Certified Risk Analyst (CRA) β Questions and Answers
Question 1: Which organization publishes the annual Global Risks Report that is widely used as a reference for emerging risk identification?
- World Economic Forum (WEF) (Correct answer)
- Bank for International Settlements (BIS)
- Organisation for Economic Co-operation and Development (OECD)
- International Monetary Fund (IMF)
Correct answer: World Economic Forum (WEF)
The World Economic Forum publishes the annual Global Risks Report, which surveys global leaders to identify and rank the most critical emerging risks across economic, environmental, geopolitical, societal, and technological categories.
Question 2: Which Pillar of the Basel framework covers market discipline through public disclosure requirements?
- Pillar 3 (Correct answer)
- Pillar 4
- Pillar 1
- Pillar 2
Correct answer: Pillar 3
Pillar 3 of Basel requires banks to publicly disclose their risk exposures, capital adequacy, and risk management practices to enhance market discipline.
Question 3: Which decision-making framework specifically accounts for ambiguity by distinguishing between situations where probabilities are known versus unknown?
- Expected utility theory
- Knight's distinction between risk and uncertainty (Correct answer)
- Monte Carlo simulation
- Bayesian updating
Correct answer: Knight's distinction between risk and uncertainty
Frank Knight distinguished between risk (known probabilities) and uncertainty (unknown probabilities), which is foundational to modern risk decision-making frameworks.
Question 4: Which method is used for quantitative risk assessment?
- Flowcharts
- Role play
- Qualitative matrix
- Decision tree analysis (Correct answer)
Correct answer: Decision tree analysis
Decision tree analysis is a quantitative risk assessment method that visually maps out possible decisions and their potential outcomes, including associated probabilities and costs/benefits. It helps in making informed choices under uncertainty by calculating expected monetary values for different paths.
Question 5: A portfolio manager uses a copula in Monte Carlo VaR to model the dependence structure between assets. What does a Gaussian copula fail to capture compared to a t-copula?
- Individual asset volatility
- Linear correlation between assets
- Portfolio-level diversification benefits
- Tail dependence during market stress (Correct answer)
Correct answer: Tail dependence during market stress
The Gaussian copula implies zero tail dependence, meaning extreme joint losses appear less likely than observed in real markets; the t-copula captures positive tail dependence.
Question 6: A bank is classified as 'well capitalized' under U.S. PCA rules if its Total Risk-Based Capital ratio is at least:
- 12%
- 10% (Correct answer)
- 8%
- 6%
Correct answer: 10%
A U.S. bank is 'well capitalized' under PCA if its Total Risk-Based Capital ratio is at least 10%, Tier 1 ratio at least 8%, and CET1 at least 6.5%.
Question 7: Which risk appetite framework component links strategic objectives directly to acceptable risk levels for each business line?
- Risk heat map
- Risk tolerance cascade (Correct answer)
- Risk register
- Control self-assessment
Correct answer: Risk tolerance cascade
The risk tolerance cascade translates the enterprise-level risk appetite into specific, actionable limits for individual business lines aligned to their strategic objectives.
Question 8: What does transparency mean in governance?
- Sharing trade secrets
- Open communication and clear disclosures (Correct answer)
- Avoiding board meetings
- Keeping decisions private
Correct answer: Open communication and clear disclosures
Transparency in governance means that an organization's operations, decisions, and information are accessible and understandable to its stakeholders. It fosters trust and accountability by ensuring clear communication and full disclosure of relevant information, rather than keeping matters private.
Question 9: A new CEO wants to increase the firm's risk appetite significantly to pursue aggressive growth. What is the CORRECT governance process?
- The CEO can unilaterally update the risk appetite statement immediately
- The proposed change must be presented to and approved by the Board of Directors (Correct answer)
- Risk appetite can be changed by the CRO without board involvement
- The change takes effect automatically at the start of the next fiscal year
Correct answer: The proposed change must be presented to and approved by the Board of Directors
Material changes to risk appetite require Board of Directors approval, as the board bears ultimate accountability for setting and overseeing the organization's risk appetite.
Question 10: Which COSO ERM principle states that organizations should 'identify risk in the context of business context'?
- Principle 8 β Assesses Severity of Risk
- Principle 10 β Identifies Risk (Correct answer)
- Principle 6 β Analyzes Business Context
- Principle 12 β Prioritizes Risks
Correct answer: Principle 10 β Identifies Risk
Principle 10 states that the organization identifies risk and considers how it might affect the achievement of strategy and business objectives.
Question 11: A company's risk committee reviews a project with a positive NPV but a tail risk scenario that could cause insolvency. The committee rejects the project. This decision BEST reflects:
- Ignoring shareholder return requirements
- Over-application of the precautionary principle in a low-stakes context
- Maximizing expected monetary value
- Applying a risk constraint that protects organizational survival over pure expected-value optimization (Correct answer)
Correct answer: Applying a risk constraint that protects organizational survival over pure expected-value optimization
Protecting the firm from ruin risk means accepting a lower expected return to avoid scenarios that threaten solvency, a principle central to enterprise risk management.
Question 12: A bank's risk appetite statement says it will accept up to $50M in credit losses annually. This year losses reach $48M. What is the most appropriate immediate action?
- Immediately liquidate credit exposures
- Issue a warning and increase monitoring intensity (Correct answer)
- Take no action as the limit has not been breached
- Escalate to the board for breach authorization
Correct answer: Issue a warning and increase monitoring intensity
When approaching but not yet breaching a tolerance limit, the appropriate response is to issue an early warning and heighten monitoring to prevent an actual breach.
Question 13: What is risk transference?
- Accepting the risk fully
- Avoiding the risk
- Ignoring the risk
- Outsourcing or insuring against the risk (Correct answer)
Correct answer: Outsourcing or insuring against the risk
Risk transference is a strategy where the financial responsibility or consequences of a risk are shifted to a third party. This is most commonly achieved through purchasing insurance, where an insurer agrees to cover potential losses, or by outsourcing a risky activity to another entity. The goal is to offload the burden of a potential loss to someone else.
Question 14: The Bank Secrecy Act (BSA) requires financial institutions to file a Suspicious Activity Report (SAR) within how many calendar days of detecting a suspicious transaction?
- 60 days
- 30 days (Correct answer)
- 45 days
- 15 days
Correct answer: 30 days
Under BSA regulations, financial institutions must file a SAR within 30 calendar days of the initial detection of the suspicious activity.
Question 15: Which governance mechanism ensures that the risk function maintains independence from business line pressures?
- Risk managers reporting directly to business unit heads
- Risk policies being drafted by front-office staff
- Risk budgets being controlled by the trading desk
- The Chief Risk Officer (CRO) having a direct reporting line to the board or CEO (Correct answer)
Correct answer: The Chief Risk Officer (CRO) having a direct reporting line to the board or CEO
Independence of the risk function is preserved when the CRO reports directly to the board or CEO, preventing business units from overriding or suppressing unfavorable risk assessments.
Question 16: A company faces a 15% probability of a $2M loss from a supplier default. The annual insurance premium to cover this risk is $280,000. What is the expected value of the uninsured loss?
- $280,000
- $300,000 (Correct answer)
- $1,700,000
- $2,000,000
Correct answer: $300,000
Expected value = probability Γ impact = 0.15 Γ $2,000,000 = $300,000, which exceeds the $280,000 premium, making insurance cost-effective.
Question 17: A manufacturing company's ERM team identifies that a key supplier has a single point of failure. This is an example of which risk category?
- Operational/supply chain risk (Correct answer)
- Market risk
- Liquidity risk
- Reputational risk
Correct answer: Operational/supply chain risk
Single-supplier dependence is a concentration within supply chain operations, which falls under operational risk.
Question 18: Which practice best ensures that risk dashboard information remains actionable rather than purely decorative?
- Publishing the dashboard quarterly in an annual report
- Keeping all risks visible on the dashboard regardless of current status
- Designing the dashboard purely for external stakeholder communication
- Linking each dashboard indicator to specific owners, response plans, and review dates (Correct answer)
Correct answer: Linking each dashboard indicator to specific owners, response plans, and review dates
Tying each indicator to an owner, a response plan, and a review date transforms the dashboard from an informational display into a management tool.
Question 19: Which ERM concept describes the total risk an entity can bear before it breaches its capital or operational limits?
- Risk tolerance
- Risk appetite
- Residual risk
- Risk capacity (Correct answer)
Correct answer: Risk capacity
Risk capacity is the maximum risk an organization can absorb given its financial and operational resources.
Question 20: Which communication practice is most effective for a CRA communicating risk findings to a non-technical executive audience?
- Providing complete mathematical derivations of risk models
- Sharing only quantitative data without contextual interpretation
- Presenting raw statistical outputs and confidence intervals
- Translating complex risk metrics into business impact using plain language and visuals (Correct answer)
Correct answer: Translating complex risk metrics into business impact using plain language and visuals
Effective risk communication to executives requires simplifying technical findings into clear business language that highlights impact, likelihood, and recommended actions.
Question 21: Why is decision-making critical in risk management?
- To increase documentation
- To prolong planning stages
- To reduce teamwork
- To choose effective risk responses (Correct answer)
Correct answer: To choose effective risk responses
Decision-making is critical in risk management because it involves evaluating identified risks and selecting the most appropriate response strategy. Effective decisions ensure that an organization chooses the best course of action, whether it's to mitigate, accept, transfer, or avoid a risk. This strategic choice directly impacts the organization's ability to achieve its objectives while managing potential threats.
Question 22: In the context of regulatory capital requirements, what role does continuous professional development play for CRA practitioners?
- It is optional and only needed for career advancement
- It ensures practitioners remain current with evolving standards, technologies, and best practices (Correct answer)
- It is required only during the first year of certification
- It serves primarily as a networking opportunity with no practical benefit
Correct answer: It ensures practitioners remain current with evolving standards, technologies, and best practices
Continuous professional development is essential in regulatory capital requirements because it ensures CRA practitioners remain current with evolving standards, technologies, and best practices, maintaining competency throughout their careers.
Question 23: Which of the following is a fundamental principle of bcp & crisis scenario planning as it applies to Certified Risk Analyst?
- Avoiding documentation to streamline workflow efficiency
- Prioritizing speed of completion over accuracy and compliance
- Relying solely on personal experience without reference to guidelines
- Systematic evaluation and adherence to established industry standards (Correct answer)
Correct answer: Systematic evaluation and adherence to established industry standards
A fundamental principle of bcp & crisis scenario planning in Certified Risk Analyst is the systematic evaluation and adherence to established industry standards, which ensures consistency, quality, and regulatory compliance across all professional activities.
Question 24: In Monte Carlo VaR, which distribution assumption is most commonly used to model daily equity returns as a starting point?
- Lognormal distribution (Correct answer)
- Exponential distribution
- Uniform distribution
- Poisson distribution
Correct answer: Lognormal distribution
Equity prices are typically modeled as lognormal, meaning daily log-returns follow a normal distribution, which is the standard starting point in Monte Carlo equity VaR models.
Question 25: Which law is designed to prevent corporate fraud?
- Sarbanes-Oxley Act (Correct answer)
- Dodd-Frank Act
- HIPAA
- FERPA
Correct answer: Sarbanes-Oxley Act
The Sarbanes-Oxley Act (SOX) was enacted in 2002 in response to major corporate and accounting scandals. It mandates strict reforms to improve financial disclosures from corporations and prevent accounting fraud, enhancing corporate responsibility and protecting investors.
Question 26: A risk analyst presenting findings to regulators should prioritize which communication approach?
- Presenting only data that supports the desired regulatory outcome
- Emphasizing only positive risk outcomes to maintain confidence
- Providing transparent, accurate, and complete risk disclosures including limitations and uncertainties (Correct answer)
- Withholding model assumptions to protect proprietary methodologies
Correct answer: Providing transparent, accurate, and complete risk disclosures including limitations and uncertainties
Regulatory communications require full transparency, including disclosure of model limitations, data gaps, and uncertainties, to maintain regulatory trust and compliance.
Question 27: When constructing a geopolitical risk heat map, which dimension is plotted on the impact axis?
- Time horizon until the risk materializes
- Probability of the risk event occurring
- Magnitude of potential consequences on business objectives (Correct answer)
- Number of countries affected by the risk
Correct answer: Magnitude of potential consequences on business objectives
A risk heat map plots likelihood on one axis and impact (magnitude of consequences) on the other, allowing analysts to prioritize risks by their potential severity on business objectives.
Question 28: Which type of risk report is specifically designed to provide the board of directors with a high-level view of the firm's risk profile?
- Board Risk Report (BRR) (Correct answer)
- Operational risk incident log
- Trading desk P&L attribution report
- Credit analyst underwriting memo
Correct answer: Board Risk Report (BRR)
The Board Risk Report (BRR) aggregates key risk metrics, emerging threats, and limit breaches into a concise document tailored for board-level governance.
Question 29: In importance sampling (a Monte Carlo variance reduction technique), how is the distribution altered to improve VaR estimation efficiency?
- Random draws are replaced with equally spaced deterministic points
- The correlation matrix is replaced with an identity matrix
- More probability mass is placed on tail scenarios and reweighted to correct for the shift (Correct answer)
- All scenarios are weighted equally regardless of loss magnitude
Correct answer: More probability mass is placed on tail scenarios and reweighted to correct for the shift
Importance sampling shifts the sampling distribution toward the tail of interest and applies a likelihood ratio correction (Radon-Nikodym derivative) to obtain unbiased estimates with lower variance.
Question 30: What tool helps prioritize risk mitigation efforts?
- Gantt chart
- Project schedule
- Risk matrix (Correct answer)
- Budget report
Correct answer: Risk matrix
A risk matrix is a powerful tool used to prioritize risk mitigation efforts by visually plotting risks based on their likelihood and potential impact. This allows organizations to quickly identify which risks are most critical (high likelihood, high impact) and require immediate attention. By prioritizing, resources can be allocated efficiently to address the most significant threats.
Question 31: A 'risk champion' within an organization's business unit primarily serves to:
- Promote risk awareness and act as a liaison between the business and risk function (Correct answer)
- Replace the risk management department for that unit
- Approve all risk-taking decisions within the unit
- Conduct independent audits of risk controls
Correct answer: Promote risk awareness and act as a liaison between the business and risk function
Risk champions embed risk awareness in their business unit, bridging the gap between frontline staff and the centralized risk management function.
Question 32: An analyst notices that a country's government is increasingly controlling media narratives and judiciary appointments. From a risk perspective, this most directly signals:
- Elevated rule-of-law and governance risk (Correct answer)
- Improving institutional stability
- Reduced regulatory compliance burden
- Decreased expropriation likelihood
Correct answer: Elevated rule-of-law and governance risk
Concentration of media and judicial control by the government signals weakening institutional checks, which elevates rule-of-law risk and makes contractual and legal protections less reliable.
Question 33: Which statistical measure captures the average loss in the tail of a loss distribution beyond the VaR threshold?
- Semi-variance
- Standard deviation
- Tracking error
- Expected Shortfall (CVaR) (Correct answer)
Correct answer: Expected Shortfall (CVaR)
Expected Shortfall (also called CVaR or Conditional VaR) measures the average loss given that losses exceed the VaR level, capturing tail risk better than VaR alone.
Question 34: When documenting activities related to emerging & geopolitical risks, which practice is considered essential for CRA certification holders?
- Maintaining comprehensive records that include procedures, observations, results, and any anomalies (Correct answer)
- Recording only outcomes while omitting the methods and processes used
- Completing documentation only when requested by auditors or supervisors
- Keeping documentation in personal notes that are not accessible to other team members
Correct answer: Maintaining comprehensive records that include procedures, observations, results, and any anomalies
Comprehensive documentation that includes procedures, observations, results, and any anomalies is essential in emerging & geopolitical risks. This supports quality assurance, enables peer review, and satisfies regulatory and audit requirements.
Question 35: A global bank operates across 15 countries. How should its risk appetite framework handle jurisdictional variations in regulatory requirements?
- Set a single universal tolerance that satisfies the strictest jurisdiction
- Establish a global appetite baseline with local overlays that respect stricter local requirements (Correct answer)
- Allow each subsidiary to independently set its own risk appetite
- Apply only the home country's risk appetite globally
Correct answer: Establish a global appetite baseline with local overlays that respect stricter local requirements
Best practice is a global baseline appetite with local overlays that tighten thresholds where local regulation is stricter, ensuring both global coherence and local compliance.
Question 36: A risk analyst discovers that a single supplier provides 80% of critical components. Which type of risk concentration is this an example of?
- Liquidity risk
- Concentration risk (Correct answer)
- Systemic risk
- Reputational risk
Correct answer: Concentration risk
Concentration risk arises when a large proportion of exposure is tied to a single entity, sector, or source, amplifying potential losses.
Question 37: A risk analyst identifies that a foreign government has a history of renegotiating contracts after elections. This most directly represents:
- Environmental transition risk
- Corruption and bribery risk
- Macro-financial risk
- Political interference and regulatory risk (Correct answer)
Correct answer: Political interference and regulatory risk
Governments unilaterally renegotiating contracts post-election reflects political interference and regulatory risk, where the enforceability of legal agreements depends on political continuity.
Question 38: Under the Foreign Corrupt Practices Act (FCPA), which of the following payments is an explicitly recognized exception to the anti-bribery provisions?
- Charitable donations made on behalf of a foreign official
- Payments to political parties in foreign countries
- Gifts to foreign officials to win contracts
- Facilitating payments to expedite routine government actions (Correct answer)
Correct answer: Facilitating payments to expedite routine government actions
The FCPA contains a narrow exception for 'facilitating payments' made to foreign officials to expedite or secure routine, non-discretionary governmental actions.
Question 39: Under the COSO ERM framework, which of the following is an example of a 'risk-taking' culture element that the board should monitor?
- An annual internal audit of the risk register
- Incentive compensation structures that reward excessive short-term risk-taking (Correct answer)
- A whistleblower hotline available to all employees
- Mandatory ethics training for all staff
Correct answer: Incentive compensation structures that reward excessive short-term risk-taking
Incentive structures that reward short-term risk-taking can undermine risk culture by creating pressure to exceed appetite for bonus purposes.
Question 40: In a corporate governance context, an 'independent director' is typically defined as one who:
- Has never worked in the financial services industry
- Has served on the board for more than 10 years
- Is not a shareholder of the company
- Has no material relationship with the company that could impair objectivity (Correct answer)
Correct answer: Has no material relationship with the company that could impair objectivity
Independence requires that a director have no material financial, personal, or professional relationships with the company that could compromise their objective judgment.
Question 41: What is the primary ethical obligation of a CRA professional when a conflict of interest arises during emerging & geopolitical risks activities?
- Disclose the conflict to all relevant parties and recuse from the decision if necessary (Correct answer)
- Resolve the conflict privately without informing stakeholders
- Proceed while favoring the outcome that benefits the professional personally
- Ignore the conflict if it does not directly affect the current task
Correct answer: Disclose the conflict to all relevant parties and recuse from the decision if necessary
The primary ethical obligation when a conflict of interest arises in emerging & geopolitical risks is to disclose it to all relevant parties and, if necessary, recuse from the decision. This maintains professional integrity and stakeholder trust.
Question 42: Which of the following is the BEST leading indicator of potential social unrest in an emerging market?
- A widening Gini coefficient alongside rising youth unemployment (Correct answer)
- An increase in a country's export diversification index
- A narrowing current account deficit due to import compression
- A declining central bank foreign exchange reserve ratio
Correct answer: A widening Gini coefficient alongside rising youth unemployment
Widening income inequality (Gini coefficient) combined with high youth unemployment is a classic predictor of social instability, as it creates a large, economically marginalized population with grievances.
Question 43: When conducting a geopolitical risk scenario analysis, which scenario type best captures the 'tail risk' of extreme geopolitical outcomes?
- Historical scenario replicating a past geopolitical crisis
- Optimistic scenario based on diplomatic resolution of tensions
- Stress scenario modeling a severe but plausible geopolitical disruption (Correct answer)
- Base case scenario reflecting the most probable political trajectory
Correct answer: Stress scenario modeling a severe but plausible geopolitical disruption
Stress scenarios model severe but plausible tail eventsβsuch as regional conflict escalation or major sanctionsβthat fall outside the base case but could have disproportionate impact on business operations.
Question 44: Which scenario represents a 'risk tolerance breach' rather than a 'risk appetite exceedance'?
- A new product's projected risk is above preferred levels
- A business unit's VaR exceeds its quarterly planning target
- Operational losses exceed the maximum threshold defined in policy (Correct answer)
- A risk score increases from 'low' to 'medium'
Correct answer: Operational losses exceed the maximum threshold defined in policy
Tolerance breaches occur when actual risk outcomes exceed defined maximum limits in policy, whereas appetite exceedance reflects going beyond preferred or target levels.
Question 45: Under expected utility theory, a risk-averse decision-maker will prefer a certain outcome over a gamble with the same expected value because:
- They assign higher probability to favorable outcomes
- Their utility function is linear in wealth
- Their marginal utility of wealth diminishes, so they value certainty more than the gamble's expected payoff (Correct answer)
- They use minimax regret to evaluate all alternatives
Correct answer: Their marginal utility of wealth diminishes, so they value certainty more than the gamble's expected payoff
Risk-averse individuals have concave utility functions where diminishing marginal utility means the disutility of losing exceeds the utility of an equivalent gain.
Question 46: A company negotiates a contractual indemnification clause with a vendor that shifts liability for data breaches to the vendor. This is BEST categorized as:
- Risk reduction
- Risk retention with a self-insurance fund
- Risk avoidance
- Contractual risk transfer (Correct answer)
Correct answer: Contractual risk transfer
Contractual indemnification shifts financial liability for specified losses to another party by legal agreement, which is a form of non-insurance contractual risk transfer.
Question 47: A bank's Monte Carlo model uses geometric Brownian motion (GBM) for equity prices. Which real-world feature does GBM fail to capture?
- Continuous price changes
- Random walk behavior
- Positive drift in equity prices
- Volatility clustering and fat tails (Correct answer)
Correct answer: Volatility clustering and fat tails
GBM assumes constant volatility and normally distributed returns, failing to capture the volatility clustering and heavy tails observed in actual market returns.
Question 48: Tone from the top in risk culture refers to:
- The volume of risk reports issued by senior management
- The technical training programs offered to risk analysts
- Senior leadership's visible commitment to ethical behavior and sound risk management (Correct answer)
- The regulatory requirements communicated to front-line staff
Correct answer: Senior leadership's visible commitment to ethical behavior and sound risk management
Tone from the top means that senior leadership's words and actions set the standard for the organization's risk culture and ethical behavior.
Question 49: What is the primary purpose of a Risk Management Information System (RMIS) in stakeholder communication?
- To automate the payment of insurance claims
- To replace human judgment in risk decisions
- To aggregate, store, and distribute risk data consistently across the organization for informed decision-making (Correct answer)
- To limit risk data access to senior management only
Correct answer: To aggregate, store, and distribute risk data consistently across the organization for informed decision-making
An RMIS centralizes risk data collection, analysis, and reporting, enabling timely and consistent risk information sharing across all organizational levels and stakeholders.
Question 50: The 'Three Lines of Defense' model assigns risk management responsibility in which structure?
- Board β CEO β Employees
- External Audit β Regulators β Senior Management
- Business Units β Risk/Compliance Functions β Internal Audit (Correct answer)
- Legal β Operations β Finance
Correct answer: Business Units β Risk/Compliance Functions β Internal Audit
The Three Lines of Defense model has business units (1st line) owning risk, risk and compliance functions (2nd line) providing oversight, and internal audit (3rd line) providing independent assurance.
Certified Risk Analyst (CRA)
The AIBM Certified Risk Analyst (CRA) credential validates expertise in risk analysis principles, assessment methodologies, and mitigation strategies. It covers regulatory compliance, decision support, and emerging trends across enterprise risk management frameworks.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong β answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds