Operational Risk Management Flashcards
6 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Operational Risk Management flashcards as text
Which of the following best defines operational risk in the context of payment processing?
Answer: Risk of loss from inadequate internal processes, people, systems, or external events
Operational risk in payments is the risk of loss resulting from inadequate or failed internal processes, people, and systems, or from external events.
A payment processor experiences repeated transaction failures due to an undocumented manual workaround used by staff. Which operational risk category does this represent?
Answer: Process failure
Undocumented manual workarounds represent a process failure risk, as the lack of formal procedures creates inconsistency and potential for error.
What is the primary purpose of a Business Continuity Plan (BCP) for a payment organization?
Answer: To ensure critical payment operations can continue during and after a disruptive event
A BCP ensures that critical payment operations can be maintained or quickly restored during and after a disruptive event such as a system failure or natural disaster.
Which metric is used to describe the maximum acceptable amount of time a payment system can be offline before causing serious business impact?
Answer: Recovery Time Objective (RTO)
Recovery Time Objective (RTO) defines the maximum acceptable downtime before resuming normal operations after a disruption.
An APRP candidate is reviewing a risk register for a card payment network. What is the purpose of documenting residual risk?
Answer: To show the risk remaining after controls have been applied
Residual risk is the level of risk that remains after existing controls and mitigations have been applied to the inherent risk.
Which of the following is an example of a key risk indicator (KRI) specifically relevant to payment operations?
Answer: Number of failed authentication attempts per day
The number of failed authentication attempts per day is a KRI because it provides an early warning signal of potential fraud or system abuse in payment operations.