Operational Risk & Control Testing Flashcards
7 cards from real CCB practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Operational Risk & Control Testing flashcards as text
Under the Basel III operational risk framework, which approach requires banks to calculate a business indicator component multiplied by internal loss multiplier?
Answer: Standardized Measurement Approach (SMA)
The Standardized Measurement Approach (SMA), introduced under Basel III final rules, uses the business indicator component combined with an internal loss multiplier based on historical losses.
A compliance officer is designing a test plan for a new automated transaction monitoring system. Which testing type should be performed first?
Answer: Unit testing of individual rule components
Unit testing of individual components should occur first to ensure each rule or algorithm works correctly before integrated or user acceptance testing begins.
What is the primary difference between a risk register and a risk heat map?
Answer: A risk register lists risks while a heat map visually plots risks by likelihood and impact
A risk register is a detailed list of identified risks with attributes, while a heat map provides a visual summary by mapping risks on a likelihood-versus-impact grid.
During a control gap analysis, a compliance team discovers a preventive control is missing for a high-risk process. What type of control could serve as an interim measure?
Answer: Detective control
A detective control can serve as an interim measure by identifying when the unmitigated risk event occurs, even though it does not prevent the event.
Which metric is most useful for measuring the effectiveness of a segregation of duties (SoD) control over time?
Answer: Percentage of transactions processed by a single individual without review
Tracking the percentage of transactions processed without a second reviewer directly measures whether the SoD control is being consistently applied.
A firm's operational risk appetite statement specifies a maximum tolerance of $500,000 in annual fraud losses. Actual fraud losses total $480,000. What is the appropriate response?
Answer: Review controls and escalate as losses are near the threshold
Losses approaching but not yet breaching the threshold indicate control weaknesses that should be investigated and escalated before the limit is exceeded.
In operational risk management, what is a 'scenario analysis' primarily used for?
Answer: Estimating potential losses from low-frequency, high-severity events not captured in historical data
Scenario analysis helps organizations estimate potential losses from rare but severe events by using expert judgment since historical data is insufficient for such events.