APRP Operational Risk Management 2 — Questions and Answers
Question 1: In payment risk management, what does a 'four-eyes principle' control primarily prevent?
- System downtime during batch processing
- Unauthorized or erroneous actions by a single individual (Correct answer)
- Data breaches originating from external hackers
- Delays in cross-border payment settlement
Correct answer: Unauthorized or erroneous actions by a single individual
The four-eyes principle requires that at least two people must authorize or review a significant action, reducing the risk of error or unauthorized activity by any single individual.
Question 2: A payment firm identifies that a key third-party processor has no documented disaster recovery plan. What risk management action should be taken first?
- Immediately terminate the contract with the processor
- Issue a formal finding and require the vendor to remediate within a defined timeframe (Correct answer)
- Accept the risk without further action since it is a vendor issue
- Notify the card networks and request a waiver
Correct answer: Issue a formal finding and require the vendor to remediate within a defined timeframe
The appropriate first action is to document the finding, communicate it to the vendor, and require remediation within an agreed timeframe as part of vendor risk management.
Question 3: What is the main goal of scenario analysis in payment operational risk management?
- To calculate exact financial losses from past incidents
- To estimate the impact of rare but high-severity events that may not be captured in historical data (Correct answer)
- To replace quantitative risk models with qualitative assessments
- To automate fraud detection algorithms
Correct answer: To estimate the impact of rare but high-severity events that may not be captured in historical data
Scenario analysis helps organizations estimate the potential impact of rare, severe operational risk events that historical loss data may not adequately represent.
Question 4: Which of the following best describes 'concentration risk' in payment operations?
- Risk from holding too many payment fraud cases in a single queue
- Risk from over-reliance on a single vendor, geography, or technology for critical payment functions (Correct answer)
- Risk that a payment message is duplicated during transmission
- Risk from employee turnover in the payments compliance team
Correct answer: Risk from over-reliance on a single vendor, geography, or technology for critical payment functions
Concentration risk arises when an organization is overly dependent on a single vendor, region, or technology, making it vulnerable if that single source fails.
Question 5: An organization's operational loss data shows a spike in internal processing errors following a core system upgrade. What is the most appropriate operational risk response?
- Accept the losses as a normal cost of the upgrade
- Conduct a root cause analysis and implement corrective controls (Correct answer)
- Transfer the risk entirely to the system vendor
- Avoid future system upgrades to prevent recurrence
Correct answer: Conduct a root cause analysis and implement corrective controls
A root cause analysis identifies what went wrong during the upgrade, enabling targeted corrective controls to prevent recurrence.
Question 6: Under the Basel framework, which approach allows banks to calculate operational risk capital using their own internal loss data models?
- Basic Indicator Approach (BIA)
- Standardized Approach (SA)
- Advanced Measurement Approach (AMA) (Correct answer)
- Internal Ratings-Based (IRB) Approach
Correct answer: Advanced Measurement Approach (AMA)
The Advanced Measurement Approach (AMA) allows qualifying banks to use their own internal models and historical loss data to calculate operational risk capital requirements.
In payment risk management, what does a 'four-eyes principle' control primarily prevent?