CBA Risk Management Auditing 3 — Questions and Answers
Question 1: Which audit procedure best tests the effectiveness of a bank's third-party risk management program?
- Reviewing contracts for standard indemnification clauses
- Confirming that all vendors have completed onboarding paperwork
- Testing whether ongoing monitoring activities are performed and documented for critical vendors (Correct answer)
- Verifying that the procurement team approved all vendor selections
Correct answer: Testing whether ongoing monitoring activities are performed and documented for critical vendors
Effectiveness of third-party risk management is demonstrated through ongoing monitoring of critical vendors, not just initial onboarding.
Question 2: A bank's fraud risk assessment identifies wire transfer origination as high-risk. Which control is most effective at mitigating this risk?
- Requiring dual authorization and call-back verification for large wire transfers (Correct answer)
- Limiting wire transfer capabilities to branch managers only
- Printing wire transfer confirmations and filing them in physical folders
- Reviewing wire transfer logs monthly during reconciliation
Correct answer: Requiring dual authorization and call-back verification for large wire transfers
Dual authorization combined with out-of-band call-back verification is the most effective preventive control against fraudulent wire transfers.
Question 3: When auditing interest rate risk in the banking book (IRRBB), what does an EVE (Economic Value of Equity) measure capture?
- The bank's short-term earnings sensitivity to rate changes over the next 12 months
- The present value impact of rate shocks on the bank's entire balance sheet (Correct answer)
- The regulatory capital required under Pillar 1 for market risk
- The net interest income forecast for the current fiscal year
Correct answer: The present value impact of rate shocks on the bank's entire balance sheet
EVE measures the change in the economic value of all assets, liabilities, and off-balance-sheet items in response to interest rate shocks.
Question 4: An auditor discovers that the risk management function reports to the CFO. Under best practices, what concern should be raised?
- The CFO has insufficient financial expertise to oversee risk management
- Risk management reporting to the CFO impairs its independence from business line influence (Correct answer)
- Regulatory guidance prohibits CFO oversight of risk functions in all bank sizes
- The CFO's dual role increases the efficiency of risk-adjusted return calculations
Correct answer: Risk management reporting to the CFO impairs its independence from business line influence
Best practice and regulatory guidance call for the Chief Risk Officer to report independently to the CEO or board, not through a business-oriented function like the CFO.
Question 5: Which of the following is an example of a key risk indicator (KRI) for cybersecurity risk?
- Number of new customer accounts opened per month
- Percentage of systems with overdue critical patch deployments (Correct answer)
- Total IT department headcount relative to prior year
- Annual budget variance for the information security department
Correct answer: Percentage of systems with overdue critical patch deployments
The percentage of systems with unpatched critical vulnerabilities is a forward-looking KRI that signals elevated cyber risk before an incident occurs.
Question 6: In a bank's three lines of defense model, which party is responsible for owning and managing risks day to day?
- Internal audit
- The compliance department
- The board risk committee
- Business line management (first line) (Correct answer)
Correct answer: Business line management (first line)
The first line of defense—business line management—owns, manages, and is accountable for risks inherent in their operations.
Question 7: When stress testing a loan portfolio, a CBA candidate should understand that a 'severely adverse' scenario is designed to represent which condition?
- Expected losses under baseline economic projections
- A moderate recession consistent with a typical business cycle downturn
- A severe recession with unemployment reaching approximately 10% or higher (Correct answer)
- A gradual rate increase spread over five years
Correct answer: A severe recession with unemployment reaching approximately 10% or higher
The severely adverse scenario in Federal Reserve stress tests represents a deep recession with significant unemployment increases, typically 10% or more.
Which audit procedure best tests the effectiveness of a bank's third-party risk management program?