CRA Risk Identification & Assessment 2 — Questions and Answers
Question 1: Which risk identification technique involves subject matter experts anonymously providing estimates that are refined through multiple rounds of feedback?
- Nominal Group Technique
- Delphi Technique (Correct answer)
- SWOT Analysis
- Root Cause Analysis
Correct answer: Delphi Technique
The Delphi Technique uses anonymous expert input over iterative rounds to converge on a consensus risk estimate without group-think bias.
Question 2: A risk architect is assessing operational risk in a financial institution. Which component of the Basel III framework specifically addresses operational risk capital requirements?
- Pillar 1 – Minimum Capital Requirements (Correct answer)
- Pillar 2 – Supervisory Review Process
- Pillar 3 – Market Discipline
- Leverage Ratio Framework
Correct answer: Pillar 1 – Minimum Capital Requirements
Pillar 1 of Basel III sets minimum capital requirements that explicitly include operational risk alongside credit and market risk.
Question 3: When using a Risk Breakdown Structure (RBS), what is its primary purpose in risk identification?
- To assign dollar values to identified risks
- To hierarchically categorize risk sources for systematic identification (Correct answer)
- To rank risks by probability and impact
- To document risk owners and response strategies
Correct answer: To hierarchically categorize risk sources for systematic identification
An RBS hierarchically categorizes risk sources, ensuring comprehensive coverage of all potential risk areas during identification.
Question 4: Which type of risk assessment approach assigns numerical probabilities and monetary values to risk outcomes?
- Qualitative risk assessment
- Quantitative risk assessment (Correct answer)
- Semi-quantitative risk assessment
- Inherent risk assessment
Correct answer: Quantitative risk assessment
Quantitative risk assessment uses numerical probabilities and financial values to produce objective, measurable risk metrics.
Question 5: An organization discovers that a single vendor supplies components to three critical business units, creating concentration risk. Which risk identification method would most likely have surfaced this dependency?
- Fault Tree Analysis
- Assumption Analysis
- Dependency Mapping (Correct answer)
- Checklist Analysis
Correct answer: Dependency Mapping
Dependency mapping visualizes relationships between suppliers, processes, and business units, surfacing concentration and single-point-of-failure risks.
Question 6: In the context of enterprise risk management, what does 'risk appetite' specifically define?
- The maximum possible loss an organization could suffer
- The amount and type of risk an organization is willing to accept in pursuit of its objectives (Correct answer)
- The residual risk remaining after controls are applied
- The cost of risk mitigation activities
Correct answer: The amount and type of risk an organization is willing to accept in pursuit of its objectives
Risk appetite defines the broad level and types of risk an organization is prepared to accept while pursuing its strategic goals.
Question 7: Which of the following best describes an 'emerging risk' in enterprise risk management?
- A known risk that has recently materialized into an actual loss event
- A risk that has been identified but not yet assigned an owner
- A risk that is new, evolving, or not yet fully understood with uncertain potential impact (Correct answer)
- A residual risk remaining after mitigation controls are implemented
Correct answer: A risk that is new, evolving, or not yet fully understood with uncertain potential impact
Emerging risks are new or evolving threats that are not yet fully understood, making their probability and impact difficult to quantify.
Which risk identification technique involves subject matter experts anonymously providing estimates that are refined through multiple rounds of feedback?