โ† All CRA Flashcard Decks

Risk Identification & Assessment Flashcards

7 cards from real CRA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Identification & Assessment flashcards as text
  1. A risk architect is assessing supply chain risk and uses a technique that traces each material back to its origin through every tier of suppliers. Which technique is this?

    Answer: Multi-tier Supply Chain Mapping

    Multi-tier supply chain mapping traces materials and dependencies through all supplier tiers to identify hidden concentration, geographic, or geopolitical risks.

  2. In risk assessment, what does 'loss given default' (LGD) measure in credit risk?

    Answer: The proportion of the exposure amount that is lost if a default occurs

    LGD measures the fraction of the credit exposure that will not be recovered after a borrower defaults, net of any collateral or recovery proceeds.

  3. Which of the following is a limitation of using historical data alone for risk identification and assessment?

    Answer: Past events may not capture novel or unprecedented risks that have never occurred before

    Historical data cannot identify risks for which there is no precedent, such as entirely new technologies, black swan events, or novel threat actors.

  4. A risk architect identifies that the IT department's estimate of system downtime risk contradicts the operations team's estimate for the same risk. Which step should the architect take first?

    Answer: Facilitate a structured workshop to reconcile differing perspectives and validate assumptions

    Conflicting estimates reflect different assumptions and perspectives; a structured workshop aligns stakeholders, surfaces hidden context, and produces a more accurate shared estimate.

  5. Which risk metric expresses the expected loss that will not be exceeded at a given confidence level over a specified time horizon?

    Answer: Value at Risk (VaR)

    Value at Risk (VaR) quantifies the maximum loss not expected to be exceeded at a specified confidence level (e.g., 99%) over a defined time period.

  6. When conducting a risk assessment for a new business initiative, at which point in the project lifecycle should risk identification ideally begin?

    Answer: During the planning or initiation phase before significant commitments are made

    Risk identification should begin during planning or initiation when options are still open and the cost of adjusting the initiative to address risks is lowest.

  7. What distinguishes 'risk interconnectedness' from evaluating risks in isolation, and why does it matter for a Risk Architect?

    Answer: Risks can amplify each other when they co-occur, so treating them in isolation underestimates aggregate exposure

    Interconnected risks can compound and amplify each other, meaning the aggregate exposure is often greater than the sum of individual risk assessments evaluated separately.