APRP Operational Risk Management 5 — Questions and Answers
Question 1: A payments institution conducts a Business Impact Analysis (BIA) as part of its business continuity planning. What is the PRIMARY output of a BIA?
- A ranked list of critical business functions and their maximum tolerable downtime (Correct answer)
- A detailed IT disaster recovery runbook
- A regulatory compliance checklist for operational resilience
- A financial model for insurance premium calculations
Correct answer: A ranked list of critical business functions and their maximum tolerable downtime
A BIA identifies critical business functions, dependencies, and the maximum tolerable period of disruption (MTPD) to prioritize recovery efforts.
Question 2: Which risk response strategy is being used when a payment company decides to accept a low-probability operational risk because the cost of controls exceeds the expected loss?
- Risk avoidance
- Risk mitigation
- Risk acceptance (Correct answer)
- Risk transfer
Correct answer: Risk acceptance
Risk acceptance is the deliberate decision to retain a risk when its cost of mitigation outweighs the potential loss impact.
Question 3: A payment processor implements a 'four-eyes' approval policy requiring two authorized personnel to approve large wire transfers. This control BEST addresses which operational risk category?
- External fraud
- Internal fraud and unauthorized transactions (Correct answer)
- System failures
- Natural disasters
Correct answer: Internal fraud and unauthorized transactions
Four-eyes controls are designed to prevent unauthorized or fraudulent internal transactions by requiring dual authorization.
Question 4: Under the NIST Cybersecurity Framework, which function focuses on developing organizational understanding to manage cybersecurity risk to systems and assets?
- Protect
- Detect
- Identify (Correct answer)
- Respond
Correct answer: Identify
The 'Identify' function establishes the foundation for cybersecurity risk management by understanding assets, risks, and governance contexts.
Question 5: A risk manager is calculating the Annualized Loss Expectancy (ALE) for a payment system outage. If the Single Loss Expectancy (SLE) is $500,000 and the outage is expected to occur twice per year, the ALE is:
- $250,000
- $500,000
- $1,000,000 (Correct answer)
- $1,500,000
Correct answer: $1,000,000
ALE = SLE × Annual Rate of Occurrence (ARO); $500,000 × 2 = $1,000,000.
Question 6: During an operational risk assessment, a payments firm discovers that its recovery time objective (RTO) for core transaction processing is 4 hours, but its current recovery capability is 12 hours. This gap represents:
- A key risk indicator breach requiring immediate escalation
- A business continuity planning deficiency that must be remediated (Correct answer)
- A regulatory capital adequacy shortfall
- An acceptable residual risk within tolerance
Correct answer: A business continuity planning deficiency that must be remediated
When actual recovery capability exceeds the RTO, the firm has a business continuity planning gap that needs investment or process improvements.
Question 7: Which of the following BEST describes the role of a Risk Control Self-Assessment (RCSA) in a payments organization?
- An external audit procedure performed by regulators to assess compliance
- An internal process where business units identify, assess, and document their own risks and controls (Correct answer)
- A statistical model used to calculate operational risk capital requirements
- A vendor assessment tool to evaluate third-party risk exposure
Correct answer: An internal process where business units identify, assess, and document their own risks and controls
An RCSA is a structured internal process that empowers business lines to proactively identify operational risks and evaluate the adequacy of existing controls.
A payments institution conducts a Business Impact Analysis (BIA) as part of its business continuity planning.
What is the PRIMARY output of a BIA?