CBA Auditing Risk Management 3 — Questions and Answers
Question 1: A bank's Three Lines of Defense model assigns internal audit to which line?
- First line
- Second line
- Third line (Correct answer)
- Fourth line
Correct answer: Third line
Internal audit represents the third line of defense, providing independent assurance over the effectiveness of the first and second lines.
Question 2: When evaluating a bank's operational risk event data collection process, an auditor should be most concerned if:
- Near-miss events are captured alongside actual loss events
- Loss event thresholds below $10,000 are excluded from reporting
- Business lines self-report loss events with no independent validation (Correct answer)
- Risk categories follow Basel II event type classifications
Correct answer: Business lines self-report loss events with no independent validation
Self-reporting without independent validation creates a significant integrity risk, as business lines may under-report or misclassify operational losses.
Question 3: Which metric is most appropriate for measuring a bank's exposure to interest rate risk in the banking book (IRRBB)?
- Net Interest Margin (NIM) sensitivity and Economic Value of Equity (EVE) (Correct answer)
- Loan-to-Deposit Ratio
- Return on Risk-Adjusted Capital (RORAC)
- Tier 1 Capital Ratio
Correct answer: Net Interest Margin (NIM) sensitivity and Economic Value of Equity (EVE)
NIM sensitivity measures income impact while EVE measures the present value impact of rate changes, making them the primary IRRBB metrics.
Question 4: An auditor notices that a bank's Risk and Control Self-Assessment (RCSA) scores have been consistently 'low risk' for three consecutive years with no significant changes. The most appropriate audit response is to:
- Accept the RCSA results as evidence of effective controls
- Test the RCSA process for completeness, challenge assumptions, and validate against loss event data (Correct answer)
- Recommend the RCSA be performed annually instead of quarterly
- Escalate to regulators immediately
Correct answer: Test the RCSA process for completeness, challenge assumptions, and validate against loss event data
Consistently favorable RCSA results without changes may indicate assessment complacency; auditors should validate results against actual loss data and challenge the methodology.
Question 5: Under the Dodd-Frank Act, bank holding companies with total consolidated assets of $50 billion or more are required to submit annual capital plans to which regulator?
- FDIC
- OCC
- Federal Reserve (Correct answer)
- CFPB
Correct answer: Federal Reserve
The Federal Reserve administers the Comprehensive Capital Analysis and Review (CCAR) process, requiring large BHCs to submit annual capital plans.
Question 6: When auditing a bank's model risk management framework, which of the following represents a key validation requirement for a credit scoring model?
- The model must be developed by an independent third party
- The model must be validated by a team independent of model development, including conceptual soundness review (Correct answer)
- Validation must occur only at initial model implementation
- Model documentation is optional if performance metrics are strong
Correct answer: The model must be validated by a team independent of model development, including conceptual soundness review
SR 11-7 guidance requires model validation to be performed by staff independent of development, including conceptual soundness, outcome analysis, and ongoing monitoring.
Question 7: A bank experiences a significant increase in its non-performing loan (NPL) ratio. From a risk management audit perspective, which control failure is most likely indicated?
- Inadequate customer onboarding procedures
- Weaknesses in credit underwriting standards or early warning indicator systems (Correct answer)
- Insufficient marketing budget for loan products
- Poor treasury cash management practices
Correct answer: Weaknesses in credit underwriting standards or early warning indicator systems
Rising NPL ratios typically signal breakdowns in credit underwriting quality or failures in early warning systems that should identify deteriorating credits before default.
A bank's Three Lines of Defense model assigns internal audit to which line?