APRP Risk Assessment & Mitigation 5 — Questions and Answers
Question 1: A payments firm's risk appetite statement specifies a maximum tolerable fraud loss rate of 0.05% of gross payment volume. What is the BEST use of this threshold?
- To set bonuses for the fraud operations team
- To define trigger points for escalating fraud control decisions to senior management (Correct answer)
- To determine PCI DSS scope boundaries
- To calculate reserve requirements for merchant credit risk
Correct answer: To define trigger points for escalating fraud control decisions to senior management
Risk appetite thresholds serve as governance escalation triggers — when actual metrics approach or exceed them, decisions are elevated to appropriate leadership.
Question 2: Which of the following BEST describes 'concentration risk' in a merchant portfolio?
- Risk arising from processing transactions in multiple currencies
- Excessive exposure to a single merchant, industry, or geography that could cause outsized losses (Correct answer)
- Risk that a high concentration of legitimate transactions will mask fraudulent ones
- The risk of insufficient transaction volume to cover fixed processing costs
Correct answer: Excessive exposure to a single merchant, industry, or geography that could cause outsized losses
Concentration risk occurs when a portfolio is heavily weighted toward a single entity, sector, or region, so problems in that segment cause disproportionate harm.
Question 3: Under a risk-based AML program, what is the primary factor that determines the level of customer due diligence (CDD) applied to a new merchant?
- The merchant's average ticket size only
- The overall risk profile of the merchant based on business type, geography, and expected transaction patterns (Correct answer)
- Whether the merchant accepts American Express cards
- The merchant's years in business
Correct answer: The overall risk profile of the merchant based on business type, geography, and expected transaction patterns
Risk-based CDD calibrates the depth of due diligence to the customer's composite risk profile, applying enhanced measures where risk indicators are elevated.
Question 4: When a payments organization conducts a 'gap analysis' against PCI DSS requirements, it is performing which step of the risk management lifecycle?
- Risk response/mitigation
- Risk identification and assessment (Correct answer)
- Risk monitoring and reporting
- Risk appetite setting
Correct answer: Risk identification and assessment
A gap analysis compares current controls against required standards to identify deficiencies, which is a risk identification and assessment activity.
Question 5: In payments fraud risk, which model performance metric indicates the percentage of actual fraud cases correctly identified by a detection system?
- Precision
- Recall (sensitivity) (Correct answer)
- Specificity
- False positive rate
Correct answer: Recall (sensitivity)
Recall measures what fraction of actual fraudulent transactions the model successfully catches, directly reflecting how well the system identifies true fraud.
Question 6: Which risk mitigation approach is most appropriate when a risk's probability and impact are both very low?
- Transfer the risk through insurance
- Implement extensive preventive controls
- Accept the risk and monitor it periodically (Correct answer)
- Avoid the activity that generates the risk
Correct answer: Accept the risk and monitor it periodically
Low-probability, low-impact risks are typically accepted because the cost of controls or insurance would exceed the expected value of the loss.
Question 7: A payments processor implements dual authorization controls for wire transfers above $100,000. This is an example of which risk mitigation principle?
- Risk avoidance
- Separation of duties / dual control (Correct answer)
- Risk transfer
- Risk quantification
Correct answer: Separation of duties / dual control
Dual authorization (dual control) requires two independent approvals for high-value transactions, reducing the risk of unauthorized transfers through separation of duties.
A payments firm's risk appetite statement specifies a maximum tolerable fraud loss rate of 0.05% of gross payment volume.
What is the BEST use of this threshold?