← All APRP Flashcard Decks

Operational Risk Management Flashcards

7 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Operational Risk Management flashcards as text
  1. A payments institution conducts a Business Impact Analysis (BIA) as part of its business continuity planning. What is the PRIMARY output of a BIA?

    Answer: A ranked list of critical business functions and their maximum tolerable downtime

    A BIA identifies critical business functions, dependencies, and the maximum tolerable period of disruption (MTPD) to prioritize recovery efforts.

  2. Which risk response strategy is being used when a payment company decides to accept a low-probability operational risk because the cost of controls exceeds the expected loss?

    Answer: Risk acceptance

    Risk acceptance is the deliberate decision to retain a risk when its cost of mitigation outweighs the potential loss impact.

  3. A payment processor implements a 'four-eyes' approval policy requiring two authorized personnel to approve large wire transfers. This control BEST addresses which operational risk category?

    Answer: Internal fraud and unauthorized transactions

    Four-eyes controls are designed to prevent unauthorized or fraudulent internal transactions by requiring dual authorization.

  4. Under the NIST Cybersecurity Framework, which function focuses on developing organizational understanding to manage cybersecurity risk to systems and assets?

    Answer: Identify

    The 'Identify' function establishes the foundation for cybersecurity risk management by understanding assets, risks, and governance contexts.

  5. A risk manager is calculating the Annualized Loss Expectancy (ALE) for a payment system outage. If the Single Loss Expectancy (SLE) is $500,000 and the outage is expected to occur twice per year, the ALE is:

    Answer: $1,000,000

    ALE = SLE × Annual Rate of Occurrence (ARO); $500,000 × 2 = $1,000,000.

  6. During an operational risk assessment, a payments firm discovers that its recovery time objective (RTO) for core transaction processing is 4 hours, but its current recovery capability is 12 hours. This gap represents:

    Answer: A business continuity planning deficiency that must be remediated

    When actual recovery capability exceeds the RTO, the firm has a business continuity planning gap that needs investment or process improvements.

  7. Which of the following BEST describes the role of a Risk Control Self-Assessment (RCSA) in a payments organization?

    Answer: An internal process where business units identify, assess, and document their own risks and controls

    An RCSA is a structured internal process that empowers business lines to proactively identify operational risks and evaluate the adequacy of existing controls.