CRA Risk Identification & Assessment 3 — Questions and Answers
Question 1: A risk architect reviews a heat map showing risks plotted by likelihood and impact. A risk in the top-right quadrant should be treated how?
- Accepted, as all risks appearing on a heat map are within tolerance
- Transferred to a third party immediately without further analysis
- Prioritized for urgent risk response given high likelihood and high impact (Correct answer)
- Archived, as heat maps are only used for historical documentation
Correct answer: Prioritized for urgent risk response given high likelihood and high impact
Risks in the top-right quadrant of a heat map have both high likelihood and high impact, making them the highest priority for immediate risk response.
Question 2: Which statistical distribution is most commonly used to model the frequency of operational loss events in quantitative risk assessments?
- Normal distribution
- Poisson distribution (Correct answer)
- Beta distribution
- Uniform distribution
Correct answer: Poisson distribution
The Poisson distribution is widely used to model the frequency of rare, discrete loss events over a fixed time period in operational risk modeling.
Question 3: What is the key difference between 'inherent risk' and 'residual risk'?
- Inherent risk applies only to financial institutions; residual risk applies to all industries
- Inherent risk is the risk before controls, while residual risk is the risk remaining after controls are applied (Correct answer)
- Inherent risk is assessed qualitatively, while residual risk must be assessed quantitatively
- Inherent risk is strategic, while residual risk is operational
Correct answer: Inherent risk is the risk before controls, while residual risk is the risk remaining after controls are applied
Inherent risk is the raw exposure before any controls, while residual risk is what remains after existing controls and mitigations are factored in.
Question 4: During a bow-tie analysis, what does the 'tie' in the center represent?
- The risk owner responsible for managing the event
- The top event or hazardous event being analyzed (Correct answer)
- The financial impact threshold for the risk
- The control testing schedule
Correct answer: The top event or hazardous event being analyzed
In bow-tie analysis, the central 'knot' represents the top event or hazard, with threats on the left and consequences on the right.
Question 5: Which risk identification method systematically examines each step in a process to identify what could go wrong and why?
- PESTLE Analysis
- Hazard and Operability Study (HAZOP) (Correct answer)
- Delphi Technique
- Scenario Analysis
Correct answer: Hazard and Operability Study (HAZOP)
HAZOP systematically examines each process step using guide words to identify deviations and potential hazards in complex operational systems.
Question 6: A company in the retail sector wants to identify risks from its external environment including regulatory, economic, and social changes. Which framework is best suited for this purpose?
- COSO ERM Framework
- PESTLE Analysis (Correct answer)
- ISO 31000
- FAIR Model
Correct answer: PESTLE Analysis
PESTLE Analysis (Political, Economic, Social, Technological, Legal, Environmental) is specifically designed to identify external macro-environmental risks.
Question 7: What is 'velocity' in the context of risk assessment?
- The speed at which a risk can escalate from identification to impact (Correct answer)
- The financial magnitude of a risk event
- The frequency with which a risk is reviewed in the risk register
- The number of stakeholders affected by a risk event
Correct answer: The speed at which a risk can escalate from identification to impact
Risk velocity measures how quickly a risk can materialize and cause harm once triggered, informing the urgency of response planning.
A risk architect reviews a heat map showing risks plotted by likelihood and impact.
A risk in the top-right quadrant should be treated how?