Operational Risk Management Flashcards
7 cards from real CRA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Operational Risk Management flashcards as text
A risk architect is implementing an Operational Risk Management Information System (ORMIS). Which capability is most essential for aggregating enterprise-wide operational risk data?
Answer: Standardized taxonomy and data dictionary across all business lines
A consistent taxonomy and data dictionary ensures that loss events, KRIs, and RCSA results are classified and reported uniformly across business units for meaningful aggregation.
Which of the following is an example of 'boundary risk' in the context of operational risk classification?
Answer: Risk events that have characteristics of both operational and market/credit risk
Boundary events, such as failed settlement due to a systems error causing a credit exposure, straddle two risk categories and require careful classification to avoid double-counting.
A bank is considering using external loss data from a consortium to supplement its internal loss data. What is the primary challenge of using external data?
Answer: External losses may not be relevant due to differences in business scale, environment, and controls
External loss data must be scaled and adjusted for relevance because other institutions' sizes, business mixes, and control environments may differ materially from the firm using the data.
What is the role of the 'Business Indicator' (BI) in the Basel III Standardized Measurement Approach for operational risk capital?
Answer: It serves as a proxy for a bank's size and activity level to determine base capital requirements
The Business Indicator is a financial measure combining interest, services, and financial components that acts as a proxy for the bank's operational risk exposure based on its business volume.
During a post-incident review of a major operational failure, which action most directly supports a culture of continuous improvement?
Answer: Conducting a root cause analysis and implementing systemic control enhancements
Root cause analysis identifies systemic weaknesses that enabled the failure, while control enhancements address those weaknesses to prevent recurrence.
Which operational risk framework element ensures that risk appetite is translated into actionable limits at the business line level?
Answer: Risk appetite cascading through risk tolerances and KRI thresholds
Cascading risk appetite into business-line tolerances and KRI thresholds operationalizes the board's risk appetite into day-to-day risk management decisions.
A firm's operational risk manager notes that a control designed to prevent unauthorized system access has a 'design gap' versus an 'operating gap.' What is the key distinction?
Answer: A design gap means the control is conceptually inadequate for the risk; an operating gap means the control exists but is not functioning as designed
A design gap indicates the control was never capable of addressing the risk adequately, while an operating gap means a well-designed control is failing in practice due to poor execution or circumvention.