APRP Operational Risk Management 4 — Questions and Answers
Question 1: A payments processor experiences a surge in chargebacks due to a compromised merchant. Which operational risk control should be triggered FIRST?
- Suspend the merchant account pending investigation (Correct answer)
- Notify the card network and increase reserves
- Issue refunds to all affected cardholders immediately
- File a SAR with FinCEN
Correct answer: Suspend the merchant account pending investigation
Suspending the merchant account is the immediate containment action to stop further fraud exposure before escalating to networks or regulators.
Question 2: Under the Basel II operational risk framework, which loss event type category covers payment processing errors caused by system failures?
- External fraud
- Execution, delivery, and process management
- Business disruption and system failures (Correct answer)
- Clients, products, and business practices
Correct answer: Business disruption and system failures
Basel II classifies system outages and technology failures under 'Business Disruption and System Failures,' distinct from process errors.
Question 3: A payment firm's key risk indicator (KRI) for failed settlement transactions exceeds its threshold. What is the primary purpose of a KRI threshold breach?
- To trigger automatic transaction reversals
- To signal that a risk may be approaching unacceptable levels requiring management action (Correct answer)
- To report the incident to regulatory authorities immediately
- To calculate the firm's operational risk capital charge
Correct answer: To signal that a risk may be approaching unacceptable levels requiring management action
KRI thresholds serve as early-warning signals prompting management review and corrective action before losses materialize.
Question 4: Which method for calculating operational risk capital under Basel II/III uses a fixed percentage of gross income averaged over three years?
- Advanced Measurement Approach (AMA)
- Standardized Approach (TSA)
- Basic Indicator Approach (BIA) (Correct answer)
- Internal Models Approach (IMA)
Correct answer: Basic Indicator Approach (BIA)
The Basic Indicator Approach applies a 15% alpha factor to average positive annual gross income over the preceding three years.
Question 5: A payments company wants to transfer operational risk exposure for large-scale data breaches to a third party. The BEST mechanism to accomplish this is:
- Increasing internal controls and audit frequency
- Purchasing cyber liability insurance (Correct answer)
- Implementing two-factor authentication
- Outsourcing IT operations to a cloud provider
Correct answer: Purchasing cyber liability insurance
Cyber liability insurance is a risk transfer mechanism that shifts financial consequences of data breaches to an insurer.
Question 6: In a payments operational risk context, 'tail risk' BEST refers to:
- Risks that occur at the end of the business day during settlement
- Low-probability, high-severity loss events that fall in the extreme tail of a loss distribution (Correct answer)
- Residual risk remaining after controls are applied
- The final stage of the risk management lifecycle
Correct answer: Low-probability, high-severity loss events that fall in the extreme tail of a loss distribution
Tail risk describes rare but catastrophic events in the far end of a statistical loss distribution, such as a major system outage affecting billions in transactions.
Question 7: An APRP candidate reviewing a vendor contract notices the agreement lacks provisions for audit rights and incident notification timelines. This gap PRIMARILY creates which type of risk?
- Credit risk from vendor insolvency
- Third-party operational risk due to inadequate oversight controls (Correct answer)
- Market risk from vendor pricing changes
- Liquidity risk from delayed vendor payments
Correct answer: Third-party operational risk due to inadequate oversight controls
Missing audit rights and incident notification requirements are third-party operational risk gaps that reduce the firm's ability to monitor and respond to vendor failures.
A payments processor experiences a surge in chargebacks due to a compromised merchant.
Which operational risk control should be triggered FIRST?