← All CRA Flashcard Decks

Risk Mitigation and Controls Flashcards

7 cards from real CRA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Mitigation and Controls flashcards as text
  1. Under ISO 31000, the process of monitoring and reviewing risks and controls is important because:

    Answer: Risks and the effectiveness of controls change over time

    ISO 31000 emphasizes that risk monitoring and review is ongoing because both the risk environment and control performance evolve, requiring continuous assessment.

  2. A risk architect is designing controls for a high-impact, low-likelihood risk. Which approach is most appropriate?

    Answer: Implement cost-effective preventive and contingency controls focused on impact reduction

    For high-impact, low-likelihood risks, the focus should be on cost-effective controls that reduce impact (contingency planning) and prevent the event where feasible.

  3. Which of the following best describes a Key Control Indicator (KCI)?

    Answer: A metric that signals whether a control is performing as designed

    A KCI measures the performance and health of a specific control, indicating whether it is functioning effectively and as intended.

  4. In a three lines of defense model, which line is responsible for designing and implementing risk controls?

    Answer: First line (Business operations)

    The first line of defense — business operations — owns and implements day-to-day controls as part of their operational responsibilities.

  5. A financial institution applies stress testing to its credit portfolio. This is primarily used to:

    Answer: Assess potential losses under severe but plausible adverse scenarios

    Stress testing quantifies potential losses under extreme scenarios, helping institutions understand vulnerabilities and determine whether capital buffers and controls are adequate.

  6. When a control is described as 'automated,' what key advantage does it offer over a manual control?

    Answer: It applies consistently without human error or override

    Automated controls execute consistently every time the trigger condition is met, eliminating variability and the risk of human error or intentional bypass.

  7. An organization's risk treatment plan includes both preventive and corrective actions for the same risk. This layered approach is known as:

    Answer: Defense in depth

    Defense in depth applies multiple layers of controls so that if one control fails, others remain in place to detect, prevent, or correct the risk event.