CCB Operational Risk & Control Testing 2 — Questions and Answers
Question 1: A compliance officer discovers that a control test was performed using a sample size of 5 out of 10,000 transactions. What is the primary concern?
- The test was too expensive
- The sample size is insufficient for statistical reliability (Correct answer)
- The test was performed by the wrong department
- The transactions were from the wrong time period
Correct answer: The sample size is insufficient for statistical reliability
A sample of 5 from 10,000 transactions is statistically too small to draw reliable conclusions about the effectiveness of the control.
Question 2: Which control testing approach involves reviewing documentation, logs, and records without directly observing the process?
- Walkthrough testing
- Inquiry testing
- Inspection testing (Correct answer)
- Re-performance testing
Correct answer: Inspection testing
Inspection testing involves examining documents, records, and reports to verify that a control exists and has been applied.
Question 3: A company's key risk indicator (KRI) for trade error rates exceeds its threshold for three consecutive months. What should the compliance team do first?
- Ignore it until the annual review
- Escalate to the board immediately without investigation
- Conduct a root cause analysis to identify the underlying issue (Correct answer)
- Terminate the employees responsible for the errors
Correct answer: Conduct a root cause analysis to identify the underlying issue
A persistent KRI breach requires a root cause analysis to understand why the control is failing before any corrective action is taken.
Question 4: In the context of operational risk, what does a 'near miss' event represent?
- A loss that exceeded the risk appetite threshold
- An event that could have caused a loss but did not (Correct answer)
- A control that was not tested during the period
- A regulatory fine that was narrowly avoided through negotiation
Correct answer: An event that could have caused a loss but did not
A near miss is an event where a loss was averted, often through luck or a compensating control, and it signals a real underlying risk.
Question 5: Which of the following best describes a 'compensating control'?
- A control that pays employees for identifying risks
- An alternative control that mitigates risk when the primary control is absent or weak (Correct answer)
- A control that automatically adjusts transaction limits
- A regulatory requirement that compensates for industry losses
Correct answer: An alternative control that mitigates risk when the primary control is absent or weak
A compensating control is a secondary safeguard designed to reduce risk when a primary control cannot be fully implemented.
Question 6: An operational risk assessment reveals that a critical process relies on a single employee with no backup. This is best categorized as which type of risk?
- Credit risk
- Key person risk (a form of operational risk) (Correct answer)
- Market risk
- Liquidity risk
Correct answer: Key person risk (a form of operational risk)
Dependence on a single person without succession planning is a key person risk, which falls under operational risk related to human resources.
Question 7: What is the purpose of a control self-assessment (CSA)?
- To allow external auditors to test controls independently
- To enable business units to evaluate the effectiveness of their own controls (Correct answer)
- To replace the need for an internal audit function
- To document regulatory requirements for submission to regulators
Correct answer: To enable business units to evaluate the effectiveness of their own controls
A CSA is a process by which management and staff identify and evaluate risks and controls within their own business units.
A compliance officer discovers that a control test was performed using a sample size of 5 out of 10,000 transactions.
What is the primary concern?