Mixed Deck — All CRA Topics Flashcards
100 cards from real CRA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All CRA Topics flashcards as text
When developing a risk register, which attribute of a risk entry is MOST critical for enabling effective risk ownership?
Answer: A named individual accountable for managing the risk
Assigning a named risk owner establishes clear accountability, ensuring someone is responsible for monitoring, reporting, and responding to each risk.
Which of the following represents a 'secondary risk' in risk management?
Answer: A risk that arises as a direct result of implementing a risk response
Secondary risks are new risks that emerge as unintended consequences of implementing a risk response or mitigation action.
In risk-adjusted performance measurement, RAROC is calculated as:
Answer: Risk-adjusted return divided by economic capital
RAROC (Risk-Adjusted Return on Capital) = Risk-adjusted net income / Economic capital, used to compare performance across business units on a risk basis.
What is a risk acceptance strategy?
Answer: Accepting the risk and planning for its consequences
Risk acceptance is a deliberate decision by an organization to acknowledge a risk and tolerate its potential consequences without implementing specific mitigation actions to reduce its likelihood or impact. This strategy is typically chosen when the cost of mitigation outweighs the potential loss, or when the risk is deemed low. However, it often involves having contingency plans in place to manage the fallout if the risk materializes.
A company is deciding whether to develop a new product line internally or to acquire a smaller company that already has a similar product. This decision involves multiple stages, uncertain outcomes, and associated costs and payoffs. Which quantitative risk analysis technique is most appropriate for visualizing and evaluating these different paths and their potential outcomes?
Answer: Decision Tree Analysis
Decision Tree Analysis is specifically designed for situations involving sequential decisions and their potential outcomes under conditions of uncertainty. It provides a visual, tree-like model of decisions and their possible consequences, including chance events, resource costs, and utility, making it perfect for comparing complex strategic choices like 'build versus buy'.
What is the primary financial risk implication of a company having a high proportion of fixed costs relative to variable costs?
Answer: Higher operating leverage, amplifying earnings volatility during revenue fluctuations
High fixed costs increase operating leverage, causing small revenue changes to produce magnified swings in operating profit, increasing earnings volatility and financial risk.
In strategic risk governance, a 'second opinion' or 'challenge function' is MOST important when:
Answer: High-stakes strategic decisions are being made with limited time for deliberation
Challenge functions prevent groupthink and cognitive bias precisely when the stakes are highest and time pressure may suppress dissenting views.
What is the primary function of Key Risk Indicators (KRIs) in a risk technology system?
Answer: To provide early warning signals of increasing risk exposure
KRIs serve as early warning metrics that signal when risk levels are approaching unacceptable thresholds, enabling proactive risk management.
Under the Sarbanes-Oxley Act Section 302, which executive is primarily responsible for certifying the accuracy of financial reports?
Answer: CEO and CFO jointly
SOX Section 302 requires the CEO and CFO to personally certify the accuracy and completeness of financial reports filed with the SEC.
A risk architect observes that two risk factors have a Pearson correlation of 0.85 in normal conditions but move in tandem almost perfectly during market crises. This phenomenon is known as:
Answer: Tail dependence
Tail dependence describes the tendency of variables to become more strongly correlated in the tails of their joint distribution, particularly during extreme events.
When applying a risk mitigation hierarchy, which approach should typically be considered first before other response strategies?
Answer: Risk elimination (avoidance)
Risk elimination — removing the source of the risk entirely — is the most effective response and should be evaluated before less complete strategies.
What is the primary purpose of a risk register in an enterprise risk management program?
Answer: To serve as a centralized record documenting identified risks, their attributes, and assigned ownership
The risk register is a central repository that captures all identified risks, their likelihood, impact, owners, and response strategies for tracking and governance.
Which concept describes risks that are difficult to identify because they fall between established organizational silos and are owned by no single function?
Answer: Orphan risks
Orphan risks are those that fall through the cracks of organizational ownership because they span multiple departments or functions with no clear accountable owner.
Why is continuous monitoring of risks necessary in risk management?
Answer: It helps identify new or changing risks and adjust mitigation strategies
Continuous monitoring of risks is crucial because the business environment is dynamic, meaning new risks can emerge and existing ones can change in nature or severity. This ongoing process allows organizations to promptly identify these shifts and adjust their mitigation strategies accordingly. It ensures the risk management plan remains relevant and effective in protecting the organization.
Which regulatory body oversees the enforcement of the Foreign Corrupt Practices Act (FCPA) for securities-related violations?
Answer: Securities and Exchange Commission (SEC)
The SEC enforces FCPA's anti-bribery and accounting provisions for issuers of securities, while the DOJ handles criminal enforcement.
Which statistical test is commonly used to assess whether observed loss data fits a hypothesized parametric distribution?
Answer: Kolmogorov-Smirnov (K-S) test
The K-S test compares the empirical cumulative distribution function of the data to the theoretical CDF of the hypothesized distribution.
Under the EU's Digital Operational Resilience Act (DORA), financial entities must report major ICT-related incidents to competent authorities within what initial timeframe?
Answer: 24 hours
DORA requires an initial notification to competent authorities within 24 hours of classifying an incident as major, followed by an intermediate report within 72 hours.
Which of the following is a key limitation of using historical data alone for quantitative operational risk modeling?
Answer: Rare tail events may not be represented in the historical record
Black swan or low-frequency, high-severity events may simply not appear in historical datasets, causing models to underestimate tail risk.
In the NIST Risk Management Framework, which step involves selecting and implementing security controls?
Answer: Implement
The Implement step in NIST RMF focuses on putting chosen security controls into practice within the information system.
What is the primary purpose of a Risk Information System (RIS)?
Answer: To centralize and manage risk data for reporting and analysis
A Risk Information System centralizes risk data to support consistent reporting, monitoring, and decision-making across the enterprise.