CCB Operational Risk & Control Testing 4 โ Questions and Answers
Question 1: A third-party vendor that processes customer data experiences a data breach. Under operational risk frameworks, this event is best classified as:
- External fraud
- Third-party/vendor operational risk (Correct answer)
- Market disruption risk
- Credit default risk
Correct answer: Third-party/vendor operational risk
Risks arising from third-party service providers are classified as vendor or third-party operational risk, a recognized sub-category of operational risk.
Question 2: Which element is typically NOT included in an operational risk loss event report?
- Date and time of the event
- Root cause classification
- Future market price forecasts (Correct answer)
- Financial impact of the loss
Correct answer: Future market price forecasts
Loss event reports capture historical operational failures; future market price forecasts are unrelated to documenting an operational loss event.
Question 3: A walkthrough of a cash reconciliation process reveals that the same employee both prepares and approves the reconciliation. This is an example of:
- Adequate dual control
- A segregation of duties violation (Correct answer)
- An effective detective control
- A compensating control in place
Correct answer: A segregation of duties violation
Having one person both prepare and approve a reconciliation violates the principle of segregation of duties, as no independent check exists.
Question 4: When testing controls over a financial reporting process, a compliance professional finds that the control operates 'as designed' but the underlying process still produces errors. What does this indicate?
- The control is designed effectively but may be insufficient for the risk (Correct answer)
- The control should be documented as fully effective
- The process errors are within acceptable tolerance automatically
- The test methodology was flawed
Correct answer: The control is designed effectively but may be insufficient for the risk
A control can operate as designed yet still be insufficient if its design does not adequately address the risk, highlighting a design deficiency rather than an operating failure.
Question 5: Which of the following is the best indicator that an organization's operational risk culture is strong?
- Employees rarely report risk events to avoid blame
- Management discourages escalation to reduce noise
- Employees proactively report near misses without fear of punishment (Correct answer)
- Risk appetite statements are updated only after losses occur
Correct answer: Employees proactively report near misses without fear of punishment
A strong risk culture is characterized by psychological safety and open reporting, where employees voluntarily disclose near misses to prevent future losses.
Question 6: A compliance team is evaluating the residual risk after controls are applied. Which formula correctly represents residual risk?
- Residual Risk = Inherent Risk + Control Effectiveness
- Residual Risk = Inherent Risk - Control Effectiveness (Correct answer)
- Residual Risk = Inherent Risk ร Likelihood
- Residual Risk = Control Effectiveness / Inherent Risk
Correct answer: Residual Risk = Inherent Risk - Control Effectiveness
Residual risk equals inherent risk minus the risk reduction achieved through controls, representing the remaining exposure after mitigation.
Question 7: Under US federal guidance, financial institutions are expected to conduct operational risk stress testing primarily to:
- Determine employee bonus structures
- Assess the firm's ability to withstand severe operational disruptions and capital impacts (Correct answer)
- Set daily transaction limits for customers
- Benchmark performance against peer institutions only
Correct answer: Assess the firm's ability to withstand severe operational disruptions and capital impacts
Operational risk stress testing evaluates whether a firm has sufficient capital and resilience to absorb losses from severe but plausible operational disruptions.
A third-party vendor that processes customer data experiences a data breach.
Under operational risk frameworks, this event is best classified as: