Certified Bank Auditor (CBA) — Questions and Answers
Question 1: Under CECL (ASC 326), the allowance for credit losses on a bank's held-to-maturity (HTM) securities portfolio is measured using:
- Fair value less estimated selling costs
- The incurred loss model based on past due status
- The greater of historical loss rate or current period charge-offs
- Lifetime expected credit losses from the date of acquisition (Correct answer)
Correct answer: Lifetime expected credit losses from the date of acquisition
CECL requires banks to estimate lifetime expected credit losses on HTM securities at acquisition, replacing the prior incurred-loss model.
Question 2: A bank's BSA/AML compliance program must include all of the following EXCEPT:
- A designated compliance officer
- Ongoing employee training
- Annual external audits of all loan files (Correct answer)
- Board-approved written policies and procedures
Correct answer: Annual external audits of all loan files
The four pillars of a BSA/AML program are: internal controls, a designated compliance officer, training, and independent testing—not annual external loan file audits specifically.
Question 3: In the context of model risk management, 'model validation' refers to:
- User acceptance testing of new banking software platforms
- Independent evaluation of a model's conceptual soundness, data integrity, and performance (Correct answer)
- Regulatory approval of risk models by supervisory authorities
- Annual backtesting of VaR models against actual trading losses
Correct answer: Independent evaluation of a model's conceptual soundness, data integrity, and performance
Model validation is the independent assessment of whether a model is conceptually sound, uses appropriate data, and performs as intended.
Question 4: What is the key difference between a 'compliance risk assessment' and a 'compliance audit' in a bank's compliance framework?
- A compliance audit is required by law; a risk assessment is optional
- Risk assessments focus on credit risk while audits focus on operational risk
- A risk assessment is performed by external auditors; an audit is performed internally
- A risk assessment identifies and prioritizes potential compliance risks; an audit tests whether controls are operating effectively (Correct answer)
Correct answer: A risk assessment identifies and prioritizes potential compliance risks; an audit tests whether controls are operating effectively
A compliance risk assessment identifies and prioritizes risks before they occur, while a compliance audit evaluates whether existing controls are functioning effectively to mitigate those risks.
Question 5: A bank discovers that a critical payment system was unavailable for 4 hours due to a software error. This is an example of which Basel risk category?
- Strategic risk
- Operational risk (Correct answer)
- Credit risk
- Market risk
Correct answer: Operational risk
System failures that cause service disruptions fall under operational risk, which includes technology and process failures.
Question 6: Under GLBA (Gramm-Leach-Bliley Act) Safeguards Rule, banks must implement a comprehensive information security program to protect:
- Nonpublic personal information (NPI) of individual customers (Correct answer)
- Proprietary trading strategies and algorithms
- Publicly available information about the bank's operations
- All financial data held by the bank, including institutional records
Correct answer: Nonpublic personal information (NPI) of individual customers
The GLBA Safeguards Rule specifically requires financial institutions to protect the nonpublic personal information (NPI) of individual consumers from unauthorized access or disclosure.
Question 7: Which regulatory body published the 'Principles for Enhancing Corporate Governance' that are widely used as a global benchmark for banks?
- International Monetary Fund (IMF)
- U.S. Securities and Exchange Commission (SEC)
- Basel Committee on Banking Supervision (BCBS) (Correct answer)
- Financial Accounting Standards Board (FASB)
Correct answer: Basel Committee on Banking Supervision (BCBS)
The Basel Committee on Banking Supervision published the Principles for Enhancing Corporate Governance, providing the primary global standard for bank boards.
Question 8: When auditing a bank's earnings per share (EPS) disclosures, which item requires the most careful consideration in the diluted EPS calculation?
- Cash dividends declared on common shares during the reporting period
- Treasury stock purchased under the bank's board-approved buyback program
- Preferred stock dividends paid to holders of non-convertible preferred shares
- Convertible subordinated debt where conversion would be antidilutive to EPS (Correct answer)
Correct answer: Convertible subordinated debt where conversion would be antidilutive to EPS
Antidilutive securities — those that would increase EPS if included — must be excluded from the diluted EPS calculation under ASC 260.
Question 9: Which of the following BEST describes the relationship between inherent risk, control effectiveness, and residual risk from a bank auditor's perspective?
- Inherent risk and control effectiveness are independent variables that do not impact the calculation of residual risk.
- A high level of inherent risk combined with weak control effectiveness will result in a high level of residual risk. (Correct answer)
- Residual risk is the level of risk before any controls are applied, and it is reduced by inherent risk.
- Effective controls increase the level of inherent risk, leading to a higher residual risk.
Correct answer: A high level of inherent risk combined with weak control effectiveness will result in a high level of residual risk.
This question assesses a fundamental risk concept. Inherent risk is the risk present in an activity before any controls are applied. Controls are implemented to mitigate this risk. Residual risk is the level of risk that remains after controls have been implemented. Therefore, if the inherent risk is high and the controls designed to mitigate it are weak or ineffective, the resulting residual risk will also be high. Auditors evaluate this relationship to determine where to focus their testing efforts.
Question 10: In a bank's call report (FFIEC 041), which schedule captures loan-level data on past due and nonaccrual loans?
- Schedule RC-N (Past Due and Nonaccrual) (Correct answer)
- Schedule RC-E (Deposits)
- Schedule RI (Income Statement)
- Schedule RC-B (Securities)
Correct answer: Schedule RC-N (Past Due and Nonaccrual)
Schedule RC-N of the call report specifically captures loans, leases, and debt securities categorized by days past due and nonaccrual status.
Question 11: An internal auditor at a regional bank is evaluating the institution's operational risk management framework. Which of the following represents the MOST critical component for the auditor to assess to ensure the framework's effectiveness?
- The frequency and cost of external consultants hired to review operational risk.
- The total financial amount of operational losses incurred in the previous fiscal year.
- The comprehensiveness of the bank's insurance policies for mitigating potential losses.
- The process for identifying, assessing, monitoring, and reporting operational risks across all business lines. (Correct answer)
Correct answer: The process for identifying, assessing, monitoring, and reporting operational risks across all business lines.
The core of an effective operational risk management framework is a robust, end-to-end process for proactively managing risk. An auditor must verify that the bank has a systematic way to identify risks, assess their potential impact, monitor them continuously, and report them to relevant stakeholders. While insurance, consultant usage, and historical losses are relevant data points, they are secondary to the fundamental process itself.
Question 12: Which control is MOST effective in preventing a teller from both initiating and approving their own cash transactions?
- Separation of duties (Correct answer)
- Fidelity bonding
- Surprise cash counts
- Dual control over the vault
Correct answer: Separation of duties
Separation of duties ensures no single individual can initiate, approve, and record a transaction, reducing the risk of fraud or error.
Question 13: An auditor testing a bank's reconciliation controls finds that the reconciliation is prepared but never reviewed or approved. This represents:
- A significant deficiency due to missing supervisory review
- Acceptable practice if discrepancies are below materiality threshold
- A design deficiency because the control is incomplete (Correct answer)
- A material weakness because reconciliations are ineffective
Correct answer: A design deficiency because the control is incomplete
A reconciliation without supervisory review is a design deficiency because an effective reconciliation control requires both preparation and independent review.
Question 14: What role does internal audit play in a bank's internal control system?
- Approving loans
- Independent assessment of controls (Correct answer)
- Managing customer accounts
- Setting product pricing
Correct answer: Independent assessment of controls
Internal audit provides independent evaluations of the bank’s risk management, control, and governance processes.
Question 15: In the 'Three Lines of Defense' model for risk management, what is the primary role of the internal audit function?
- To perform daily monitoring and management of risks within the front-line business units.
- To design and implement risk mitigation controls for new banking products.
- To set the overall risk appetite for the institution on behalf of the board.
- To provide independent and objective assurance on the effectiveness of risk management, governance, and internal controls. (Correct answer)
Correct answer: To provide independent and objective assurance on the effectiveness of risk management, governance, and internal controls.
The internal audit function serves as the third line of defense, providing independent assurance to the board and senior management that the first and second lines are operating effectively. It does not own or manage risks (first line) or set risk management policies (second line/management), but rather evaluates the entire framework objectively.
Question 16: When performing a regulatory compliance audit of the Gramm-Leach-Bliley Act (GLBA), which of the following is the auditor's MOST critical area of focus?
- Ensuring the timely and accurate filing of Currency Transaction Reports.
- Evaluating the adequacy of the bank's program to protect the confidentiality and security of customers' nonpublic personal information. (Correct answer)
- Verifying that all loan disclosures provide a clear Annual Percentage Rate (APR).
- Assessing the bank's efforts to provide credit services to all segments of its community.
Correct answer: Evaluating the adequacy of the bank's program to protect the confidentiality and security of customers' nonpublic personal information.
The Gramm-Leach-Bliley Act (GLBA) has two main components: the Privacy Rule and the Safeguards Rule. The Safeguards Rule is a critical focus for auditors, as it requires financial institutions to develop, implement, and maintain a comprehensive written information security program to protect nonpublic customer information.
Question 17: Which risk category encompasses losses resulting from inadequate internal processes, people, systems, or external events?
- Operational risk (Correct answer)
- Market risk
- Credit risk
- Strategic risk
Correct answer: Operational risk
Operational risk, as defined by Basel II/III, covers losses from internal failures or external events including fraud, system outages, and natural disasters.
Question 18: A politically exposed person (PEP) is subject to enhanced due diligence because they:
- Typically conduct high-volume transactions that require extra review
- Are required by law to disclose all financial accounts
- Are more likely to be targets of identity theft
- Pose higher AML risk due to potential for corruption and abuse of public positions (Correct answer)
Correct answer: Pose higher AML risk due to potential for corruption and abuse of public positions
PEPs are considered higher risk because their public positions of trust create vulnerability to corruption, bribery, and misappropriation of public funds.
Question 19: A bank's contingency funding plan (CFP) should be tested:
- Only when a liquidity crisis is imminent
- Once at inception and filed with regulators
- Periodically and updated to reflect changes in the bank's business and market conditions (Correct answer)
- Annually by external auditors only
Correct answer: Periodically and updated to reflect changes in the bank's business and market conditions
CFPs must be regularly tested and updated to remain effective; stale plans may fail when actually needed.
Question 20: In analyzing a bank's interest rate risk, a parallel upward shift of 200 basis points that causes a 15% decline in economic value of equity (EVE) indicates:
- Excellent hedging of interest rate risk in the banking book
- The bank has significant long-duration assets funded by shorter-duration liabilities (Correct answer)
- A decrease in the bank's credit risk exposure
- The bank is asset-sensitive and benefits from rising rates
Correct answer: The bank has significant long-duration assets funded by shorter-duration liabilities
A large EVE decline from rising rates signals that the bank holds long-duration assets (e.g., fixed-rate mortgages) funded by shorter-duration liabilities, creating negative duration gap exposure.
Question 21: When a bank auditor identifies that loan loss reserves are systematically below expected loss estimates, this MOST directly indicates a problem with:
- Capital adequacy reporting
- Allowance for Credit Loss (ACL) adequacy (Correct answer)
- Operational risk governance
- Market risk controls
Correct answer: Allowance for Credit Loss (ACL) adequacy
Insufficient loan loss reserves relative to expected losses points to an inadequacy in the Allowance for Credit Loss methodology or application.
Question 22: Which BEST describes the role of a bank IT auditor when reviewing a new fintech partnership?
- Setting the fintech partner's information security policies
- Developing the technical integration specifications
- Assessing whether adequate due diligence and ongoing monitoring controls exist for the third-party relationship (Correct answer)
- Approving the commercial terms of the partnership agreement
Correct answer: Assessing whether adequate due diligence and ongoing monitoring controls exist for the third-party relationship
IT auditors assess whether the bank has performed adequate due diligence and established ongoing monitoring to manage risks introduced by third-party fintech relationships.
Question 23: An auditor discovers that loan officers are encouraged to help customers 'structure' their loan applications to meet underwriting criteria. This practice MOST likely violates:
- The Bank Secrecy Act's CTR requirements
- RESPA Section 8 anti-kickback provisions
- Regulation CC hold requirements
- Regulation B and safe and sound lending standards (Correct answer)
Correct answer: Regulation B and safe and sound lending standards
Coaching applicants to misrepresent their financial information constitutes application fraud and violates Regulation B's prohibition on discriminatory or deceptive credit practices.
Question 24: Which of the following is a key component of an effective compliance program?
- Ongoing employee training (Correct answer)
- Frequent audits only
- Outsourcing core operations
- External marketing support
Correct answer: Ongoing employee training
Ongoing employee training ensures that all staff understand and adhere to current laws, regulations, and internal policies.
Question 25: Which of the following BEST describes a 'key risk indicator' (KRI) in the context of bank compliance?
- A checklist used during annual compliance audits
- A regulatory penalty imposed after a compliance failure
- A metric used to measure past compliance failures
- A forward-looking metric that signals increasing risk exposure before a breach occurs (Correct answer)
Correct answer: A forward-looking metric that signals increasing risk exposure before a breach occurs
KRIs are prospective metrics that alert management when risk levels are rising, enabling proactive intervention before a compliance breach materializes.
Question 26: Under the Bank Secrecy Act (BSA), what is the minimum transaction amount that triggers a Currency Transaction Report (CTR)?
- $15,000
- $10,000 (Correct answer)
- $5,000
- $25,000
Correct answer: $10,000
The BSA requires banks to file a CTR for any cash transaction exceeding $10,000 in a single business day.
Question 27: Which of the following best describes 'concentration risk' in a banking context?
- The risk that interest rates will change unexpectedly
- Excessive exposure to a single borrower, sector, or geography (Correct answer)
- Risk from foreign currency transactions
- Risk arising from high employee turnover in the risk department
Correct answer: Excessive exposure to a single borrower, sector, or geography
Concentration risk arises when a bank has excessive exposure to a single counterparty, industry, or geographic region, creating vulnerability to correlated losses.
Question 28: Which financial reporting standard governs the recognition and measurement of a bank's trading securities?
- ASC 310 (Receivables)
- ASC 320 (Investments in Debt Securities) (Correct answer)
- ASC 948 (Financial Services — Mortgage Banking)
- ASC 815 (Derivatives and Hedging)
Correct answer: ASC 320 (Investments in Debt Securities)
ASC 320 classifies debt securities into trading, AFS, and HTM categories, with trading securities measured at fair value through earnings.
Question 29: A Certified Bank Auditor is tasked with evaluating the effectiveness of the second line of defense in a large financial institution. Which of the following functions is the auditor MOST likely to be examining?
- The activities of the independent risk management and compliance functions. (Correct answer)
- The internal audit department's quality assurance and improvement program.
- The loan origination department's process for approving new commercial loans.
- The board of directors' process for strategic planning and objective setting.
Correct answer: The activities of the independent risk management and compliance functions.
The second line of defense is composed of the functions that oversee and challenge the risk-taking activities of the first line. This primarily includes the risk management function, the compliance function, and other control-related functions that report to senior management. Loan origination is a first-line function, internal audit is the third line, and the board is part of the overall governance structure.
Question 30: Counterparty credit risk (CCR) in derivatives is BEST measured using:
- Notional value of the derivative contract
- Mark-to-market value at trade inception
- The credit rating of the counterparty alone
- Current exposure plus potential future exposure (PFE) (Correct answer)
Correct answer: Current exposure plus potential future exposure (PFE)
CCR is measured using current exposure (current MTM if positive) plus potential future exposure to capture how exposure may grow over time.
Question 31: The risk that a bank cannot meet its payment obligations as they fall due without incurring unacceptable losses is called:
- Funding liquidity risk (Correct answer)
- Counterparty risk
- Solvency risk
- Market liquidity risk
Correct answer: Funding liquidity risk
Funding liquidity risk is the inability to raise funds to meet obligations on time without unacceptable cost.
Question 32: During a compliance audit of a bank's anti-money laundering (AML) program, the auditor finds that Customer Due Diligence (CDD) procedures do not include beneficial ownership collection for legal entity customers. Which FinCEN rule is the bank violating?
- FinCEN's Suspicious Activity Report (SAR) Rule
- FinCEN's Currency Transaction Report (CTR) Aggregation Rule
- FinCEN's Customer Identification Program (CIP) Rule
- FinCEN's Beneficial Ownership Rule (31 CFR 1010.230) (Correct answer)
Correct answer: FinCEN's Beneficial Ownership Rule (31 CFR 1010.230)
FinCEN's Beneficial Ownership Rule requires covered financial institutions to collect information on natural persons owning 25% or more of legal entity customers.
Question 33: A bank's compliance audit of its Home Equity Line of Credit (HELOC) program finds that the required three-business-day right of rescission notice was not provided to borrowers. Which regulation was violated?
- Regulation Z (Truth in Lending Act) (Correct answer)
- Regulation E (Electronic Fund Transfer Act)
- Regulation B (ECOA)
- Regulation X (RESPA)
Correct answer: Regulation Z (Truth in Lending Act)
Regulation Z (TILA) grants borrowers a three-business-day right to rescind certain consumer credit transactions secured by their principal dwelling, including HELOCs.
Question 34: A community bank's financial statements show significant growth in brokered deposits. From an audit perspective, this is most relevant to which risk area?
- Compliance risk from potential violations of the Community Reinvestment Act
- Operational risk from processing a higher volume of deposit transactions
- Credit risk from increased loan demand funded by new depositors
- Liquidity risk and concentration risk from reliance on volatile, rate-sensitive funding (Correct answer)
Correct answer: Liquidity risk and concentration risk from reliance on volatile, rate-sensitive funding
Brokered deposits are considered volatile funding sources that can be withdrawn quickly when rates change, creating significant liquidity and concentration risks.
Question 35: A bank's return on assets (ROA) is 0.85% while its return on equity (ROE) is 12.5%. The difference is primarily driven by:
- A low efficiency ratio
- Financial leverage (equity multiplier) (Correct answer)
- A high noninterest income ratio
- Elevated credit loss provisions
Correct answer: Financial leverage (equity multiplier)
The DuPont relationship ROE = ROA Ă— (Assets/Equity) shows that the equity multiplier (leverage) amplifies ROA into the higher ROE figure.
Question 36: When auditing a bank's interest rate risk management, which document MOST directly reflects how management measures and limits IRRBB exposure?
- Asset-Liability Committee (ALCO) policy and meeting minutes (Correct answer)
- External credit rating agency methodology
- Annual financial statements and footnotes
- Loan origination underwriting guidelines
Correct answer: Asset-Liability Committee (ALCO) policy and meeting minutes
The ALCO policy and its meeting minutes document how management measures, monitors, and sets limits on interest rate risk in the banking book.
Question 37: In many jurisdictions, corporate governance best practices recommend the separation of the Chief Executive Officer (CEO) and Board Chairperson roles. What is the primary governance advantage of this separation?
- It automatically reduces the operational expenses associated with the board of directors.
- It guarantees that the bank will meet all its regulatory capital requirements.
- It strengthens the board's independence and its ability to provide objective oversight of management. (Correct answer)
- It simplifies the day-to-day operational command structure for employees.
Correct answer: It strengthens the board's independence and its ability to provide objective oversight of management.
Separating the roles of CEO and Board Chair avoids concentrating excessive power in one individual. An independent chairperson can lead the board in its primary function of overseeing and evaluating the CEO and management team, which is a fundamental check and balance in a strong governance structure.
Question 38: A Certified Bank Auditor is evaluating the effectiveness of a bank's enterprise risk management (ERM) program based on the COSO framework. Which of the following activities best represents the 'Risk Assessment' component of the COSO framework?
- Segregation of duties is enforced within the loan origination and approval process.
- The internal audit function performs a follow-up review to ensure management has remediated a previously identified control weakness.
- The board of directors establishes a code of conduct and demonstrates a commitment to integrity and ethical values.
- Management uses a combination of qualitative and quantitative methods to analyze the potential likelihood and impact of identified risks. (Correct answer)
Correct answer: Management uses a combination of qualitative and quantitative methods to analyze the potential likelihood and impact of identified risks.
The 'Risk Assessment' component of the COSO framework involves identifying, analyzing, and managing the risks that threaten the achievement of an organization's objectives. Analyzing the likelihood and impact of risks is a core activity of this component. Establishing a code of conduct relates to the Control Environment, follow-up reviews are part of Monitoring Activities, and segregation of duties is an example of Control Activities.
Question 39: A bank's IT auditor is assessing vendor management controls for a cloud-based core banking provider. Which document is MOST important to review?
- The vendor's marketing brochure
- The vendor's office lease agreement
- The vendor's employee handbook
- The Service Level Agreement and right-to-audit clause (Correct answer)
Correct answer: The Service Level Agreement and right-to-audit clause
The SLA defines performance commitments and the right-to-audit clause ensures the bank can verify the vendor's controls, which is essential for regulatory compliance.
Question 40: According to the FFIEC, which of the following is one of the five required pillars of a bank's BSA/AML compliance program?
- A board-approved list of high-risk countries.
- The use of automated transaction monitoring software.
- Quarterly reporting of all cash transactions to the board of directors.
- Designation of a qualified BSA Compliance Officer. (Correct answer)
Correct answer: Designation of a qualified BSA Compliance Officer.
The five pillars required by the Bank Secrecy Act for an effective AML program are: (1) a system of internal controls, (2) independent testing, (3) a designated BSA compliance officer, (4) training for appropriate personnel, and (5) customer due diligence (CDD). The designation of a qualified individual to be responsible for the program is a mandatory pillar.
Question 41: When a bank sells mortgages and retains the servicing rights, the retained servicing rights create exposure to which specific risk?
- Settlement risk
- Prepayment risk (Correct answer)
- Funding liquidity risk
- Legal risk
Correct answer: Prepayment risk
Mortgage servicing rights lose value when prepayments accelerate (typically when rates fall), creating significant prepayment risk.
Question 42: During an audit, it is noted that a bank's senior executives consistently prioritize short-term profit goals, leading to the dismissal of compliance concerns and a high-pressure sales environment. This observation is MOST indicative of a weakness in which corporate governance element?
- The effectiveness of the internal audit charter.
- The 'tone at the top' set by leadership. (Correct answer)
- The formal structure of the board's compensation committee.
- The adequacy of the bank's business continuity plan.
Correct answer: The 'tone at the top' set by leadership.
'Tone at the top' refers to the ethical climate established by the board and senior management. When leadership demonstrates through their actions and priorities that ethics and compliance are secondary to profits, it creates a poor ethical culture that permeates the organization.
Question 43: An auditor is assessing a bank's risk appetite framework (RAF). A key attribute of an effective RAF is the clear assignment of roles and responsibilities. Which function is ultimately responsible for providing independent assurance to the board and senior management on the quality and effectiveness of the bank's risk management processes, including the RAF?
- The Chief Risk Officer (CRO)
- The business line management
- The internal audit function (Correct answer)
- The Asset-Liability Committee (ALCO)
Correct answer: The internal audit function
The internal audit function, as the third line of defense, plays a crucial role in providing independent assurance to the board and senior management. Its responsibilities include evaluating the effectiveness of the risk management and internal control systems, which encompasses the risk appetite framework. While the CRO, business lines, and ALCO are all critical to implementing and managing the RAF, internal audit provides the independent review and validation.
Question 44: What is the purpose of the statement of cash flows?
- To track net income
- To show cash movement in and out of the business (Correct answer)
- To calculate interest expense
- To assess asset turnover
Correct answer: To show cash movement in and out of the business
It provides information about a company's cash inflows and outflows, categorized into operating, investing, and financing activities.
Question 45: Which audit technique is most effective for detecting unauthorized access to a bank's core banking system?
- Interviewing branch managers about their access control practices
- Analyzing user access logs to identify access attempts outside normal business hours or from unusual locations (Correct answer)
- Reviewing annual penetration test reports prepared by management
- Confirming that the IT department has an access policy document
Correct answer: Analyzing user access logs to identify access attempts outside normal business hours or from unusual locations
Log analysis of user access patterns identifies anomalous behavior that may indicate unauthorized access, providing direct evidence rather than relying on management representations.
Question 46: A bank auditor reviewing HMDA data discovers that the bank's denial rate for minority applicants is significantly higher than for similarly qualified white applicants. This is most consistent with:
- Disparate impact or disparate treatment in lending (Correct answer)
- Statistical noise in a small sample
- Appropriate risk-based underwriting decisions
- Compliance with the Equal Housing Lender requirements
Correct answer: Disparate impact or disparate treatment in lending
Disproportionate denial rates for minority applicants relative to similarly qualified non-minorities is a classic indicator of disparate treatment or disparate impact under fair lending laws.
Question 47: What does 'related-party transaction' mean in the context of bank governance?
- A transaction executed on behalf of a family trust by the bank's wealth management division
- Any transaction exceeding $10 million in notional value
- A transaction between a bank and a closely affiliated entity such as a director, major shareholder, or their associates (Correct answer)
- A transaction with a foreign correspondent bank
Correct answer: A transaction between a bank and a closely affiliated entity such as a director, major shareholder, or their associates
Related-party transactions involve insiders or their affiliates, requiring heightened scrutiny to prevent self-dealing and conflicts of interest.
Question 48: A bank identifies that two of its board directors serve on the board of a major competitor. This situation primarily raises concerns about:
- Non-compliance with capital requirements
- Excessive director compensation
- Insufficient board diversity
- Conflicts of interest and potential breach of fiduciary duty (Correct answer)
Correct answer: Conflicts of interest and potential breach of fiduciary duty
Serving on competitor boards creates conflicts of interest, risks disclosure of confidential information, and may breach fiduciary duties.
Question 49: A bank's Board Risk Committee is reviewing documents as part of its quarterly meeting. Which of the following activities is a core responsibility of this committee?
- Overseeing the development and implementation of the bank's risk management framework and recommending the risk appetite for board approval. (Correct answer)
- Recommending the appointment and remuneration of the external auditor to the full board.
- Approving individual loan applications that exceed the limits of front-line loan officers.
- Managing the bank's investment portfolio to maximize short-term returns.
Correct answer: Overseeing the development and implementation of the bank's risk management framework and recommending the risk appetite for board approval.
The Board Risk Committee is responsible for assisting the board in its oversight of the bank's risk management framework. This includes defining the bank's risk appetite and tolerance levels for ultimate approval by the full board, and ensuring management has effective processes to identify, assess, and manage risks. Appointing the external auditor is the Audit Committee's role, while managing portfolios and approving loans are management functions.
Question 50: Under FASB ASC 825, a bank elects the fair value option for certain financial instruments. Which statement is correct regarding audit implications?
- Fair value option elections reduce the complexity of financial statement audits
- The auditor must evaluate the bank's valuation techniques and key assumptions (Correct answer)
- The election is irrevocable and applies to all financial instruments in the same category
- Fair value changes are recognized in other comprehensive income only
Correct answer: The auditor must evaluate the bank's valuation techniques and key assumptions
When the fair value option is elected, the auditor must assess the appropriateness of valuation methodologies, inputs, and assumptions used to determine fair value.
Question 51: A bank issues $100 million in subordinated debt qualifying as Tier 2 capital. After 5 years (2 years before maturity), the regulatory capital credit is:
- 20% of the original amount ($20 million)
- 80% of the original amount ($80 million) (Correct answer)
- Full $100 million
- Zero — subordinated debt within 5 years of maturity is excluded
Correct answer: 80% of the original amount ($80 million)
Basel III phases out Tier 2 capital instruments during the final 5 years before maturity at 20% per year, so with 2 years remaining, only 40% is recognized — but with exactly 2 years left the credit is 40%, and at exactly 5 years remaining it starts at 80%.
Question 52: Which of the following scenarios represents a 'tail risk' that a bank's risk management framework must specifically address?
- A simultaneous global financial crisis causing correlated defaults across multiple asset classes (Correct answer)
- A 1% increase in the federal funds rate
- Seasonal fluctuations in consumer loan demand
- Minor changes in daily trading volumes
Correct answer: A simultaneous global financial crisis causing correlated defaults across multiple asset classes
Tail risk refers to low-probability, high-impact events beyond normal VaR models, such as correlated systemic failures that can cause catastrophic losses.
Question 53: Under Basel III, the Liquidity Coverage Ratio (LCR) requires banks to maintain sufficient high-quality liquid assets (HQLA) to cover net cash outflows for how many days?
- 14 days
- 30 days (Correct answer)
- 7 days
- 60 days
Correct answer: 30 days
The LCR requires banks to hold enough HQLA to cover projected net cash outflows over a 30-day stressed liquidity scenario.
Question 54: For a large, publicly traded financial institution, which of the following is MOST likely to be identified by the external auditor as a Critical Audit Matter (CAM) in the auditor's report?
- The verification of interest income on U.S. Treasury securities classified as held-to-maturity.
- The testing of controls over the reconciliation of correspondent bank accounts.
- The review of the bank's compliance with physical security controls at branch locations.
- The valuation of the allowance for credit losses on the loan portfolio. (Correct answer)
Correct answer: The valuation of the allowance for credit losses on the loan portfolio.
A CAM is a matter that involved especially challenging, subjective, or complex auditor judgment. The valuation of the allowance for credit losses, particularly under CECL, fits this definition perfectly. It involves complex models, significant management judgment regarding economic forecasts, and requires extensive audit effort and scrutiny, making it a prime candidate for a CAM.
Question 55: Which metric measures the potential loss on a trading portfolio over a given time horizon at a specified confidence level?
- Expected Loss (EL)
- Net Stable Funding Ratio (NSFR)
- Return on Risk-Adjusted Capital (RORAC)
- Value at Risk (VaR) (Correct answer)
Correct answer: Value at Risk (VaR)
VaR quantifies the maximum expected loss over a specific period at a given confidence level (e.g., 99% over one day).
Question 56: A bank auditor is performing a cybersecurity risk assessment. The first step in this process is to identify the bank's inherent risk. Which of the following factors is MOST indicative of a high inherent cybersecurity risk?
- The bank recently conducted a successful phishing simulation for all employees.
- The bank uses a limited number of third-party vendors for non-critical services.
- The bank's internal audit department has a certified information systems auditor on staff.
- The bank offers complex international payment services and utilizes extensive online and mobile banking platforms. (Correct answer)
Correct answer: The bank offers complex international payment services and utilizes extensive online and mobile banking platforms.
Inherent risk is the level of risk a bank faces based on its activities and business model, before considering any controls. Offering complex products like international payments and having a large digital footprint through online and mobile banking significantly increases the attack surface and the potential for cyber threats, thus leading to a higher inherent risk profile.
Question 57: Which financial statement line item most directly reflects a bank's credit risk exposure from off-balance-sheet commitments?
- Contingent liabilities disclosed in footnotes (Correct answer)
- Allowance for credit losses
- Deferred tax liability
- Other comprehensive income
Correct answer: Contingent liabilities disclosed in footnotes
Unfunded loan commitments and letters of credit are off-balance-sheet exposures disclosed as contingent liabilities in the footnotes under ASC 450.
Question 58: A bank's risk appetite statement should PRIMARILY:
- Define the amount and types of risk the bank is willing to accept to achieve its objectives (Correct answer)
- Document all historical risk events and losses
- Identify specific operational controls for each business unit
- List regulatory capital requirements by risk category
Correct answer: Define the amount and types of risk the bank is willing to accept to achieve its objectives
A risk appetite statement articulates the level and nature of risk a bank is willing to take in pursuit of its strategic goals.
Question 59: Which component of the COSO Internal Control-Integrated Framework is generally considered the foundation for all other components, encompassing the 'tone at the top' set by the board of directors and senior management?
- Control Environment (Correct answer)
- Control Activities
- Risk Assessment
- Monitoring Activities
Correct answer: Control Environment
The Control Environment sets the tone of an organization, influencing the control consciousness of its people. It is the foundation for all other components of internal control, providing discipline, structure, and ethical values.
Question 60: Which governance document typically defines the scope of authority delegated from the board to senior management?
- Recovery and Resolution Plan
- Capital Adequacy Assessment
- Delegation of Authority Matrix (Correct answer)
- Liquidity Contingency Plan
Correct answer: Delegation of Authority Matrix
A Delegation of Authority Matrix formally specifies which decisions management can make independently versus those requiring board approval.
Question 61: Which type of money laundering involves inflating or deflating the price of goods in international trade invoices to transfer value across borders?
- Shell company layering
- Trade-based money laundering (TBML) (Correct answer)
- Hawala transfer
- Integration through real estate
Correct answer: Trade-based money laundering (TBML)
Trade-based money laundering exploits import/export invoice manipulation — over- or under-invoicing goods — to move value across borders while appearing as legitimate commerce.
Question 62: Under the FinCEN CDD Rule, a bank must identify and verify beneficial owners of a legal entity customer who own what minimum percentage of equity interests?
- 51%
- 10%
- 15%
- 25% (Correct answer)
Correct answer: 25%
The CDD Rule requires identifying all individuals who own 25% or more of a legal entity, plus one control prong individual regardless of ownership.
Question 63: Which of the following IT governance frameworks provides a comprehensive model that bridges the gap between technical issues, business risks, and control requirements, making it highly suitable for auditors in the banking sector?
- COBIT (Control Objectives for Information and Related Technologies) (Correct answer)
- ITIL (Information Technology Infrastructure Library)
- Scrum
- ISO/IEC 27001
Correct answer: COBIT (Control Objectives for Information and Related Technologies)
COBIT is a leading framework for the governance and management of enterprise IT. It is specifically designed to align IT with business goals, manage risks, and ensure regulatory compliance, which are all critical in the banking industry. Unlike ITIL, which focuses on IT service management, or ISO 27001, which is centered on the information security management system, COBIT provides an overarching governance structure that helps auditors evaluate the entire IT control environment in the context of business objectives.
Question 64: An IT auditor is assessing a bank's controls over end-of-life (EOL) software. Which risk is MOST significant?
- Slower system performance due to outdated code
- Increased software licensing costs
- Compatibility issues with new monitors
- No vendor security patches available, leaving known vulnerabilities permanently unmitigated (Correct answer)
Correct answer: No vendor security patches available, leaving known vulnerabilities permanently unmitigated
EOL software no longer receives security patches, meaning newly discovered vulnerabilities will never be fixed, leaving the bank permanently exposed.
Question 65: Under GAAS, when a bank auditor uses the work of an internal auditor, the external auditor must:
- Accept the internal auditor's findings without independent verification to avoid duplication
- Reduce the audit fee proportionally to reflect reliance on internal audit work
- Include the internal auditor as a co-signer on the audit report
- Evaluate the competence, objectivity, and work quality of the internal audit function (Correct answer)
Correct answer: Evaluate the competence, objectivity, and work quality of the internal audit function
AU-C Section 610 requires external auditors to assess internal auditors' competence and objectivity and evaluate the quality of their work before placing reliance on it.
Question 66: Which log type would an IT auditor MOST likely review to detect brute-force login attempts against a bank's online banking system?
- Authentication failure logs (Correct answer)
- Application error logs
- Network bandwidth utilization logs
- Database transaction logs
Correct answer: Authentication failure logs
Authentication failure logs capture repeated failed login attempts, which is the primary indicator of a brute-force attack against user accounts.
Question 67: An IT auditor finds that a bank's employees are not required to complete cybersecurity awareness training. What risk does this MOST directly create?
- Reduced software license utilization
- Increased hardware procurement costs
- Higher susceptibility to social engineering attacks such as phishing (Correct answer)
- Slower system deployment timelines
Correct answer: Higher susceptibility to social engineering attacks such as phishing
Untrained employees are primary targets for phishing and social engineering attacks, making human error the leading cause of security breaches.
Question 68: Under the Sarbanes-Oxley Act (SOX) Section 302, which bank officers must certify the accuracy of financial reports?
- The internal audit director and external audit partner
- The Chief Risk Officer and General Counsel
- The Chief Executive Officer and Chief Financial Officer (Correct answer)
- All board members collectively
Correct answer: The Chief Executive Officer and Chief Financial Officer
SOX Section 302 requires the CEO and CFO to personally certify the accuracy of periodic financial reports filed with the SEC.
Question 69: An auditor is evaluating the controls over a bank's new customer-facing mobile application, which was developed by a third-party vendor. According to the FFIEC IT Examination Handbook, which of the following is a primary responsibility of the bank's management?
- Ensuring the vendor's disaster recovery plan is tested annually.
- Requiring the vendor to use the same brand of firewall as the bank for consistency.
- Conducting a thorough risk assessment and due diligence process before and during the engagement. (Correct answer)
- Performing code-level security reviews of the vendor's software.
Correct answer: Conducting a thorough risk assessment and due diligence process before and during the engagement.
The FFIEC places significant emphasis on third-party risk management. While the bank may not perform code reviews directly, it is ultimately responsible for the risks introduced by its vendors. A primary responsibility of the bank's management is to conduct comprehensive due diligence and ongoing risk assessments of its third-party service providers. This includes evaluating the vendor's security posture, financial stability, and operational controls to ensure they meet the bank's own risk appetite and regulatory requirements.
Question 70: Which of the following BEST describes the primary purpose of the internal audit charter in a banking institution?
- To outline the annual audit plan, including the specific departments and processes to be reviewed.
- To list the professional qualifications and continuing education requirements for the internal audit staff.
- To establish the internal audit function's purpose, authority, and responsibility, and its position within the organization. (Correct answer)
- To detail the specific testing procedures and methodologies that auditors must follow during engagements.
Correct answer: To establish the internal audit function's purpose, authority, and responsibility, and its position within the organization.
The internal audit charter is a formal document that defines the internal audit function's purpose, authority, and responsibility. It establishes the function's independence, authorizes its access to records, personnel, and physical properties relevant to the performance of engagements, and defines the scope of its activities. It is approved by the board of directors and senior management.
Question 71: Which of the following is a key function of a bank's Nominations and Governance Committee?
- Identifying and recommending candidates for board membership (Correct answer)
- Managing relationships with primary regulators on a daily basis
- Setting the bank's credit underwriting standards
- Approving all new product launches
Correct answer: Identifying and recommending candidates for board membership
The Nominations and Governance Committee oversees board composition, succession planning, and governance practices.
Question 72: During a review of a bank's Identity Theft Prevention Program, an auditor is primarily concerned with compliance with the rules promulgated under which act?
- Gramm-Leach-Bliley Act (GLBA)
- Bank Secrecy Act (BSA)
- Fair and Accurate Credit Transactions Act (FACTA) (Correct answer)
- Truth in Lending Act (TILA)
Correct answer: Fair and Accurate Credit Transactions Act (FACTA)
The Fair and Accurate Credit Transactions Act (FACTA) amended the Fair Credit Reporting Act (FCRA) and required the implementation of the "Red Flags Rules." These rules mandate that financial institutions and creditors develop and implement a written Identity Theft Prevention Program to detect, prevent, and mitigate identity theft.
Question 73: Which of the following is NOT a component of the 'three lines of defense' model in bank risk governance?
- Independent risk management and compliance (2nd line)
- Business units owning and managing risk (1st line)
- External auditors providing attestation (3rd line) (Correct answer)
- Internal audit providing independent assurance (3rd line)
Correct answer: External auditors providing attestation (3rd line)
The three lines of defense model positions internal audit—not external auditors—as the third line of independent assurance.
Question 74: Which approach is required by U.S. GAAP under CECL (ASC 326) that differs most significantly from the prior incurred loss model?
- Losses are recognized only when they become probable and can be reasonably estimated
- Lifetime expected credit losses are estimated and recognized at the time of loan origination (Correct answer)
- Qualitative factors are eliminated to improve comparability across institutions
- Historical charge-off rates are the sole basis for estimating credit losses
Correct answer: Lifetime expected credit losses are estimated and recognized at the time of loan origination
CECL requires banks to estimate and record expected credit losses over the entire life of a financial instrument at origination, replacing the incurred loss trigger.
Question 75: The term 'control deficiency' in bank auditing refers to a situation where:
- A control does not allow timely prevention or detection of misstatements (Correct answer)
- Management disagrees with the auditor's findings
- An internal auditor lacks sufficient training
- The bank fails to implement recommended audit findings
Correct answer: A control does not allow timely prevention or detection of misstatements
A control deficiency exists when the design or operation of a control does not allow management or employees to prevent or detect misstatements in a timely manner.
Question 76: What does the income statement primarily reflect?
- Assets and liabilities
- Changes in equity
- Cash reserves
- Profit or loss over time (Correct answer)
Correct answer: Profit or loss over time
The income statement reports revenues and expenses over a period, showing the net profit or loss.
Question 77: Which liquidity metric does Basel III's Liquidity Coverage Ratio (LCR) specifically measure?
- The ratio of liquid assets to total assets without a stress scenario
- A bank's capacity to survive a 30-day stress scenario using high-quality liquid assets (Correct answer)
- Core deposit funding as a percentage of total liabilities
- The ratio of long-term stable funding to illiquid assets over a one-year horizon
Correct answer: A bank's capacity to survive a 30-day stress scenario using high-quality liquid assets
The LCR requires banks to hold sufficient HQLA to cover projected net cash outflows over a 30-day stress scenario, ensuring short-term liquidity resilience.
Question 78: When auditing IT general controls, which area is MOST critical to assess first because weaknesses there can undermine all application controls?
- Access controls and logical security (Correct answer)
- Data center physical security
- Backup and recovery procedures
- Change management controls
Correct answer: Access controls and logical security
Access controls and logical security are foundational IT general controls; compromised access can invalidate the effectiveness of all other controls.
Question 79: A bank auditor is reviewing controls over the bank's correspondent banking relationships. Which risk is UNIQUE to correspondent banking compared to retail banking?
- Interest rate risk on deposits
- Regulatory capital requirements for interbank deposits
- Currency conversion risk
- Nested relationships that obscure the identity of underlying customers (Correct answer)
Correct answer: Nested relationships that obscure the identity of underlying customers
Nested correspondent relationships allow respondent banks to provide services to sub-correspondents whose customers remain unknown to the U.S. bank.
Question 80: A bank's governance framework should include a formal board succession plan primarily because:
- Planned transitions ensure continuity of oversight expertise and reduce governance gaps (Correct answer)
- Succession planning is only relevant for executive management, not directors
- It reduces the need to hold annual general meetings
- Regulators require the same directors to serve for at least 10 years
Correct answer: Planned transitions ensure continuity of oversight expertise and reduce governance gaps
Board succession planning ensures that critical skills and experience are retained and governance continuity is maintained when directors retire or leave.
Question 81: An auditor is reviewing a bank's deferred tax assets (DTAs). Which condition would most likely require a valuation allowance against the DTA?
- The bank has temporary differences that are expected to reverse within five years
- The bank has a history of operating losses and limited future taxable income projections (Correct answer)
- The bank recently converted from S-corporation to C-corporation status
- The bank operates in multiple states with varying corporate income tax rates
Correct answer: The bank has a history of operating losses and limited future taxable income projections
A valuation allowance is required when it is more likely than not that some or all of the DTA will not be realized, which is indicated by a history of losses and uncertain future profitability.
Question 82: In corporate governance, the 'duty of loyalty' requires bank directors to:
- Remain loyal to the bank's founding shareholders regardless of circumstances
- Prioritize the interests of the bank over personal or third-party interests (Correct answer)
- Vote in alignment with the position of the bank's largest shareholder
- Maintain confidentiality of all board discussions for 10 years
Correct answer: Prioritize the interests of the bank over personal or third-party interests
The duty of loyalty requires directors to act in the best interests of the bank, avoiding self-dealing or conflicts of interest.
Question 83: A bank's compliance audit reveals that the overdraft opt-in disclosures for ATM and one-time debit card transactions were not provided before enrollment. Which regulation is violated?
- Regulation E (Correct answer)
- Regulation DD
- Regulation Z
- Regulation CC
Correct answer: Regulation E
Regulation E (12 CFR Part 1005) requires banks to obtain affirmative opt-in consent using a specific disclosure before charging overdraft fees on ATM and one-time debit card transactions.
Question 84: A bank reports a loan-to-deposit ratio (LDR) of 115%. Which risk does this elevated ratio PRIMARILY signal?
- Excessive capital adequacy
- Liquidity risk from over-reliance on borrowed funds (Correct answer)
- Overstatement of interest income
- Understated credit loss reserves
Correct answer: Liquidity risk from over-reliance on borrowed funds
An LDR above 100% means the bank has lent out more than it holds in deposits, indicating heavy reliance on wholesale or borrowed funding and heightened liquidity risk.
Question 85: When auditing a bank's real estate collateral valuation program, the auditor must verify compliance with regulatory requirements for appraiser independence. Which of the following situations would be a violation of these independence standards?
- An external, state-certified appraiser who performed the original appraisal is engaged to perform an updated appraisal 18 months later.
- A loan officer selects an appraiser from a pre-approved list maintained by the bank's independent real estate appraisal department. (Correct answer)
- The bank uses an Appraisal Management Company (AMC) to engage appraisers for all of its residential mortgage loans.
- The bank's Chief Appraiser reports directly to the Chief Credit Officer.
Correct answer: A loan officer selects an appraiser from a pre-approved list maintained by the bank's independent real estate appraisal department.
A core principle of appraiser independence, as outlined in the Interagency Appraisal and Evaluation Guidelines, is that individuals involved in the loan production process (like loan officers) must not select, or have influence over the selection of, the person who performs the appraisal. Allowing a loan officer to select the appraiser, even from an approved list, creates a conflict of interest and impairs the required independence.
Question 86: A bank's internal audit charter should PRIMARILY document which of the following?
- A list of all findings from the prior year's audit
- The purpose, authority, responsibility, and independence of internal audit (Correct answer)
- The names and qualifications of all internal auditors
- The detailed testing procedures for each audit area
Correct answer: The purpose, authority, responsibility, and independence of internal audit
The internal audit charter formally establishes the function's mandate, defines its authority to access records and personnel, and affirms its independence.
Question 87: Under the Bank Secrecy Act (BSA), what is the minimum threshold that triggers a Currency Transaction Report (CTR) filing requirement?
- $25,000
- $5,000
- $50,000
- $10,000 (Correct answer)
Correct answer: $10,000
The BSA requires financial institutions to file a CTR for any cash transaction exceeding $10,000 in a single business day.
Question 88: Under FinCEN's Customer Due Diligence (CDD) Rule, what is required when a legal entity customer opens a new account?
- Collection of beneficial ownership information for individuals owning 25% or more (Correct answer)
- Annual credit review of the entity
- Verification of all employees of the entity
- Filing a CTR for the initial deposit
Correct answer: Collection of beneficial ownership information for individuals owning 25% or more
FinCEN's CDD Rule requires banks to identify and verify the identity of individuals who own 25% or more of a legal entity customer.
Question 89: A bank enters into interest rate swap agreements designated as fair value hedges. Under ASC 815, the audit of hedge effectiveness requires the auditor to verify:
- That the notional amount of the swap equals the bank's total deposit liabilities
- That documentation of hedging relationships was in place at hedge inception (Correct answer)
- That swap counterparties have investment-grade credit ratings from all major agencies
- That the hedging strategy was approved by both state and federal bank regulators
Correct answer: That documentation of hedging relationships was in place at hedge inception
ASC 815 requires formal hedge documentation to exist at inception, including identification of the hedged item, hedging instrument, risk being hedged, and effectiveness assessment method.
Question 90: Which of the following is the BEST indicator that a bank's account reconciliation controls are operating effectively?
- Reconciliations are completed by branch managers monthly
- Reconciliation software produces automated exception reports
- All reconciling items are researched and resolved within 30 days (Correct answer)
- The GL balance matches the prior month's balance
Correct answer: All reconciling items are researched and resolved within 30 days
Timely resolution of reconciling items demonstrates that exceptions are investigated and corrected, not just identified.
Question 91: In auditing a bank's consolidated financial statements, which variable interest entity (VIE) scenario requires consolidation by the bank?
- The bank is the primary beneficiary that absorbs the majority of a VIE's expected losses (Correct answer)
- The bank has a correspondent banking relationship with the VIE for check clearing services
- The bank's pension trust fund holds assets that exceed the projected benefit obligation
- The bank holds a passive equity interest of less than 20% in a trust preferred entity
Correct answer: The bank is the primary beneficiary that absorbs the majority of a VIE's expected losses
Under ASC 810, a VIE must be consolidated by the entity that is the primary beneficiary — the one with power over the VIE's activities and obligation to absorb losses or right to receive benefits.
Question 92: The 'three lines of defense' model assigns primary risk ownership to:
- Business line management (Correct answer)
- Internal audit
- Board of directors
- Risk management function
Correct answer: Business line management
The first line of defense consists of business line managers who own and manage risks in their day-to-day operations.
Question 93: Under OCC guidance, which of the following is considered a key attribute of an effective bank board?
- Delegating all risk decisions to the CEO
- Micromanaging daily operations to catch errors early
- Maintaining active oversight while respecting management's operational role (Correct answer)
- Limiting board meetings to once per year to reduce disruption
Correct answer: Maintaining active oversight while respecting management's operational role
The OCC expects boards to provide active, informed oversight without crossing into management's operational domain.
Question 94: A bank's IT auditor is performing a review of Information Technology General Controls (ITGCs). Which of the following areas is considered one of the four core domains of an ITGC audit?
- IT project portfolio management.
- Change management processes. (Correct answer)
- End-user satisfaction surveys.
- Application-level transaction validation.
Correct answer: Change management processes.
IT General Controls (ITGCs) are the foundational controls for the IT environment. Audits of ITGCs typically focus on four main domains: Access Management, Change Management, IT Operations, and Data/System Backup and Recovery. Change management ensures that modifications to systems are properly authorized, tested, and implemented, which is crucial for maintaining the integrity of financial reporting systems.
Question 95: Which regulatory requirement MOST directly governs a bank's obligation to return ACH debit entries originated without customer authorization?
- Regulation DD
- NACHA Operating Rules (Correct answer)
- Regulation Z
- Bank Secrecy Act
Correct answer: NACHA Operating Rules
NACHA Operating Rules establish the timeframes and procedures for returning unauthorized ACH debit entries.
Question 96: An auditor reviewing a bank's BSA program finds that the BSA Officer role has been vacant for 6 months with no documented interim assignment. This is most likely a violation of:
- FFIEC guidance on dual controls
- OFAC sanction regulations requiring dedicated compliance staff
- The BSA requirement for a designated BSA compliance officer (Correct answer)
- FinCEN's SAR filing deadlines
Correct answer: The BSA requirement for a designated BSA compliance officer
The BSA requires all financial institutions to designate a BSA compliance officer; leaving the position vacant without proper interim designation is a direct BSA program deficiency.
Question 97: Which committee is primarily responsible for overseeing a bank's financial reporting and internal controls?
- Audit Committee (Correct answer)
- Nominations Committee
- Risk Committee
- Compensation Committee
Correct answer: Audit Committee
The Audit Committee is responsible for overseeing financial reporting integrity, internal controls, and external auditor relationships.
Question 98: According to the ACFE Fraud Triangle, which three elements must all be present for occupational fraud to occur?
- Pressure, opportunity, and rationalization (Correct answer)
- Motivation, rationalization, and capability
- Greed, access, and deception
- Intent, means, and motive
Correct answer: Pressure, opportunity, and rationalization
The ACFE Fraud Triangle identifies pressure (incentive or need), opportunity (weak controls), and rationalization (personal justification) as the three necessary conditions for occupational fraud.
Question 99: When auditing a bank's patch management process, what should an auditor verify FIRST?
- The cost of patch deployment tools
- The number of IT staff responsible for patching
- The vendor support contracts for all systems
- The existence of a formal policy defining patch testing and deployment timelines (Correct answer)
Correct answer: The existence of a formal policy defining patch testing and deployment timelines
A formal patch management policy establishing testing requirements and deployment timelines is the foundational control that all other patch management activities depend on.
Question 100: A bank experiences significant losses from unauthorized trading by a single trader who concealed positions for months. Which risk framework gap MOST directly caused this failure?
- Weak market risk limits and position monitoring controls (Correct answer)
- Insufficient liquidity buffers
- Inadequate credit underwriting standards
- Inadequate anti-money laundering (AML) procedures
Correct answer: Weak market risk limits and position monitoring controls
Rogue trader events typically result from inadequate position limits, weak reconciliation controls, and insufficient independent monitoring of trading books.
Question 101: Which of the following board compositions would BEST reflect sound corporate governance at a publicly traded bank?
- Majority independent directors with diverse expertise (Correct answer)
- Majority insider directors with deep operational knowledge
- All directors drawn from the financial services industry
- Directors who are also the bank's largest shareholders
Correct answer: Majority independent directors with diverse expertise
A majority of independent directors with varied expertise reduces conflicts of interest and improves objective oversight.
Question 102: A key principle of sound corporate governance in banking is the presence of a significant number of independent directors on the board. What is the primary rationale for this requirement?
- To ensure the board is composed exclusively of individuals with prior bank CEO experience.
- To fulfill a requirement that all board members must be major shareholders of the bank.
- To reduce the number of board committees required for effective oversight.
- To provide objective judgment, challenge management's perspectives, and mitigate potential conflicts of interest. (Correct answer)
Correct answer: To provide objective judgment, challenge management's perspectives, and mitigate potential conflicts of interest.
Independent directors are crucial because their detachment from the bank's daily operations allows them to provide unbiased oversight and constructive challenges to management. This independence helps ensure that the board acts in the best interest of all stakeholders, not just management.
Question 103: A bank uses a cash flow hedge to convert a variable-rate borrowing to fixed rate. The effective portion of the hedge gain/loss is recorded in:
- Goodwill on the balance sheet
- Noninterest expense
- Other comprehensive income (AOCI) until the hedged item affects earnings (Correct answer)
- Net interest income on the income statement
Correct answer: Other comprehensive income (AOCI) until the hedged item affects earnings
Under ASC 815, the effective portion of a cash flow hedge is deferred in AOCI and reclassified into earnings when the hedged forecasted transaction (variable-rate interest payments) affects earnings.
Question 104: When auditing interest rate risk in the banking book (IRRBB), what does an EVE (Economic Value of Equity) measure capture?
- The net interest income forecast for the current fiscal year
- The bank's short-term earnings sensitivity to rate changes over the next 12 months
- The present value impact of rate shocks on the bank's entire balance sheet (Correct answer)
- The regulatory capital required under Pillar 1 for market risk
Correct answer: The present value impact of rate shocks on the bank's entire balance sheet
EVE measures the change in the economic value of all assets, liabilities, and off-balance-sheet items in response to interest rate shocks.
Question 105: What is the primary purpose of a bank's employee fraud hotline?
- To allow customers to report dissatisfaction with interest rates and fees
- To notify banking regulators directly of suspicious transaction activity
- To provide an anonymous reporting channel for employees to report suspected fraud without fear of retaliation (Correct answer)
- To collect customer feedback on the quality of digital banking services
Correct answer: To provide an anonymous reporting channel for employees to report suspected fraud without fear of retaliation
A fraud hotline gives employees and others a confidential, anonymous channel to report suspected wrongdoing, encouraging reporting by protecting the identity and employment status of those who come forward.
Question 106: Under the Community Reinvestment Act (CRA), federal regulators evaluate a bank's record of meeting credit needs in its:
- Foreign correspondent banking relationships
- Nationwide branch network
- Assessment area, typically its local communities (Correct answer)
- Wholesale banking division
Correct answer: Assessment area, typically its local communities
CRA evaluations focus on how well a bank serves the credit needs of its defined assessment area, which encompasses the communities where it operates.
Question 107: Which of the following BEST describes the primary role of a bank's Board of Directors in the institution's corporate governance framework?
- Executing the bank's day-to-day business strategy and managing departmental staff.
- Developing the detailed procedures for the bank's daily operational risk controls.
- Approving and overseeing management's implementation of the bank's strategic objectives, risk appetite, and corporate culture. (Correct answer)
- Conducting the fieldwork for internal audits of the bank's various departments and functions.
Correct answer: Approving and overseeing management's implementation of the bank's strategic objectives, risk appetite, and corporate culture.
According to the Basel Committee on Banking Supervision, the Board has the ultimate responsibility for the bank, which includes approving and overseeing management's implementation of strategic objectives, the governance framework, and corporate culture. The other options describe responsibilities of management or the internal audit function.
Question 108: The 'three lines of defense' model in banking assigns internal audit to which line?
- Fourth line — external oversight
- First line — operational management
- Third line — independent assurance (Correct answer)
- Second line — risk management and compliance
Correct answer: Third line — independent assurance
Internal audit represents the third line of defense, providing independent assurance on the effectiveness of the first two lines.
Question 109: Which federal agency serves as the primary federal regulator for national banks and federal savings associations?
- Federal Reserve Board
- Federal Deposit Insurance Corporation (FDIC)
- Office of the Comptroller of the Currency (OCC) (Correct answer)
- Consumer Financial Protection Bureau (CFPB)
Correct answer: Office of the Comptroller of the Currency (OCC)
The OCC charters, regulates, and supervises national banks and federal savings associations, serving as their primary federal prudential regulator.
Question 110: When auditing IT controls for a bank's automated clearing house (ACH) operations, which control is MOST critical to verify?
- The age of ACH processing hardware
- Dual authorization controls for ACH file releases exceeding defined dollar thresholds (Correct answer)
- The number of monitors at each ACH workstation
- The color scheme of the ACH processing dashboard
Correct answer: Dual authorization controls for ACH file releases exceeding defined dollar thresholds
Dual authorization for high-value ACH files prevents a single individual from initiating and releasing large fund transfers, mitigating fraud and error risk.
Question 111: The Chief Audit Executive (CAE) of a large commercial bank is developing the annual audit plan. Which of the following is the MOST critical first step in establishing the scope and priorities for the upcoming audit cycle?
- Meeting with the Board of Directors' Audit Committee to understand their primary concerns.
- Reviewing the findings and recommendations from the prior year's audit reports.
- Evaluating the current staffing levels and technical expertise of the internal audit department.
- Conducting a comprehensive, bank-wide risk assessment to identify and rank high-risk areas. (Correct answer)
Correct answer: Conducting a comprehensive, bank-wide risk assessment to identify and rank high-risk areas.
A risk-based approach is fundamental to modern internal auditing in banking. The initial step should be a comprehensive risk assessment to ensure that audit resources are focused on the areas that pose the greatest threat to the bank's objectives. While prior audit findings, board concerns, and staff capabilities are all important inputs, they are best considered within the context of the overall risk landscape identified by the assessment.
Question 112: Which risk management technique involves assigning probability distributions to uncertain variables to assess the range of possible outcomes?
- Gap analysis
- Monte Carlo simulation (Correct answer)
- Stress testing
- Scenario analysis
Correct answer: Monte Carlo simulation
Monte Carlo simulation uses random sampling across probability distributions to model the range of possible financial outcomes.
Question 113: Which regulatory guidance specifically addresses the audit committee's oversight responsibilities for internal controls at U.S. banks?
- SEC Regulation S-X
- FASB ASC 310 on Receivables
- Basel III Capital Accord
- OCC Handbook on Corporate and Risk Governance (Correct answer)
Correct answer: OCC Handbook on Corporate and Risk Governance
The OCC Handbook on Corporate and Risk Governance outlines expectations for board and audit committee oversight of internal controls at national banks.
Question 114: Why are exception reports important in banking operations audits?
- They track ATM usage patterns
- They automate financial forecasting
- They summarize training records
- They highlight unusual transactions (Correct answer)
Correct answer: They highlight unusual transactions
Exception reports identify irregular or unusual activities, which help auditors detect potential errors or fraud.
Question 115: How can an internal audit improve banking operations?
- By enhancing operational efficiency through recommendations (Correct answer)
- By increasing marketing spend
- By managing external partnerships
- By hiring customer service agents
Correct answer: By enhancing operational efficiency through recommendations
Audits provide insights and recommendations that strengthen internal controls, improve process efficiency, and ensure compliance.
Question 116: During a disaster recovery test, a bank's IT systems are restored but customer transaction data is missing for the last 4 hours before the declared disaster. Which metric was NOT achieved?
- Recovery Point Objective (RPO) (Correct answer)
- Mean Time to Repair (MTTR)
- System Availability SLA
- Recovery Time Objective (RTO)
Correct answer: Recovery Point Objective (RPO)
RPO defines the maximum acceptable data loss measured in time; missing 4 hours of transaction data indicates the backup frequency did not meet the defined RPO.
Question 117: When testing the effectiveness of a bank's internal control over the wire transfer approval process, which of the following audit procedures generally provides the most persuasive evidence?
- Reperforming the approval control for a selected sample of wire transfers. (Correct answer)
- Inquiring with the wire room supervisor about the approval process.
- Inspecting documented evidence of supervisory approval for a sample of transfers.
- Observing the wire transfer clerk perform their duties for one hour.
Correct answer: Reperforming the approval control for a selected sample of wire transfers.
Reperformance involves the auditor independently executing procedures or controls that were originally performed as part of the entity's internal control. It provides the highest level of assurance because the auditor is directly verifying the control's effectiveness, rather than relying on inquiry (what people say), observation (what people do when watched), or inspection (the paper trail).
Question 118: According to established auditing standards and corporate governance principles, who has the primary responsibility for establishing and maintaining an effective system of internal controls within a bank?
- The bank's management (Correct answer)
- The external auditors
- The internal audit department
- The primary federal regulator
Correct answer: The bank's management
While the board provides oversight, auditors provide independent assurance, and regulators set requirements, it is the bank's management that has the direct, primary responsibility for designing, implementing, and maintaining the institution's internal control system.
Question 119: An auditor testing the bank's official check (cashier's check) issuance process finds that voided checks are not retained or defaced. This represents a weakness in controls over:
- Check stock custody and destruction procedures (Correct answer)
- GL posting accuracy
- Stop payment processing
- Customer identity verification
Correct answer: Check stock custody and destruction procedures
Voided official check stock must be defaced and retained to prevent fraudulent re-use of pre-printed check documents.
Question 120: A bank auditor identifies that the operations division uses spreadsheets maintained by a single employee to calculate daily fee income. The BEST control recommendation is to:
- Increase the frequency of supervisory review of the spreadsheet
- Have the external auditor test the spreadsheet quarterly
- Require the employee to document all formulas in a separate manual
- Migrate fee calculations to a validated, system-based process with access controls (Correct answer)
Correct answer: Migrate fee calculations to a validated, system-based process with access controls
System-based calculations with access controls eliminate single-point-of-failure and manipulation risks inherent in end-user-maintained spreadsheets.
Question 121: A bank's IT auditor is reviewing the effectiveness of data loss prevention (DLP) controls. Which scenario represents a DLP control FAILURE?
- An alert is generated when a user accesses data outside their role
- An employee's email with an encrypted attachment is flagged for review
- A system blocks an unauthorized USB drive from copying files
- A bulk file of customer SSNs is successfully emailed to an external personal account (Correct answer)
Correct answer: A bulk file of customer SSNs is successfully emailed to an external personal account
Successfully emailing a bulk file of customer SSNs externally indicates the DLP system failed to detect and block the unauthorized exfiltration of sensitive data.
Question 122: An auditor is examining the collateral documentation for a portfolio of commercial real estate (CRE) loans. The auditor notes that for several large loans, the most recent property appraisals are over three years old. This finding represents a significant weakness in which area?
- Liquidity risk monitoring.
- Collateral risk management. (Correct answer)
- Fair lending compliance.
- Interest rate risk management.
Correct answer: Collateral risk management.
Collateral is a secondary source of repayment for CRE loans, and its value can fluctuate significantly. Relying on outdated appraisals means the bank may not have an accurate understanding of its current collateral position. If property values have declined, the loan-to-value ratio may be much higher than policy allows, indicating an unacceptably high level of credit risk due to potential under-collateralization. Regulatory guidance requires banks to have processes for obtaining current collateral valuations.
Question 123: Under COSO's Internal Control—Integrated Framework, which component involves an organization's values, ethics, and operating style?
- Information & Communication
- Monitoring Activities
- Risk Assessment
- Control Environment (Correct answer)
Correct answer: Control Environment
The Control Environment is the foundation of internal control and encompasses the organization's tone, values, ethical standards, and management philosophy.
Question 124: How does the concept of 'board information asymmetry' threaten effective bank governance?
- Directors from different backgrounds interpret information differently, causing deadlock
- Information asymmetry only matters in publicly traded banks, not private ones
- Directors receiving too much information become overly involved in operations
- Management controlling what information reaches the board can limit effective oversight (Correct answer)
Correct answer: Management controlling what information reaches the board can limit effective oversight
When management filters or selectively presents information to the board, directors cannot provide informed oversight or effective challenge.
Question 125: Which governance failure was most commonly cited as a contributing factor to the 2008 global financial crisis among major banks?
- Lack of shareholder engagement in strategic planning
- Over-diversification of loan portfolios
- Inadequate board oversight of risk-taking activities (Correct answer)
- Excessive regulatory capital buffers limiting lending
Correct answer: Inadequate board oversight of risk-taking activities
Post-crisis analyses repeatedly found that bank boards failed to understand or effectively challenge the excessive risks being taken by management.
Question 126: Under Regulation Z (Truth in Lending Act), the Annual Percentage Rate (APR) disclosure is designed to:
- Determine the bank's required loan loss reserve
- Establish the maximum interest rate allowed on consumer loans
- Calculate the bank's net interest margin
- Enable consumers to compare the true cost of credit across different lenders (Correct answer)
Correct answer: Enable consumers to compare the true cost of credit across different lenders
APR standardizes the cost of credit by expressing the interest rate and fees as a single annual rate, allowing consumers to make meaningful comparisons between loan products.
Question 127: A bank discovers its loan loss model systematically underestimates defaults during economic downturns. This is an example of:
- Operational risk
- Credit concentration risk
- Strategic risk
- Model risk (Correct answer)
Correct answer: Model risk
Model risk arises when a model produces inaccurate outputs due to flawed assumptions, errors, or misuse.
Question 128: When auditing controls over the bank's trading book, the auditor should PRIMARILY focus on which risk?
- Market risk from unauthorized or limit-exceeding trading positions (Correct answer)
- Credit risk from customer loan defaults
- Operational risk from system downtime
- Liquidity risk from deposit withdrawals
Correct answer: Market risk from unauthorized or limit-exceeding trading positions
Unauthorized trading or positions that exceed approved limits represent the primary internal control risk in the trading book, capable of causing massive sudden losses.
Question 129: In the context of managing an internal audit function, which of the following is a primary objective of a robust quality assurance and improvement program (QAIP)?
- To provide reasonable assurance that the audit function conforms with the Standards for the Professional Practice of Internal Auditing. (Correct answer)
- To ensure the audit team receives favorable performance reviews from auditees.
- To focus exclusively on identifying and disciplining underperforming audit staff members.
- To guarantee that all audits are completed within their allocated budget and timeframe.
Correct answer: To provide reasonable assurance that the audit function conforms with the Standards for the Professional Practice of Internal Auditing.
A quality assurance and improvement program (QAIP) is essential for an internal audit function to evaluate its conformance with professional standards (such as those from The Institute of Internal Auditors), assess its efficiency and effectiveness, and identify opportunities for improvement. The QAIP helps ensure the credibility and quality of the audit work performed.
Question 130: A bank director who also owns a significant stake in a vendor seeking a major contract with the bank should:
- Inform only the CEO and proceed as normal
- Disclose the conflict and recuse themselves from related discussions and votes (Correct answer)
- Vote in favor to demonstrate commitment to the bank's efficiency
- Negotiate the best deal possible given their industry knowledge
Correct answer: Disclose the conflict and recuse themselves from related discussions and votes
Disclosure and recusal are the required responses to conflicts of interest to preserve the integrity of the board's decision-making.
Question 131: Under the COSO framework, which component addresses the ongoing processes that monitor the quality of internal control performance over time?
- Risk Assessment
- Control Activities
- Information and Communication
- Monitoring Activities (Correct answer)
Correct answer: Monitoring Activities
Monitoring Activities is the COSO component focused on evaluating whether controls are present and functioning effectively on an ongoing basis.
Question 132: Which of the following scenarios BEST illustrates 'settlement risk' in banking?
- A bank pays on a foreign exchange trade but the counterparty fails to deliver before settlement completes (Correct answer)
- A borrower defaults before loan maturity
- A trading algorithm executes orders in the wrong direction
- Rising rates reduce the market value of a fixed-income portfolio
Correct answer: A bank pays on a foreign exchange trade but the counterparty fails to deliver before settlement completes
Settlement risk (Herstatt risk) arises when one party fulfills its payment obligation but the counterparty fails to deliver before final settlement.
Question 133: During the fieldwork phase of an audit of a bank's lending department, an auditor discovers that a loan officer has been overriding system-based credit controls for several high-value loans without documented approval. What is the auditor's immediate responsibility?
- Document the finding and escalate it to the in-charge auditor or audit manager for further review. (Correct answer)
- Discontinue the audit of the lending department until management resolves the issue.
- Include the finding in the final audit report to be presented to the audit committee.
- Confront the loan officer directly to request an explanation for the overrides.
Correct answer: Document the finding and escalate it to the in-charge auditor or audit manager for further review.
Standard audit procedures require that significant findings or potential irregularities discovered during fieldwork be properly documented and escalated to audit management promptly. This ensures the issue is addressed at the appropriate level, allows for a coordinated response (which may include expanding the audit scope), and maintains the objectivity of the audit process. Confronting the individual directly or waiting until the final report could compromise the investigation and allow the issue to persist.
Question 134: In evaluating the design adequacy of a control, an auditor is assessing whether:
- The control, if operating as intended, would effectively mitigate the risk (Correct answer)
- Management has documented the control in written policies
- Employees have been trained on how to perform the control
- The control has been operating consistently for at least one year
Correct answer: The control, if operating as intended, would effectively mitigate the risk
Design adequacy assesses whether a control is theoretically capable of preventing or detecting a misstatement or risk if it operates as intended.
Question 135: Which of the following is a primary objective of auditing IT General Controls (ITGCs) within a financial institution?
- To provide reasonable assurance that the overall IT control environment is effective and supports the reliability of application controls. (Correct answer)
- To test the effectiveness of the bank's marketing campaigns on social media platforms.
- To ensure the accuracy of specific calculations within a loan amortization application.
- To verify that all employees have completed annual cybersecurity training.
Correct answer: To provide reasonable assurance that the overall IT control environment is effective and supports the reliability of application controls.
ITGCs form the foundation of the IT control structure. They are the policies and procedures that apply to all or a large segment of the institution's information systems and help ensure their continued, proper operation. A strong ITGC environment is necessary for application controls (which are specific to individual software) to be effective and reliable. Auditing ITGCs addresses the framework within which applications and data are managed.
Question 136: Which AML red flag is most indicative of 'structuring' (smurfing) activity?
- Frequent currency exchanges between dollars and euros
- Multiple cash deposits just below $10,000 made on consecutive days (Correct answer)
- A customer making a single large wire transfer to a foreign bank
- A business account receiving payroll direct deposits from many employers
Correct answer: Multiple cash deposits just below $10,000 made on consecutive days
Structuring involves deliberately breaking up transactions to stay below the $10,000 CTR reporting threshold, often on consecutive days.
Question 137: Which of the following is typically reviewed during a banking operations audit?
- Marketing email campaigns
- Transaction processing systems (Correct answer)
- Loan advertisements
- Customer reward programs
Correct answer: Transaction processing systems
Transaction processing systems are a core focus, as auditors assess their accuracy, timeliness, and control mechanisms.
Question 138: When evaluating a bank's Pillar 2 Internal Capital Adequacy Assessment Process (ICAAP), auditors should assess whether:
- All material risks, including those not captured in Pillar 1, are identified and capitalized (Correct answer)
- The ICAAP is prepared solely by the finance department
- Stress testing is excluded to avoid overstating capital needs
- Capital calculations strictly mirror Pillar 1 standardized approach outputs
Correct answer: All material risks, including those not captured in Pillar 1, are identified and capitalized
ICAAP must capture all material risks including Pillar 2 risks such as concentration risk, IRRBB, and strategic risk that are not fully addressed in Pillar 1.
Question 139: A bank's Risk Appetite Statement (RAS) should be:
- Treated as confidential and not shared with regulators
- Approved by the board and clearly linked to the bank's strategic plan (Correct answer)
- Drafted exclusively by the Chief Risk Officer without board input
- Updated only when a significant loss event occurs
Correct answer: Approved by the board and clearly linked to the bank's strategic plan
Best practice requires the board to approve the RAS and ensure it is integrated with strategy, capital planning, and compensation.
Question 140: What is the MOST significant limitation of relying solely on preventive controls in a bank's internal control framework?
- They are too expensive to implement
- They cannot detect errors or fraud that circumvent or override the prevention mechanism (Correct answer)
- They require more technology than detective controls
- They are not recognized under COSO standards
Correct answer: They cannot detect errors or fraud that circumvent or override the prevention mechanism
Preventive controls reduce the likelihood of errors or fraud occurring, but detective controls are also needed to identify issues that bypass preventive measures.
Question 141: Under the Basel Committee's corporate governance principles, the board of directors is responsible for:
- Approving all individual loan decisions
- Day-to-day operational management
- Conducting internal audits independently
- Setting the bank's risk appetite and overseeing senior management (Correct answer)
Correct answer: Setting the bank's risk appetite and overseeing senior management
The Basel Committee assigns the board responsibility for setting risk appetite and providing effective oversight of senior management.
Question 142: Which of the following best describes the role of 'shadow directors' in bank governance risk?
- Individuals who exercise board-level influence without formal appointment, potentially avoiding accountability (Correct answer)
- Directors who serve on subsidiary boards but not the parent board
- Non-executive directors who observe but do not vote at board meetings
- External auditors who shadow the board to assess governance quality
Correct answer: Individuals who exercise board-level influence without formal appointment, potentially avoiding accountability
Shadow directors exert control over a bank without formal director status, creating accountability gaps and potential governance failures.
Question 143: Which of the following scenarios MOST represents a breakdown in the governance oversight of a bank's compliance function?
- The board receives a quarterly compliance risk report and asks clarifying questions
- An independent compliance testing team identifies and escalates control gaps
- The board's audit committee reviews the annual compliance plan and budget
- The Chief Compliance Officer reports solely to the CEO with no direct access to the board (Correct answer)
Correct answer: The Chief Compliance Officer reports solely to the CEO with no direct access to the board
When the CCO lacks direct board access and reports only to the CEO, management can suppress or filter compliance findings, undermining independent oversight.
Question 144: Which of the following is the primary objective of a compliance audit focused on the Community Reinvestment Act (CRA)?
- To verify that the bank is not engaging in predatory lending practices in any of its operating areas.
- To ensure the bank has adequate controls to prevent money laundering and terrorist financing.
- To confirm the accuracy and timeliness of the bank's quarterly financial reports to shareholders.
- To assess whether the bank is effectively meeting the credit needs of its entire community, including low- and moderate-income neighborhoods. (Correct answer)
Correct answer: To assess whether the bank is effectively meeting the credit needs of its entire community, including low- and moderate-income neighborhoods.
The Community Reinvestment Act (CRA) was enacted to encourage federally insured banks to meet the credit needs of their entire communities, with a particular focus on low- and moderate-income (LMI) neighborhoods. A CRA audit evaluates the bank's performance in lending, investments, and services within these communities.
Question 145: Value at Risk (VaR) is a widely used metric for measuring market risk. A bank calculates that its trading portfolio has a one-day VaR of $5 million at a 99% confidence level. What is the correct interpretation of this result?
- There is a 99% probability that the portfolio's losses will not exceed $5 million on any given day. (Correct answer)
- The portfolio is guaranteed to not lose more than $5 million in one day.
- The absolute maximum possible loss for the portfolio is $5 million.
- There is a 1% chance that the portfolio will gain more than $5 million in one day.
Correct answer: There is a 99% probability that the portfolio's losses will not exceed $5 million on any given day.
Value at Risk (VaR) estimates the potential loss in value of a portfolio over a defined period for a given confidence interval. A one-day, 99% VaR of $5 million means that there is a 99% chance that the portfolio's losses will be less than or equal to $5 million over the next day under normal market conditions. Conversely, it implies there is a 1% chance that the losses could exceed $5 million.
Question 146: Which type of risk is associated with borrower default?
- Reputation risk
- Operational risk
- Liquidity risk
- Credit risk (Correct answer)
Correct answer: Credit risk
Credit risk refers to the possibility that a borrower may fail to fulfill financial obligations, impacting the lender's earnings.
Question 147: According to regulatory guidance, an effective Compliance Management System (CMS) is built upon several key pillars. Which of the following is considered the foundational component that establishes the 'tone at the top' for compliance?
- The selection of third-party compliance software.
- Board and management oversight. (Correct answer)
- A detailed schedule for compliance training.
- Comprehensive consumer complaint response procedures.
Correct answer: Board and management oversight.
Regulators consistently identify active and engaged board and management oversight as the cornerstone of an effective CMS. This includes demonstrating a clear commitment to compliance, adopting relevant policies, appointing a qualified compliance officer, and allocating sufficient resources to the compliance function.
Question 148: In an audit of a bank's data governance program, which of the following findings would represent the MOST significant weakness?
- The data classification policy has not been reviewed by the legal department.
- A complete data lineage for a non-critical marketing report cannot be produced.
- There is a lack of clearly defined ownership and stewardship for critical data elements. (Correct answer)
- The bank has not yet adopted the latest version of its data analytics software.
Correct answer: There is a lack of clearly defined ownership and stewardship for critical data elements.
A fundamental principle of effective data governance is accountability, which is established through clear ownership and stewardship roles. Without defined owners for critical data elements (e.g., customer information, transaction records), there is no clear responsibility for data quality, integrity, and security, leading to increased risk of data breaches, poor decision-making, and regulatory non-compliance.
Question 149: A bank auditor performing a credit review should focus on the 'five Cs of credit.' Which of the following is NOT one of the five Cs?
- Character
- Capacity
- Collateral
- Compliance (Correct answer)
Correct answer: Compliance
The five Cs of credit are Character, Capacity, Capital, Collateral, and Conditions—Compliance is not among them.
Question 150: An IT auditor is reviewing a bank's change management process for its core banking system. Which of the following represents the MOST significant control weakness?
- The same developer who codes a change is responsible for deploying it into the production environment. (Correct answer)
- Change requests are documented using a paper-based form before being entered into the tracking system.
- End-user testing is performed in a dedicated test environment but not by the original requester.
- Emergency changes are verbally approved and documented retrospectively within five business days.
Correct answer: The same developer who codes a change is responsible for deploying it into the production environment.
The most significant weakness is the lack of segregation of duties. A developer having the ability to both write and deploy code to production creates a risk of unauthorized or untested changes, potentially leading to fraud, data integrity issues, or system failure. The other options, while not ideal, represent lesser risks. Paper forms are an inefficiency, not a critical control failure. Testing by someone other than the requester can be acceptable. Documenting emergency changes retrospectively is a common practice, provided the initial approval is timely and the process is well-controlled.
Question 151: When auditing a bank's allowance for loan and lease losses (ALLL), which methodology is most consistent with GAAP?
- Incurred loss model based on historical loss rates and qualitative factors (Correct answer)
- Mark-to-market valuation of all loans quarterly
- Expected loss model projecting lifetime credit losses at origination
- Specific identification only for non-performing loans
Correct answer: Incurred loss model based on historical loss rates and qualitative factors
Under legacy GAAP (pre-CECL), the ALLL is estimated using the incurred loss model, incorporating historical loss experience and qualitative adjustments.
Question 152: During an audit of a bank holding company, the auditor discovers an intercompany loan between the parent and a subsidiary at a below-market interest rate. The primary audit concern is:
- Whether the loan violates Regulation W restrictions on affiliate transactions
- Whether the loan is properly eliminated in consolidation
- Whether the subsidiary has recorded appropriate interest income on its books
- Whether the transaction requires related party disclosure and arm's length consideration (Correct answer)
Correct answer: Whether the transaction requires related party disclosure and arm's length consideration
Below-market intercompany loans require disclosure as related party transactions, and auditors must assess whether they were conducted on arm's-length terms.
Question 153: A bank's compliance audit reveals that its flood insurance procedures do not include force-placing flood insurance within the required timeframe after a borrower's lapse in coverage. Under the Flood Disaster Protection Act, what is the required force-placement timeframe?
- 90 days after the borrower is notified
- 45 days after sending notice of lapse (Correct answer)
- 30 days after sending an initial notice of lapse
- 60 days after the policy expiration date
Correct answer: 45 days after sending notice of lapse
The Flood Disaster Protection Act requires lenders to force-place flood insurance if the borrower fails to obtain coverage within 45 days of the initial notice.
Question 154: An auditor identifies that a bank's fraud detection system generates a large number of false-positive alerts, consuming significant compliance staff time. The BEST course of action is to recommend:
- Tuning the detection models using validated data to reduce false positives while maintaining detection efficacy (Correct answer)
- Hiring additional staff to review all alerts regardless of system performance
- Eliminating the fraud detection system to improve efficiency
- Lowering the alert threshold so fewer transactions are flagged
Correct answer: Tuning the detection models using validated data to reduce false positives while maintaining detection efficacy
Tuning detection models to reduce false positives while preserving genuine threat detection optimizes both compliance effectiveness and operational efficiency.
Question 155: Which type of bank fraud involves an employee creating fictitious loans to generate fraudulent commissions or misappropriate proceeds?
- Check kiting
- Embezzlement through payroll manipulation
- Identity theft
- Loan origination fraud (Correct answer)
Correct answer: Loan origination fraud
Loan origination fraud occurs when employees create fictitious or unsupported loans to earn commissions or divert loan proceeds for personal gain.
Question 156: A bank auditor finds that the operations center processes end-of-day batch jobs without a documented run book or operator instructions. The PRIMARY concern is:
- Increased hardware maintenance costs
- Failure to meet customer service level agreements
- Inability to recover consistently from processing errors or abends (Correct answer)
- Non-compliance with data retention schedules
Correct answer: Inability to recover consistently from processing errors or abends
Without documented run books, operators cannot consistently restart or recover failed jobs, creating operational continuity risk.
Question 157: When a bank's external auditor is also providing significant consulting services, this raises a concern about:
- Auditor independence and objectivity (Correct answer)
- The bank's liquidity coverage ratio
- Regulatory capital adequacy
- Dividend payout ratios
Correct answer: Auditor independence and objectivity
Providing consulting services alongside audit work creates a financial dependency that can compromise the auditor's independence.
Question 158: A compliance auditor reviewing Regulation CC (Availability of Funds) finds that a bank places a 7-business-day hold on all local checks. What is the likely violation?
- The hold period is compliant if the customer signed a funds availability disclosure
- Regulation CC requires local checks to be made available no later than the second business day after deposit (Correct answer)
- A 7-day hold is permissible for checks over $5,000 regardless of check type
- Local checks are exempt from Regulation CC hold requirements
Correct answer: Regulation CC requires local checks to be made available no later than the second business day after deposit
Regulation CC generally requires local checks to be available by the second business day following deposit, making a blanket 7-day hold a violation.
Question 159: Which of the following is a required communication from the external auditor to the bank's audit committee?
- An overview of the planned scope and timing of the audit, including significant risks identified. (Correct answer)
- Management's confidential performance reviews for key finance personnel.
- A comparative analysis of the bank's performance against its primary competitors.
- The detailed daily schedule and staff assignments for the audit fieldwork.
Correct answer: An overview of the planned scope and timing of the audit, including significant risks identified.
Auditing standards (such as PCAOB AS 1301) require auditors to communicate an overview of the overall audit strategy to the audit committee. This includes the planned scope, the timing of the audit, and a discussion of the significant risks that were identified during the risk assessment process. This communication ensures the audit committee has proper oversight of the audit process.
Question 160: Counterparty credit risk in derivatives is BEST described as:
- The risk of loss from an issuer defaulting on a bond
- The risk of settlement system failure
- The risk that the other party to a derivative contract defaults before final settlement (Correct answer)
- The risk that market prices move adversely
Correct answer: The risk that the other party to a derivative contract defaults before final settlement
Counterparty credit risk is the possibility that a derivative counterparty will default before the contract's obligations are fulfilled.
Question 161: During an audit of logical access controls for the bank's wire transfer system, which of the following conditions would be of GREATEST concern to a Certified Bank Auditor?
- A former employee's access was revoked two business days after their termination date.
- The system does not enforce a minimum password length of 12 characters.
- Shared, generic user accounts are used by the treasury department for end-of-day processing. (Correct answer)
- Access reviews are conducted semi-annually by department managers instead of quarterly.
Correct answer: Shared, generic user accounts are used by the treasury department for end-of-day processing.
The use of shared or generic accounts is the most significant concern because it eliminates individual accountability. If a fraudulent transaction occurs, it becomes impossible to trace the action to a specific person. This undermines non-repudiation and makes investigation extremely difficult. While delayed termination, weak password policies, and less frequent access reviews are all control weaknesses, the inability to hold individuals accountable for their actions poses a more severe and direct risk to the institution.
Question 162: Which federal law prohibits discriminatory credit practices based on race, color, religion, national origin, sex, marital status, or age?
- Community Reinvestment Act
- Equal Credit Opportunity Act (ECOA) (Correct answer)
- Fair Housing Act
- Home Mortgage Disclosure Act (HMDA)
Correct answer: Equal Credit Opportunity Act (ECOA)
ECOA (Regulation B) prohibits creditors from discriminating against applicants based on protected characteristics, including race, sex, religion, national origin, and age.
Question 163: What is 'say-on-pay' in the context of bank corporate governance?
- A regulator's right to cap banker bonuses
- A shareholder vote on executive compensation packages (Correct answer)
- The board's power to approve compensation plans
- The CEO's authority to set compensation for direct reports
Correct answer: A shareholder vote on executive compensation packages
Say-on-pay gives shareholders an advisory or binding vote on executive compensation, enhancing board accountability.
Question 164: According to ACFE Occupational Fraud studies, what is the most common category of fraud committed against financial institutions?
- Asset misappropriation (Correct answer)
- Corruption and bribery schemes
- Financial statement fraud
- Cyber-enabled fraud
Correct answer: Asset misappropriation
Asset misappropriation — which includes theft of cash, checks, inventory, and other assets — is consistently the most common category of occupational fraud, accounting for the vast majority of reported cases.
Question 165: A bank auditor reviewing ATM operations finds that ATM cassette loading is performed by a single technician with no witness present. Which risk does this control gap MOST directly create?
- Cash skimming or misappropriation (Correct answer)
- Network connectivity loss
- System downtime risk
- Regulatory reporting failures
Correct answer: Cash skimming or misappropriation
Without a witness during cassette loading, a single technician can pocket cash without detection, creating a theft risk.
Question 166: A Certified Bank Auditor is planning an audit of the bank's cybersecurity incident response plan. Which audit test would BEST assess the plan's practical effectiveness?
- Reviewing the results and lessons learned from a recent tabletop exercise or simulation drill. (Correct answer)
- Ensuring the plan is stored in a secure, access-controlled location both on-site and off-site.
- Confirming the plan has been reviewed and approved by the Board of Directors within the last year.
- Verifying that the plan includes an up-to-date contact list for all incident response team members.
Correct answer: Reviewing the results and lessons learned from a recent tabletop exercise or simulation drill.
While plan approval, accurate contact lists, and secure storage are important compliance checks, the best way to assess the *effectiveness* of an incident response plan is to see how it performs in practice. Reviewing the outcomes of a tabletop exercise or a full simulation drill provides concrete evidence of the team's preparedness, identifies gaps in the plan, and demonstrates the bank's ability to respond to an actual incident.
Question 167: In the context of bank governance, 'constructive challenge' by board members refers to:
- Directors filing formal legal objections to management proposals
- Challenging regulatory requirements in court proceedings
- Active, critical questioning of management's assumptions and proposals without being adversarial (Correct answer)
- Directors voting against all management resolutions as a default position
Correct answer: Active, critical questioning of management's assumptions and proposals without being adversarial
Constructive challenge means directors critically evaluate management information and proposals to improve decisions without undermining collaboration.
Question 168: A bank auditor reviewing credit concentration risk should MOST likely focus on:
- Foreign exchange hedging positions
- Large exposures to single borrowers or correlated sectors (Correct answer)
- Trading book mark-to-market losses
- Intraday liquidity positions
Correct answer: Large exposures to single borrowers or correlated sectors
Credit concentration risk is the exposure to large individual borrowers or highly correlated borrower groups that can cause significant loss.
Question 169: Which of the following is an example of a key risk indicator (KRI) for cybersecurity risk?
- Percentage of systems with overdue critical patch deployments (Correct answer)
- Annual budget variance for the information security department
- Number of new customer accounts opened per month
- Total IT department headcount relative to prior year
Correct answer: Percentage of systems with overdue critical patch deployments
The percentage of systems with unpatched critical vulnerabilities is a forward-looking KRI that signals elevated cyber risk before an incident occurs.
Question 170: An auditor discovers that a bank's model risk management controls lack independent validation for a credit scoring model. Under which regulatory guidance is this deficiency evaluated?
- SR 11-7 / OCC 2011-12 on Model Risk Management (Correct answer)
- Basel II Pillar 2 supervisory review
- COSO Enterprise Risk Management Framework
- FFIEC IT Examination Handbook
Correct answer: SR 11-7 / OCC 2011-12 on Model Risk Management
SR 11-7 (Federal Reserve) and OCC 2011-12 provide the U.S. supervisory guidance on model risk management, including requirements for independent model validation.
Question 171: Which compliance program element is considered the MOST critical for ensuring a bank's BSA/AML program is effective according to the four pillars?
- Independent testing and auditing
- Customer identification procedures
- Designation of a BSA Compliance Officer (Correct answer)
- Filing of SARs and CTRs
Correct answer: Designation of a BSA Compliance Officer
Designation of a qualified BSA Compliance Officer is one of the four pillars of an effective BSA/AML program and is essential for program oversight and accountability.
Question 172: Which fraud scheme involves a bank insider approving credit to related parties on preferential terms not available to the general public?
- Identity theft and account takeover
- Phishing and credential harvesting
- Self-dealing or insider abuse of position (Correct answer)
- Check kiting through affiliated accounts
Correct answer: Self-dealing or insider abuse of position
Self-dealing or insider abuse occurs when bank employees use their position to extend credit, waive fees, or provide other benefits to themselves or related parties on terms unavailable to ordinary customers.
Question 173: Which of the following best describes 'structured transactions' (structuring) as it relates to BSA compliance audits?
- Breaking large cash transactions into smaller amounts to evade CTR reporting (Correct answer)
- Bundling small loans into a single large credit facility
- Organizing transactions by account type in the general ledger
- Routing wire transfers through multiple correspondent banks
Correct answer: Breaking large cash transactions into smaller amounts to evade CTR reporting
Structuring is the illegal practice of breaking transactions into amounts below $10,000 specifically to avoid Currency Transaction Report filing.
Question 174: During an audit of regulatory capital disclosures, an auditor finds that a bank has included certain instruments as Tier 2 capital. Which characteristic would disqualify an instrument from Tier 2 capital under Basel III?
- The instrument is subordinated to depositors and general creditors
- The instrument was issued with a below-market coupon rate at time of issuance
- The instrument has a fixed maturity date of more than five years
- The instrument contains a call option exercisable by the bank within the first five years (Correct answer)
Correct answer: The instrument contains a call option exercisable by the bank within the first five years
Tier 2 capital instruments must not contain incentives to redeem early; a call option exercisable within the first five years creates an effective maturity that disqualifies the instrument.
Question 175: The principle of 'tone at the top' in bank governance refers to:
- The volume level of board meetings
- Capital buffers held above regulatory minimums
- Senior leadership's demonstrated commitment to ethical standards and compliance (Correct answer)
- Marketing messages directed at top-tier customers
Correct answer: Senior leadership's demonstrated commitment to ethical standards and compliance
Tone at the top describes how senior leaders' behaviors and values shape the overall ethical culture and compliance environment of the institution.
Question 176: Board effectiveness evaluations in banks are conducted primarily to:
- Identify gaps in board performance, composition, and skills (Correct answer)
- Determine individual director compensation adjustments
- Comply with SEC Form 10-K reporting requirements
- Satisfy external auditor requests for evidence of board activity
Correct answer: Identify gaps in board performance, composition, and skills
Board effectiveness evaluations help identify areas for improvement in how the board functions, its skillset, and its collective performance.
Question 177: A bank's net interest margin (NIM) declines when interest rates rise unexpectedly. This is an example of which risk?
- Interest rate risk in the banking book (IRRBB) (Correct answer)
- Credit risk
- Operational risk
- Liquidity risk
Correct answer: Interest rate risk in the banking book (IRRBB)
IRRBB captures the adverse impact of interest rate movements on a bank's net interest income and economic value.
Question 178: A bank outsources its data center operations. Under OCC guidance, who retains ULTIMATE responsibility for the security of customer data?
- The outsourced data center vendor
- The data center's insurance provider
- The Federal Reserve
- The bank itself (Correct answer)
Correct answer: The bank itself
OCC guidance makes clear that banks cannot outsource their regulatory responsibilities — the bank retains ultimate accountability for data security even when operations are outsourced.
Question 179: Which audit procedure is most effective for detecting unrecorded deposit liabilities at a bank?
- Comparing current year deposit totals to prior year for unusual fluctuations
- Reviewing interest expense recorded for reasonableness relative to average deposits (Correct answer)
- Confirming large deposit balances with customers directly
- Tracing deposits from the general ledger to supporting documentation
Correct answer: Reviewing interest expense recorded for reasonableness relative to average deposits
Analytical review of interest expense relative to average deposit balances can reveal if deposits are understated because understated liabilities produce lower-than-expected interest expense.
Question 180: Under the Truth in Lending Act (TILA), Regulation Z requires lenders to disclose the Annual Percentage Rate (APR) primarily to:
- Determine HMDA reportability of the transaction
- Calculate the lender's profitability on the loan
- Satisfy capital adequacy requirements
- Allow borrowers to compare credit costs across different loan products (Correct answer)
Correct answer: Allow borrowers to compare credit costs across different loan products
TILA's APR disclosure is designed to give borrowers a standardized cost metric so they can meaningfully compare the true cost of credit across different lenders and products.
Question 181: During a business continuity audit, an IT auditor reviews a bank's Recovery Time Objective (RTO). What does the RTO define?
- The maximum tolerable downtime before a system must be restored (Correct answer)
- The minimum time required to perform a backup
- The frequency of disaster recovery testing
- The maximum acceptable data loss measured in time
Correct answer: The maximum tolerable downtime before a system must be restored
RTO defines the maximum acceptable period of time that a business process can be offline before the impact becomes unacceptable to the organization.
Question 182: When auditing a bank's mortgage servicing rights (MSRs), which valuation input most significantly affects the fair value estimate?
- The geographic concentration of properties in the serviced loan portfolio
- Prepayment speed assumptions based on current interest rate environment (Correct answer)
- The contractual servicing fee rate specified in the servicing agreement
- The credit quality of the underlying borrowers in the serviced portfolio
Correct answer: Prepayment speed assumptions based on current interest rate environment
Prepayment speed assumptions are the most sensitive input in MSR valuation because faster prepayments shorten the servicing period and reduce the asset's value.
Question 183: Under the Dodd-Frank Act, bank holding companies with total consolidated assets of $50 billion or more are required to submit annual capital plans to which regulator?
- Federal Reserve (Correct answer)
- CFPB
- FDIC
- OCC
Correct answer: Federal Reserve
The Federal Reserve administers the Comprehensive Capital Analysis and Review (CCAR) process, requiring large BHCs to submit annual capital plans.
Question 184: An internal auditor is reviewing the minutes of the bank's Audit Committee meetings. Which of the following topics would the auditor LEAST expect to be a primary focus of this committee's discussions?
- The review of significant findings from recent internal audits.
- The performance and independence of the external auditors.
- The adequacy of the bank's internal controls over financial reporting.
- The approval of the bank's new marketing and brand strategy. (Correct answer)
Correct answer: The approval of the bank's new marketing and brand strategy.
The Audit Committee's primary duties involve oversight of financial reporting, internal controls, and the internal and external audit functions. Developing and approving a marketing strategy is a management responsibility related to business strategy, not a core governance oversight function of the Audit Committee.
Question 185: An internal auditor discovers that a bank's reconciliation process for a correspondent bank account, which has a material balance, was not performed for three consecutive months due to employee turnover. This failure means that a material misstatement of the financial statements would not be detected in a timely manner. How should this control failure be classified?
- An acceptable operational risk.
- A standard control deficiency.
- A material weakness. (Correct answer)
- A significant deficiency.
Correct answer: A material weakness.
A material weakness is a deficiency, or a combination of deficiencies, in internal control over financial reporting, such that there is a reasonable possibility that a material misstatement of the entity's financial statements will not be prevented, or detected and corrected, on a timely basis. The failure to reconcile a material account for an extended period directly fits this definition.
Question 186: Which of the following best describes the purpose of a bank's Risk Committee at the board level?
- To conduct internal audits of the risk management department
- To provide oversight of the bank's overall risk profile, risk appetite, and risk management framework (Correct answer)
- To manage day-to-day operational risk incidents
- To approve all individual loan transactions above a set threshold
Correct answer: To provide oversight of the bank's overall risk profile, risk appetite, and risk management framework
The Board Risk Committee provides governance-level oversight of the bank's aggregate risk profile and ensures the risk management framework is appropriate and effective.
Question 187: A bank's risk appetite statement should primarily be approved and owned by which group?
- Board of directors (Correct answer)
- Internal audit committee
- External auditors
- Chief Risk Officer alone
Correct answer: Board of directors
The board of directors is responsible for approving and owning the bank's risk appetite statement as part of its governance obligations.
Question 188: Which department typically oversees enterprise risk management in a bank?
- Customer service department
- Human resources department
- Compliance department
- Risk management department (Correct answer)
Correct answer: Risk management department
The risk management department is responsible for identifying and controlling risks across the entire organization.
Question 189: During the planning phase of an audit of a bank's lending function, the Certified Bank Auditor identifies a new, complex commercial loan product that was recently introduced. Which of the following is the most appropriate initial step?
- Request that management provide a separate, formal assertion about the control effectiveness for the new product.
- Proceed with the original audit plan, as the new product is not yet material to the overall portfolio.
- Immediately expand the audit scope to include a 100% review of all new loan product transactions.
- Perform a preliminary risk assessment of the new product to understand its processes, inherent risks, and associated controls. (Correct answer)
Correct answer: Perform a preliminary risk assessment of the new product to understand its processes, inherent risks, and associated controls.
When encountering new products or significant changes, the auditor's first step is to understand the associated risks. A preliminary risk assessment is crucial for identifying the inherent risks, evaluating the design of internal controls, and determining the appropriate nature, timing, and extent of audit procedures needed. This step informs the rest of the audit plan.
Question 190: How does executive compensation structure relate to bank governance and risk management?
- Compensation has no material impact on risk-taking behavior
- Regulators do not have authority to comment on compensation practices
- High fixed salaries always lead to better risk management outcomes
- Short-term bonus incentives can encourage excessive risk-taking misaligned with long-term stability (Correct answer)
Correct answer: Short-term bonus incentives can encourage excessive risk-taking misaligned with long-term stability
Poorly structured compensation that rewards short-term profits can incentivize excessive risk-taking, a key governance and systemic risk concern.
Question 191: A bank's internal audit function discovers that management has implemented a compensating control to address a control weakness. The auditor should:
- Remove the finding from the audit report entirely
- Require the bank to implement the originally recommended control instead
- Evaluate whether the compensating control is effective enough to adequately mitigate the residual risk (Correct answer)
- Automatically downgrade the finding severity since a compensating control exists
Correct answer: Evaluate whether the compensating control is effective enough to adequately mitigate the residual risk
Auditors must assess whether compensating controls actually reduce risk to an acceptable level before adjusting finding severity or closing the issue.
Question 192: A bank's internal audit team discovers that the compliance department has not updated its BSA/AML policies since a major regulatory change 18 months ago. Which corrective action is MOST appropriate?
- Escalate directly to FinCEN without board involvement
- Close the finding as immaterial since no violations were detected
- Issue a management letter requiring immediate policy updates and re-training (Correct answer)
- File a SAR reporting the compliance department's inaction
Correct answer: Issue a management letter requiring immediate policy updates and re-training
The appropriate corrective action is to issue a management letter or finding requiring the compliance department to update policies promptly and conduct staff retraining to address the gap.
Question 193: A bank auditor reviewing the Net Stable Funding Ratio (NSFR) finds the ratio at 98%. What action is required?
- Immediate remediation; the NSFR minimum requirement of 100% is not met (Correct answer)
- The ratio is acceptable because it is within 5% of the 100% target
- Disclosure to shareholders only; no regulatory reporting is triggered
- No action; 98% exceeds the minimum 90% threshold
Correct answer: Immediate remediation; the NSFR minimum requirement of 100% is not met
The Basel III NSFR must be at least 100% at all times; a ratio below 100% indicates insufficient stable funding relative to required stable funding.
Question 194: During an audit of closed-end mortgage loans, an auditor notes that a borrower's final Closing Disclosure showed an Annual Percentage Rate (APR) that was 0.15% higher than the APR on the initial Loan Estimate. The loan was closed without issuing a revised disclosure and providing a new three-day waiting period. This practice is most likely a violation of which consumer protection regulation?
- Regulation E (Electronic Fund Transfer Act)
- Regulation B (Equal Credit Opportunity Act)
- Regulation Z (Truth in Lending Act) (Correct answer)
- The Community Reinvestment Act (CRA)
Correct answer: Regulation Z (Truth in Lending Act)
Regulation Z, which implements the Truth in Lending Act (TILA), has strict rules regarding the accuracy of the APR. For most fixed-rate mortgage transactions, if the APR at closing varies from the most recent disclosure by more than 1/8 of 1 percent (0.125%), the lender must provide a corrected disclosure and a new three-day waiting period before consummation.
Question 195: An auditor reviewing a bank's daily cash transaction logs notices a commercial customer, who owns a chain of convenience stores, has multiple employees making separate cash deposits of $9,500 at different branches on the same day. This pattern is a significant red flag for which potential regulatory violation?
- Inadequate segregation of duties in cash handling.
- Failure to perform adequate OFAC screening on new employees.
- Structuring transactions to evade Currency Transaction Report (CTR) filing requirements. (Correct answer)
- A violation of the Expedited Funds Availability Act (Regulation CC).
Correct answer: Structuring transactions to evade Currency Transaction Report (CTR) filing requirements.
The Bank Secrecy Act (BSA) requires banks to file a Currency Transaction Report (CTR) for cash transactions exceeding $10,000. Structuring is the illegal practice of breaking down a single large transaction into multiple smaller ones to avoid triggering this reporting threshold. The described pattern is a classic example of structuring.
Question 196: Under BSA regulations, a Currency Transaction Report (CTR) must be filed for cash transactions exceeding what threshold?
- $5,000
- $10,000 (Correct answer)
- $50,000
- $25,000
Correct answer: $10,000
Financial institutions must file a CTR with FinCEN for any cash transaction exceeding $10,000 in a single business day.
Question 197: In the context of the 'Three Lines of Defense' model for risk management in a bank, which function serves as the third line?
- The internal audit function. (Correct answer)
- Business unit management and process owners.
- The board of directors and its committees.
- The independent risk management and compliance functions.
Correct answer: The internal audit function.
In the Three Lines of Defense model, the first line is business operations management, which owns and manages risk. The second line includes the risk management and compliance functions that provide oversight. The third line is the internal audit function, which provides independent and objective assurance on the effectiveness of governance, risk management, and internal controls to the board and senior management.
Question 198: Under the Basel III framework, which pillar is specifically focused on enhancing market discipline through effective disclosure of risk management practices and capital adequacy to the public?
- Pillar 3 (Correct answer)
- Pillar 2
- Pillar 1
- Pillar 4
Correct answer: Pillar 3
The Basel III framework is structured around three pillars. Pillar 3 is dedicated to market discipline. It aims to increase transparency by requiring banks to publish a range of disclosures on their risks, capital, and risk management policies. This allows market participants to better assess a bank's risk profile and capital adequacy.
Question 199: During an audit of ACH operations, an auditor finds the bank lacks a formal return item monitoring process. The PRIMARY exposure is:
- Non-compliance with Check 21 requirements
- Violation of NACHA rules and potential financial loss from undetected unauthorized debits (Correct answer)
- Increased cost of funds
- Failure to meet Regulation E disclosure timelines
Correct answer: Violation of NACHA rules and potential financial loss from undetected unauthorized debits
NACHA rules impose return rate thresholds, and failure to monitor returns can result in financial loss and NACHA sanctions.
Question 200: Which of the following best describes residual risk in a bank's risk management framework?
- Risk transferred to a third party through insurance or derivatives
- The risk assigned to the internal audit function for monitoring
- The total gross risk before any controls are applied
- The risk remaining after management controls and mitigants have been applied (Correct answer)
Correct answer: The risk remaining after management controls and mitigants have been applied
Residual risk is the exposure that remains after inherent risk is reduced by the effectiveness of existing controls.
Certified Bank Auditor (CBA)
The CBA is a professional certification awarded by the Institute of Certified Bankers (ICB), validating expertise in bank auditing across risk management, audit processes, IT, corporate governance, regulatory compliance, and financial auditing.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds