CCB Operational Risk & Control Testing 3 β Questions and Answers
Question 1: Under the Basel III operational risk framework, which approach requires banks to calculate a business indicator component multiplied by internal loss multiplier?
- Basic Indicator Approach (BIA)
- Standardized Approach (TSA)
- Standardized Measurement Approach (SMA) (Correct answer)
- Advanced Measurement Approach (AMA)
Correct answer: Standardized Measurement Approach (SMA)
The Standardized Measurement Approach (SMA), introduced under Basel III final rules, uses the business indicator component combined with an internal loss multiplier based on historical losses.
Question 2: A compliance officer is designing a test plan for a new automated transaction monitoring system. Which testing type should be performed first?
- Regression testing
- User acceptance testing
- Unit testing of individual rule components (Correct answer)
- Penetration testing
Correct answer: Unit testing of individual rule components
Unit testing of individual components should occur first to ensure each rule or algorithm works correctly before integrated or user acceptance testing begins.
Question 3: What is the primary difference between a risk register and a risk heat map?
- A risk register lists risks while a heat map visually plots risks by likelihood and impact (Correct answer)
- A risk register is used by regulators while a heat map is used internally
- A risk register covers only financial risks while a heat map covers all risk types
- A risk register is a real-time tool while a heat map is historical
Correct answer: A risk register lists risks while a heat map visually plots risks by likelihood and impact
A risk register is a detailed list of identified risks with attributes, while a heat map provides a visual summary by mapping risks on a likelihood-versus-impact grid.
Question 4: During a control gap analysis, a compliance team discovers a preventive control is missing for a high-risk process. What type of control could serve as an interim measure?
- Directive control
- Detective control (Correct answer)
- Preventive control from another department
- No interim measure is needed
Correct answer: Detective control
A detective control can serve as an interim measure by identifying when the unmitigated risk event occurs, even though it does not prevent the event.
Question 5: Which metric is most useful for measuring the effectiveness of a segregation of duties (SoD) control over time?
- Number of employees trained on the policy
- Percentage of transactions processed by a single individual without review (Correct answer)
- Total volume of transactions processed per month
- Number of policies updated annually
Correct answer: Percentage of transactions processed by a single individual without review
Tracking the percentage of transactions processed without a second reviewer directly measures whether the SoD control is being consistently applied.
Question 6: A firm's operational risk appetite statement specifies a maximum tolerance of $500,000 in annual fraud losses. Actual fraud losses total $480,000. What is the appropriate response?
- No action required since the threshold was not breached
- Increase the risk appetite threshold to $600,000
- Review controls and escalate as losses are near the threshold (Correct answer)
- Report the breach to regulators immediately
Correct answer: Review controls and escalate as losses are near the threshold
Losses approaching but not yet breaching the threshold indicate control weaknesses that should be investigated and escalated before the limit is exceeded.
Question 7: In operational risk management, what is a 'scenario analysis' primarily used for?
- Estimating potential losses from low-frequency, high-severity events not captured in historical data (Correct answer)
- Reviewing past losses to identify trends
- Setting employee performance benchmarks
- Calculating regulatory capital under Basel rules only
Correct answer: Estimating potential losses from low-frequency, high-severity events not captured in historical data
Scenario analysis helps organizations estimate potential losses from rare but severe events by using expert judgment since historical data is insufficient for such events.
Under the Basel III operational risk framework, which approach requires banks to calculate a business indicator component multiplied by internal loss multiplier?