to produce objective, measurable risk metrics.
Question 34: When a quantitative risk model consistently underestimates losses during back-testing, the most likely cause is:
- The historical data used was too long a time horizon
- The model's probability confidence level is set too high
- The model is using too many simulations
- The model's assumptions do not capture tail risk or regime changes adequately (Correct answer)
Correct answer: The model's assumptions do not capture tail risk or regime changes adequately
Systematic underestimation during back-testing usually indicates the model fails to capture fat-tailed distributions or shifts in risk regime.
Question 35: A firm subject to the EU's Markets in Financial Instruments Directive II (MiFID II) must record and retain telephone conversations and electronic communications related to client orders for how long?
- 3 years
- 1 year
- 7 years
- 5 years (Correct answer)
Correct answer: 5 years
MiFID II requires investment firms to retain recordings of client-order communications for a minimum of 5 years (up to 7 years if requested by a competent authority).
Question 36: In a Bayesian network used for risk analysis, what do the conditional probability tables (CPTs) represent?
- The marginal distribution of each node independently
- The probability of a node's state given the states of its parent nodes (Correct answer)
- The correlation coefficients between all risk variables
- The posterior distribution after data is observed
Correct answer: The probability of a node's state given the states of its parent nodes
CPTs define the conditional probability of each node given every combination of its parent nodes' states in the Bayesian network.
Question 37: Which of the following best describes 'epistemic uncertainty' in quantitative risk analysis?
- Uncertainty caused by model parameter rounding
- Uncertainty arising from lack of knowledge or data (Correct answer)
- Uncertainty from inherent randomness in a process
- Uncertainty from correlated risk events occurring simultaneously
Correct answer: Uncertainty arising from lack of knowledge or data
Epistemic uncertainty stems from incomplete knowledge and can theoretically be reduced by gathering more information.
Question 38: Enterprise Risk Management (ERM) frameworks like COSO ERM 2017 emphasize integrating risk management with:
- Strategy setting and performance management (Correct answer)
- Regulatory compliance programs as the primary driver
- IT governance frameworks only
- Financial reporting controls exclusively
Correct answer: Strategy setting and performance management
COSO ERM 2017 explicitly links risk management to strategy setting and performance to enhance value creation and preservation.
Question 39: Under the Sarbanes-Oxley Act Section 302, which executive is primarily responsible for certifying the accuracy of financial reports?
- Chief Risk Officer
- CEO and CFO jointly (Correct answer)
- Chief Compliance Officer
- External Auditor
Correct answer: CEO and CFO jointly
SOX Section 302 requires the CEO and CFO to personally certify the accuracy and completeness of financial reports filed with the SEC.
Question 40: What is the recommended review frequency for high-risk vendor relationships according to leading TPRM practices?
- At least annually, with more frequent reviews based on elevated risk or material changes (Correct answer)
- Every five years aligned with standard contract renewal cycles
- Once at contract inception and never again unless problems arise
- Only when a regulatory examination or security incident occurs
Correct answer: At least annually, with more frequent reviews based on elevated risk or material changes
High-risk vendor relationships require at least annual reviews, with increased frequency triggered by changes in the vendor's risk profile, ownership, or operational circumstances.
Question 41: What is cyber resilience in the context of business continuity management?
- The ability to continuously deliver intended outcomes despite cyber attacks or incidents (Correct answer)
- The practice of installing stronger network firewalls and perimeter defenses
- The policy of hiring additional cybersecurity personnel
- The strategy of eliminating all external internet connectivity
Correct answer: The ability to continuously deliver intended outcomes despite cyber attacks or incidents
Cyber resilience combines cybersecurity with business continuity, ensuring the organization can maintain operations and recover quickly from cyber incidents.
Question 42: The OCC's 'heightened standards' guidance (12 CFR Part 30, Appendix D) applies to national banks and federal savings associations with assets exceeding:
- $10 billion
- $50 billion
- $250 billion
- $100 billion (Correct answer)
Correct answer: $100 billion
OCC's heightened standards for risk governance apply to covered institutions with average total consolidated assets of $50 billion or more—though often cited as $50B, the OCC's own threshold is $50B for initial applicability.
Question 43: A risk architect is reviewing their company's ERM program, which is based on the COSO framework. They notice that while risks are identified and assessed, the process for evaluating how well the ERM components are functioning over time and making necessary adjustments is weak. Which COSO ERM component needs to be strengthened?
- Review & Revision (Correct answer)
- Information, Communication, & Reporting
- Performance
- Strategy & Objective-Setting
Correct answer: Review & Revision
The 'Review & Revision' component of the COSO ERM framework deals with assessing the performance of the ERM capabilities over time and pursuing continual improvement. If the process for evaluating the effectiveness of the ERM components and making adjustments is weak, this is the specific component that requires attention.
Question 44: When developing a risk register, which attribute of a risk entry is MOST critical for enabling effective risk ownership?
- A named individual accountable for managing the risk (Correct answer)
- A color-coded priority rating
- A reference to the regulatory framework the risk falls under
- A unique risk identifier number
Correct answer: A named individual accountable for managing the risk
Assigning a named risk owner establishes clear accountability, ensuring someone is responsible for monitoring, reporting, and responding to each risk.
Question 45: What is a Business Continuity Management System (BCMS)?
- An insurance policy mechanism covering financial losses from business disruptions
- A holistic management framework that establishes, implements, and continually improves business continuity capabilities (Correct answer)
- A database repository of all historical business disruptions and responses
- A software application for tracking and logging disruption incidents
Correct answer: A holistic management framework that establishes, implements, and continually improves business continuity capabilities
A BCMS is a comprehensive management framework based on standards like ISO 22301 that integrates policies, procedures, and controls to build and maintain business continuity capabilities.
Question 46: A copula function in risk modeling is used primarily to:
- Convert discrete risk events into continuous probability distributions
- Model the dependence structure between random variables independently of their marginals (Correct answer)
- Estimate the marginal distribution of individual risk variables
- Calculate the expected value of a portfolio of risks
Correct answer: Model the dependence structure between random variables independently of their marginals
Copulas capture the joint dependence structure between variables while allowing separate modeling of each variable's marginal distribution.
Question 47: What is the primary purpose of a Business Impact Analysis (BIA)?
- To evaluate the effectiveness of marketing campaigns
- To identify critical business functions and quantify the impact of their disruption (Correct answer)
- To conduct a financial statement audit
- To assess employee job satisfaction levels
Correct answer: To identify critical business functions and quantify the impact of their disruption
A BIA identifies which business processes are critical, quantifies disruption impacts, and informs recovery time and point objectives.
Question 48: When applying a risk mitigation hierarchy, which approach should typically be considered first before other response strategies?
- Risk transfer
- Risk elimination (avoidance) (Correct answer)
- Risk reduction
- Risk acceptance
Correct answer: Risk elimination (avoidance)
Risk elimination — removing the source of the risk entirely — is the most effective response and should be evaluated before less complete strategies.
Question 49: Which certification is most commonly accepted as evidence of a vendor's information security controls effectiveness over time?
- SOC 2 Type II examination report (Correct answer)
- PCI DSS Level 4 self-assessment questionnaire
- GDPR Article 42 certification
- ISO 9001 Quality Management certification
Correct answer: SOC 2 Type II examination report
SOC 2 Type II reports provide evidence that a vendor's security, availability, and confidentiality controls operated effectively over a defined reporting period.
Question 50: What is the role of the 'Business Indicator' (BI) in the Basel III Standardized Measurement Approach for operational risk capital?
- It serves as a proxy for a bank's size and activity level to determine base capital requirements (Correct answer)
- It measures the number of business lines in a bank
- It tracks customer satisfaction scores across products
- It calculates the probability of default for each business unit
Correct answer: It serves as a proxy for a bank's size and activity level to determine base capital requirements
The Business Indicator is a financial measure combining interest, services, and financial components that acts as a proxy for the bank's operational risk exposure based on its business volume.
Certified Risk Architect (CRA)
The Certified Risk Architect (CRA) credential validates expertise in designing and implementing enterprise risk management frameworks, covering business continuity, regulatory compliance, quantitative risk analysis, mitigation strategies, and risk technology.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds