โ† All CRA Flashcard Decks

Risk Identification Principles Flashcards

7 cards from real CRA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Identification Principles flashcards as text
  1. In enterprise risk management, what distinguishes a 'pure risk' from a 'speculative risk'?

    Answer: Pure risks involve only the possibility of loss, while speculative risks involve both possible loss and gain

    Pure risks present only downside outcomes (loss or no loss), whereas speculative risks carry both upside potential and downside loss, as seen in investment decisions.

  2. An organization operates in a highly regulated industry. Which risk identification source is MOST likely to surface emerging regulatory risks before they become compliance failures?

    Answer: Regulatory horizon scanning and legislative monitoring programs

    Horizon scanning and legislative monitoring proactively track proposed regulations and enforcement trends before they become mandatory requirements.

  3. Which concept describes risks that are difficult to identify because they fall between established organizational silos and are owned by no single function?

    Answer: Orphan risks

    Orphan risks are those that fall through the cracks of organizational ownership because they span multiple departments or functions with no clear accountable owner.

  4. A risk architect facilitates a pre-mortem session before a major system implementation. What is the PRIMARY purpose of this technique?

    Answer: To prospectively imagine the project has failed and identify what could have caused it

    A pre-mortem asks participants to assume failure has already occurred and work backward to identify the most likely causes, surfacing overlooked risks.

  5. When identifying technology risks, which factor most significantly increases an organization's exposure to supply chain software risks?

    Answer: Reliance on third-party libraries and software dependencies without ongoing vulnerability tracking

    Untracked third-party dependencies create hidden attack surfaces and vulnerabilities that the organization does not directly control or monitor.

  6. What is the primary purpose of a Risk Breakdown Structure (RBS) in the identification phase?

    Answer: To hierarchically categorize risk sources to ensure comprehensive coverage across all domains

    An RBS organizes risks into a hierarchical framework by source category, helping ensure that no major risk domain is overlooked during identification.

  7. Which of the following scenarios BEST illustrates a 'strategic risk' as distinct from an operational risk?

    Answer: Competitor adoption of disruptive technology that renders the organization's core product obsolete

    Strategic risks threaten the viability of the organization's business model or competitive position, unlike operational risks which affect day-to-day processes.

Risk Identification Principles Flashcards โ€” CRA Study Cards with Answers