CRA Operational Risk Events & KRIs 2 — Questions and Answers
Question 1: Which Basel II operational risk event category covers losses from unauthorized trading activities?
- Clients, Products & Business Practices
- Internal Fraud (Correct answer)
- Execution, Delivery & Process Management
- Employment Practices & Workplace Safety
Correct answer: Internal Fraud
Unauthorized trading, such as rogue trading, falls under Internal Fraud because it involves intentional misuse of authority by an employee.
Question 2: A bank's KRI shows a spike in failed trade settlements over three consecutive days. What is the primary operational risk concern?
- Market risk exposure
- Execution, Delivery & Process Management failures (Correct answer)
- Credit counterparty default
- Regulatory capital shortfall
Correct answer: Execution, Delivery & Process Management failures
Repeated failed settlements signal process breakdowns in trade execution and lifecycle management, a core Execution, Delivery & Process Management event.
Question 3: Which characteristic distinguishes a Key Risk Indicator (KRI) from a Key Performance Indicator (KPI)?
- KRIs measure past outcomes while KPIs measure future risks
- KRIs signal potential risk exposure while KPIs measure operational efficiency (Correct answer)
- KRIs are always financial metrics; KPIs are non-financial
- KRIs are reported monthly; KPIs are reported quarterly
Correct answer: KRIs signal potential risk exposure while KPIs measure operational efficiency
KRIs are forward-looking signals of emerging risk, whereas KPIs measure how well a process is performing currently or historically.
Question 4: A fire destroys a firm's primary data center. Under Basel II event categories, this loss is classified as:
- External Fraud
- Damage to Physical Assets (Correct answer)
- Business Disruption & System Failures
- Execution, Delivery & Process Management
Correct answer: Damage to Physical Assets
Physical destruction of assets from natural or man-made disasters is categorized as Damage to Physical Assets under Basel II.
Question 5: An organization tracks 'number of unresolved audit findings' as a KRI. This metric primarily signals risk in which area?
- Market volatility
- Control environment effectiveness (Correct answer)
- Credit portfolio quality
- Liquidity buffer adequacy
Correct answer: Control environment effectiveness
Unresolved audit findings indicate weaknesses in the internal control environment, a direct operational risk signal.
Question 6: When setting KRI thresholds, a 'red' threshold is typically defined as:
- The level at which risk is within appetite and no action is needed
- The level requiring immediate escalation and management intervention (Correct answer)
- The level triggering enhanced monitoring but no immediate action
- The long-run historical average of the metric
Correct answer: The level requiring immediate escalation and management intervention
A red (breach) threshold signals that the risk has exceeded acceptable limits and requires immediate management escalation and corrective action.
Question 7: Which of the following is an example of an External Fraud operational risk event?
- Employee submitting false expense reports
- A hacker breaching the firm's systems to steal customer data (Correct answer)
- A rogue trader concealing losses
- Miscommunication between front and back office causing trade errors
Correct answer: A hacker breaching the firm's systems to steal customer data
Cyberattacks by external parties are classified as External Fraud under Basel II operational risk event categories.
Which Basel II operational risk event category covers losses from unauthorized trading activities?