Froggy Jumps
Risk Discovery Quest: Data & Model Risk Assessment EditionOnline version
Data & Model risk assessment
1
Before identifying any data or model risk, what must be clearly defined?
2
Why does the Job Aid require completing all context fields first?
3
Which of the following is a required early decision in the template?
4
Which question best helps uncover upstream and downstream data risk?
5
A stakeholder says ‘we’ve always used this data.’ What is the BEST next question?
6
Which question MOST directly addresses data quality risk?
7
Which question helps identify hidden risk in AI or model-driven solutions?
8
When should ‘No Expected Risk’ be selected in the template?
9
If uncertainty exists about data transformations, the correct action is to:
10
ISO 27001 supports which two types of risk assessment?
11
Inherent risk represents:
12
Residual risk represents:
13
Why does the Job Aid emphasize scoring residual risk as “future state”?
14
Which control characteristic typically lowers residual risk most effectively?
15
Strong risk statements should always include:
16
Once a risk is identified and scored, what must happen next?
17
Why does ISO 27001 describe the risk register as a “living document”?
18
SOC 2 focuses on which five trust services criteria?
19
Which regulatory concept is described as ensuring consistency of security controls across supplier networks?
20
What is the main purpose of Dora in the EU framework?
21
A model performs well today, but data inputs are changing rapidly. What risk should be explored next?
22
Which question best connects risk identification to real business impact?
23
Which question best tests whether controls are actually operating, not just designed?
24
When should a risk be escalated beyond the immediate assessment group?
|