CRA Operational Risk Management 3 — Questions and Answers
Question 1: A risk architect is designing a three lines of defense model. Which function represents the second line of defense?
- Business units owning and managing risks day-to-day
- Risk and compliance functions providing oversight and challenge (Correct answer)
- Internal audit providing independent assurance
- External auditors and regulators
Correct answer: Risk and compliance functions providing oversight and challenge
The second line of defense consists of risk management and compliance functions that set frameworks, provide oversight, and challenge the first line's risk management.
Question 2: What distinguishes a 'near miss' from an operational loss event in loss data collection?
- Near misses involve external parties while loss events are internal
- A near miss is an event that could have resulted in a loss but did not due to chance or control intervention (Correct answer)
- Near misses are always caused by technology failures
- A near miss always exceeds the reporting threshold
Correct answer: A near miss is an event that could have resulted in a loss but did not due to chance or control intervention
A near miss is an incident where a loss was averted—by luck or control—providing valuable risk intelligence without an actual financial impact.
Question 3: Which scenario analysis technique involves asking subject matter experts to estimate the frequency and severity of hypothetical extreme operational risk scenarios?
- Monte Carlo simulation
- Stress testing using historical data
- Expert judgment-based scenario analysis (Correct answer)
- Regression analysis
Correct answer: Expert judgment-based scenario analysis
Expert judgment-based scenario analysis elicits structured estimates from experienced practitioners for rare but plausible events not captured in historical loss data.
Question 4: A bank's operational risk framework establishes a risk appetite of no more than $10M in annual operational losses. This type of statement is best classified as a:
- Risk tolerance threshold (Correct answer)
- Key Risk Indicator limit
- Risk capacity statement
- Regulatory minimum
Correct answer: Risk tolerance threshold
A risk tolerance threshold defines the acceptable level of risk variation the institution is willing to experience relative to its risk appetite.
Question 5: Under the OCC's Heightened Standards (12 CFR Part 30), which of the following is a required component of an operational risk management framework for large US banks?
- Quarterly board certification of zero operational losses
- A risk governance framework with an independent risk management function reporting to the board (Correct answer)
- Mandatory outsourcing of operational risk assessments to third parties
- Elimination of all manual processes to prevent human error
Correct answer: A risk governance framework with an independent risk management function reporting to the board
OCC Heightened Standards require large banks to have an independent risk management function with direct reporting lines to the board to ensure objective oversight.
Question 6: When evaluating vendor/third-party operational risk, which control is most critical for ensuring business continuity if a key vendor fails?
- Requiring vendors to carry cyber insurance
- Maintaining a documented exit strategy and fallback arrangements (Correct answer)
- Conducting annual vendor audits
- Capping vendor contract values below $1M
Correct answer: Maintaining a documented exit strategy and fallback arrangements
A documented exit strategy and fallback arrangements ensure the organization can transfer services or bring them in-house if a critical vendor becomes unavailable.
Question 7: In operational risk management, what is the difference between inherent risk and residual risk?
- Inherent risk is financial loss only; residual risk includes reputational loss
- Inherent risk exists before controls; residual risk remains after controls are applied (Correct answer)
- Inherent risk is quantified; residual risk is qualitative
- Inherent risk applies to market risk; residual risk applies to credit risk
Correct answer: Inherent risk exists before controls; residual risk remains after controls are applied
Inherent risk is the gross risk level before any mitigating controls are considered; residual risk is what remains after the effectiveness of controls is accounted for.
A risk architect is designing a three lines of defense model.
Which function represents the second line of defense?