CCB Operational Risk & Control Testing 5 — Questions and Answers
Question 1: A compliance officer reviews a control testing workpaper and notices the tester documented 'no exceptions found' but did not retain evidence of the sample reviewed. What is the main deficiency?
- The control was over-tested
- The test conclusion is not supportable without evidence of work performed (Correct answer)
- The sample size was too large
- The conclusion should always note at least one exception
Correct answer: The test conclusion is not supportable without evidence of work performed
Without retaining evidence of the sample reviewed, the testing conclusion cannot be independently verified or supported in the event of an audit or review.
Question 2: Which of the following best describes the 'four-eyes principle' in operational risk control?
- A physical inspection requiring two compliance officers to observe simultaneously
- Requiring two independent individuals to review and approve a critical transaction or decision (Correct answer)
- A biometric security measure for system access
- A dual reporting line structure in the organizational chart
Correct answer: Requiring two independent individuals to review and approve a critical transaction or decision
The four-eyes principle mandates that at least two people must independently review and authorize significant actions to reduce the risk of errors or fraud.
Question 3: A bank's operational risk team is categorizing a loss event where a rogue trader bypassed internal controls to hide trading losses. Under Basel event type classifications, this falls under:
- External Fraud
- Internal Fraud (Correct answer)
- Execution, Delivery & Process Management
- Clients, Products & Business Practices
Correct answer: Internal Fraud
Unauthorized trading by an employee to conceal losses is classified as Internal Fraud under Basel operational risk event type categories.
Question 4: What is the primary purpose of an operational risk control inventory?
- To list all financial instruments held by the firm
- To catalogue all controls mapped to specific risks so gaps and redundancies can be identified (Correct answer)
- To track employee certifications and training completions
- To record all regulatory fines paid in the past five years
Correct answer: To catalogue all controls mapped to specific risks so gaps and redundancies can be identified
A control inventory provides a comprehensive list of controls linked to risks, enabling organizations to spot where coverage is missing or where controls overlap unnecessarily.
Question 5: When performing a 'test of design' for an operational control, a compliance officer is evaluating whether:
- The control was actually executed during the testing period
- The control, if operating as intended, would effectively mitigate the identified risk (Correct answer)
- The control has been tested in prior periods without exception
- The control meets the minimum number of automated checks required by regulation
Correct answer: The control, if operating as intended, would effectively mitigate the identified risk
A test of design assesses whether the control is conceptually capable of addressing the risk, separate from whether it is actually being performed.
Question 6: A compliance manager is tasked with assessing operational risk in a newly launched digital payment product. Which framework component should be completed first?
- Issue tracking and remediation log
- Risk and control self-assessment (RCSA) for the new product (Correct answer)
- Loss event database update
- KRI threshold recalibration
Correct answer: Risk and control self-assessment (RCSA) for the new product
An RCSA should be conducted at product launch to identify and assess the inherent risks and evaluate whether existing controls are adequate before operations begin.
Question 7: Under the COSO ERM framework, which component focuses on an organization's policies, procedures, and mechanisms to ensure that risk responses are carried out effectively?
- Risk Identification
- Event Identification
- Control Activities (Correct answer)
- Information and Communication
Correct answer: Control Activities
Control Activities under COSO ERM are the policies and procedures that help ensure management's risk responses are executed effectively across the organization.
A compliance officer reviews a control testing workpaper and notices the tester documented 'no exceptions found' but did not retain evidence of the sample reviewed.
What is the main deficiency?