APRP Risk Assessment & Mitigation 4 — Questions and Answers
Question 1: A payments organization wants to reduce inherent credit risk from merchants without exiting the relationship. Which mitigation tool is MOST directly targeted at this goal?
- Increasing transaction processing fees
- Establishing a rolling reserve funded from merchant settlement proceeds (Correct answer)
- Requiring merchants to use tokenization
- Enhancing fraud detection models
Correct answer: Establishing a rolling reserve funded from merchant settlement proceeds
A rolling reserve withholds a percentage of merchant proceeds to create a buffer that covers potential chargebacks or losses without terminating the relationship.
Question 2: In the NIST Cybersecurity Framework, which function focuses on developing and implementing activities to limit or contain the impact of a cybersecurity event?
- Identify
- Protect
- Respond (Correct answer)
- Recover
Correct answer: Respond
The 'Respond' function in the NIST CSF covers activities to contain the impact of an incident, including response planning, communications, and mitigation.
Question 3: Which card brand program places merchants at risk of fines and additional scrutiny when they persistently exceed dispute ratio thresholds?
- The Visa Merchant Purchase Inquiry (VMPI) program
- The Visa Dispute Monitoring Program (VDMP) and Mastercard Excessive Chargeback Program (ECP) (Correct answer)
- The Mastercard SecureCode program
- The Visa Verified by Visa enrollment program
Correct answer: The Visa Dispute Monitoring Program (VDMP) and Mastercard Excessive Chargeback Program (ECP)
VDMP (Visa) and ECP (Mastercard) impose graduated fines and may lead to merchant disqualification when chargeback thresholds are repeatedly breached.
Question 4: What is the primary purpose of scenario analysis in operational risk assessment for a payments firm?
- To backtest fraud models against historical transaction data
- To estimate potential losses from severe but plausible events not captured in historical loss data (Correct answer)
- To benchmark processing fees against competitor pricing
- To evaluate compliance with card brand operating rules
Correct answer: To estimate potential losses from severe but plausible events not captured in historical loss data
Scenario analysis helps organizations estimate the potential impact of rare, high-severity events (e.g., major cyberattack) for which historical loss data may be insufficient.
Question 5: A financial institution identifies that a payment gateway vendor's contract lacks a right-to-audit clause. This gap creates PRIMARILY which type of risk?
- Liquidity risk
- Third-party/vendor risk with compliance and oversight implications (Correct answer)
- Interest rate risk
- Settlement finality risk
Correct answer: Third-party/vendor risk with compliance and oversight implications
Without a right-to-audit clause, the institution cannot independently verify the vendor's controls, creating blind spots in third-party risk management and potential regulatory exposure.
Question 6: Which technique involves systematically identifying all the ways a process could fail and then prioritizing those failures by severity and detectability?
- Root cause analysis (RCA)
- Failure Mode and Effects Analysis (FMEA) (Correct answer)
- Monte Carlo simulation
- Fault tree analysis
Correct answer: Failure Mode and Effects Analysis (FMEA)
FMEA evaluates each potential failure mode, rates its severity, occurrence probability, and detectability to calculate a Risk Priority Number (RPN) for prioritization.
Question 7: For a US payments organization, which regulatory body has primary supervisory authority over unfair, deceptive, or abusive acts or practices (UDAAP) in consumer financial products?
- The Federal Reserve Board
- The Consumer Financial Protection Bureau (CFPB) (Correct answer)
- The Office of the Comptroller of the Currency (OCC)
- The Financial Crimes Enforcement Network (FinCEN)
Correct answer: The Consumer Financial Protection Bureau (CFPB)
The CFPB holds primary UDAAP authority over most consumer financial products and services under the Dodd-Frank Act.
A payments organization wants to reduce inherent credit risk from merchants without exiting the relationship.
Which mitigation tool is MOST directly targeted at this goal?