Risk Identification Principles Flashcards
7 cards from real CRA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Risk Identification Principles flashcards as text
Which cognitive bias causes risk identification teams to focus disproportionately on risks that are easily recalled from recent or dramatic events?
Answer: Availability heuristic
The availability heuristic leads people to overweight risks that come easily to mind due to recent exposure or emotional salience, distorting comprehensive identification.
In the context of CRA risk architecture, what is the significance of identifying 'risk interdependencies'?
Answer: They reveal how the materialization of one risk can trigger or amplify other risks
Risk interdependencies show correlations and causal chains between risks, which is critical for understanding aggregate exposure and cascading failure scenarios.
A financial institution uses scenario analysis to identify risks. Which scenario type is MOST useful for identifying tail risks that fall outside normal operating ranges?
Answer: Stress scenarios based on severe but plausible adverse conditions
Stress scenarios push the system to extreme but credible conditions, making them the best tool for surfacing tail risks that standard analysis would miss.
When developing a risk register, which attribute of a risk entry is MOST critical for enabling effective risk ownership?
Answer: A named individual accountable for managing the risk
Assigning a named risk owner establishes clear accountability, ensuring someone is responsible for monitoring, reporting, and responding to each risk.
Which of the following is the BEST example of a 'risk appetite statement' informing the risk identification process?
Answer: We will not pursue markets where regulatory uncertainty could impair our license to operate
A risk appetite statement defines boundaries around acceptable risk-taking, directly guiding which risk scenarios warrant identification and response versus acceptance.
An organization's risk team identifies a risk but cannot determine its likelihood or impact due to insufficient data. How should this risk be treated in the register?
Answer: Record it with a notation of high uncertainty and establish a data-gathering plan
Risks with high uncertainty should still be recorded with an acknowledgment of data gaps and a plan to gather the information needed for proper assessment.
Which framework explicitly integrates risk identification as a core component of the internal control environment, linking it to financial reporting reliability?
Answer: COSO ERM Framework
The COSO ERM Framework embeds risk identification within its components of risk assessment and control activities, directly linking it to reliable financial reporting and governance.