โ† All CCB Flashcard Decks

Operational Risk & Control Testing Flashcards

7 cards from real CCB practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Operational Risk & Control Testing flashcards as text
  1. A third-party vendor that processes customer data experiences a data breach. Under operational risk frameworks, this event is best classified as:

    Answer: Third-party/vendor operational risk

    Risks arising from third-party service providers are classified as vendor or third-party operational risk, a recognized sub-category of operational risk.

  2. Which element is typically NOT included in an operational risk loss event report?

    Answer: Future market price forecasts

    Loss event reports capture historical operational failures; future market price forecasts are unrelated to documenting an operational loss event.

  3. A walkthrough of a cash reconciliation process reveals that the same employee both prepares and approves the reconciliation. This is an example of:

    Answer: A segregation of duties violation

    Having one person both prepare and approve a reconciliation violates the principle of segregation of duties, as no independent check exists.

  4. When testing controls over a financial reporting process, a compliance professional finds that the control operates 'as designed' but the underlying process still produces errors. What does this indicate?

    Answer: The control is designed effectively but may be insufficient for the risk

    A control can operate as designed yet still be insufficient if its design does not adequately address the risk, highlighting a design deficiency rather than an operating failure.

  5. Which of the following is the best indicator that an organization's operational risk culture is strong?

    Answer: Employees proactively report near misses without fear of punishment

    A strong risk culture is characterized by psychological safety and open reporting, where employees voluntarily disclose near misses to prevent future losses.

  6. A compliance team is evaluating the residual risk after controls are applied. Which formula correctly represents residual risk?

    Answer: Residual Risk = Inherent Risk - Control Effectiveness

    Residual risk equals inherent risk minus the risk reduction achieved through controls, representing the remaining exposure after mitigation.

  7. Under US federal guidance, financial institutions are expected to conduct operational risk stress testing primarily to:

    Answer: Assess the firm's ability to withstand severe operational disruptions and capital impacts

    Operational risk stress testing evaluates whether a firm has sufficient capital and resilience to absorb losses from severe but plausible operational disruptions.