Risk Assessment & Mitigation Flashcards
7 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Assessment & Mitigation flashcards as text
A payments firm's risk appetite statement specifies a maximum tolerable fraud loss rate of 0.05% of gross payment volume. What is the BEST use of this threshold?
Answer: To define trigger points for escalating fraud control decisions to senior management
Risk appetite thresholds serve as governance escalation triggers — when actual metrics approach or exceed them, decisions are elevated to appropriate leadership.
Which of the following BEST describes 'concentration risk' in a merchant portfolio?
Answer: Excessive exposure to a single merchant, industry, or geography that could cause outsized losses
Concentration risk occurs when a portfolio is heavily weighted toward a single entity, sector, or region, so problems in that segment cause disproportionate harm.
Under a risk-based AML program, what is the primary factor that determines the level of customer due diligence (CDD) applied to a new merchant?
Answer: The overall risk profile of the merchant based on business type, geography, and expected transaction patterns
Risk-based CDD calibrates the depth of due diligence to the customer's composite risk profile, applying enhanced measures where risk indicators are elevated.
When a payments organization conducts a 'gap analysis' against PCI DSS requirements, it is performing which step of the risk management lifecycle?
Answer: Risk identification and assessment
A gap analysis compares current controls against required standards to identify deficiencies, which is a risk identification and assessment activity.
In payments fraud risk, which model performance metric indicates the percentage of actual fraud cases correctly identified by a detection system?
Answer: Recall (sensitivity)
Recall measures what fraction of actual fraudulent transactions the model successfully catches, directly reflecting how well the system identifies true fraud.
Which risk mitigation approach is most appropriate when a risk's probability and impact are both very low?
Answer: Accept the risk and monitor it periodically
Low-probability, low-impact risks are typically accepted because the cost of controls or insurance would exceed the expected value of the loss.
A payments processor implements dual authorization controls for wire transfers above $100,000. This is an example of which risk mitigation principle?
Answer: Separation of duties / dual control
Dual authorization (dual control) requires two independent approvals for high-value transactions, reducing the risk of unauthorized transfers through separation of duties.