Certified Bank Auditor (CBA) β Questions and Answers
Question 1: Which ratio is commonly used to evaluate a bankβs profitability?
- Inventory turnover
- Current ratio
- Return on Assets (ROA) (Correct answer)
- Debt-to-equity ratio
Correct answer: Return on Assets (ROA)
Return on Assets (ROA) indicates how efficiently a bank is using its assets to generate profit.
Question 2: When auditing a bank's data governance framework, which of the following is the MOST critical principle for an auditor to verify?
- The speed and performance of the data warehouse.
- The use of the latest data analytics software for marketing purposes.
- The number of data reports generated for senior management each month.
- The establishment of clear ownership and accountability for critical data elements. (Correct answer)
Correct answer: The establishment of clear ownership and accountability for critical data elements.
A fundamental principle of effective data governance is establishing clear ownership and accountability. This ensures that there are designated individuals or teams responsible for the quality, security, and management of specific data assets throughout their lifecycle. Without clear ownership, it becomes difficult to enforce policies, maintain data quality, and manage risks effectively.
Question 3: Which analytical procedure would best help an auditor assess the reasonableness of a bank's net interest margin (NIM)?
- Reviewing loan officer compensation expense relative to loan origination volume
- Recalculating total interest expense based on average deposit balances
- Benchmarking the bank's NIM against peer institutions and prior period trends (Correct answer)
- Comparing total non-interest income to prior year balances
Correct answer: Benchmarking the bank's NIM against peer institutions and prior period trends
Comparing NIM to peer institutions and historical trends provides context for evaluating whether the reported margin is reasonable given the rate environment and asset mix.
Question 4: A bank has recently launched a new mobile banking application with peer-to-peer payment capabilities. When auditing the risk management process for this new product, which of the following would be the auditor's primary concern regarding operational risk?
- The possibility that the new service violates consumer lending regulations.
- The potential for losses due to fluctuations in interest rates.
- The likelihood that the bank's strategic goals for the new product will not be met.
- The risk of loss resulting from inadequate or failed internal processes, people, and systems. (Correct answer)
Correct answer: The risk of loss resulting from inadequate or failed internal processes, people, and systems.
Operational risk is defined as the risk of loss resulting from inadequate or failed internal processes, people, and systems, or from external events. A new mobile application introduces risks related to system failures, cybersecurity breaches, transaction processing errors, and potential for fraud, all of which fall under the category of operational risk. Interest rate risk, compliance risk, and strategic risk are other distinct risk categories.
Question 5: A bank's IT auditor is assessing vendor management controls for a cloud-based core banking provider. Which document is MOST important to review?
- The vendor's office lease agreement
- The vendor's employee handbook
- The Service Level Agreement and right-to-audit clause (Correct answer)
- The vendor's marketing brochure
Correct answer: The Service Level Agreement and right-to-audit clause
The SLA defines performance commitments and the right-to-audit clause ensures the bank can verify the vendor's controls, which is essential for regulatory compliance.
Question 6: A bank's risk appetite statement should primarily be approved and owned by which group?
- Chief Risk Officer alone
- Internal audit committee
- External auditors
- Board of directors (Correct answer)
Correct answer: Board of directors
The board of directors is responsible for approving and owning the bank's risk appetite statement as part of its governance obligations.
Question 7: When evaluating a bank's operational risk event data collection process, an auditor should be most concerned if:
- Near-miss events are captured alongside actual loss events
- Business lines self-report loss events with no independent validation (Correct answer)
- Loss event thresholds below $10,000 are excluded from reporting
- Risk categories follow Basel II event type classifications
Correct answer: Business lines self-report loss events with no independent validation
Self-reporting without independent validation creates a significant integrity risk, as business lines may under-report or misclassify operational losses.
Question 8: What is the purpose of the statement of cash flows?
- To calculate interest expense
- To assess asset turnover
- To show cash movement in and out of the business (Correct answer)
- To track net income
Correct answer: To show cash movement in and out of the business
It provides information about a company's cash inflows and outflows, categorized into operating, investing, and financing activities.
Question 9: Which of the following scenarios MOST represents a breakdown in the governance oversight of a bank's compliance function?
- The Chief Compliance Officer reports solely to the CEO with no direct access to the board (Correct answer)
- The board's audit committee reviews the annual compliance plan and budget
- An independent compliance testing team identifies and escalates control gaps
- The board receives a quarterly compliance risk report and asks clarifying questions
Correct answer: The Chief Compliance Officer reports solely to the CEO with no direct access to the board
When the CCO lacks direct board access and reports only to the CEO, management can suppress or filter compliance findings, undermining independent oversight.
Question 10: An auditor reviewing operational risk finds that a bank has not updated its Business Continuity Plan (BCP) in three years. Which risk is most directly elevated?
- Credit risk from unrecovered loan portfolios
- Strategic risk from outdated product offerings
- Operational risk from untested recovery capabilities (Correct answer)
- Compliance risk from failure to file regulatory reports
Correct answer: Operational risk from untested recovery capabilities
An outdated and untested BCP leaves the bank vulnerable to operational disruptions it cannot recover from efficiently.
Question 11: Which of the following is a key difference between a compliance risk assessment and a compliance audit?
- A risk assessment tests specific transactions while an audit evaluates policies only
- There is no functional difference β the terms are interchangeable in banking
- A compliance audit is performed by management while a risk assessment is performed by internal audit
- A risk assessment identifies and prioritizes compliance risks, while an audit provides independent testing and verification of controls (Correct answer)
Correct answer: A risk assessment identifies and prioritizes compliance risks, while an audit provides independent testing and verification of controls
Risk assessments identify and rank potential compliance exposures to guide audit focus, while audits independently test whether controls are operating effectively.
Question 12: Which log type would an IT auditor MOST likely review to detect brute-force login attempts against a bank's online banking system?
- Database transaction logs
- Network bandwidth utilization logs
- Application error logs
- Authentication failure logs (Correct answer)
Correct answer: Authentication failure logs
Authentication failure logs capture repeated failed login attempts, which is the primary indicator of a brute-force attack against user accounts.
Question 13: Under FinCEN's Customer Due Diligence (CDD) Rule, what is required when a legal entity customer opens a new account?
- Verification of all employees of the entity
- Filing a CTR for the initial deposit
- Collection of beneficial ownership information for individuals owning 25% or more (Correct answer)
- Annual credit review of the entity
Correct answer: Collection of beneficial ownership information for individuals owning 25% or more
FinCEN's CDD Rule requires banks to identify and verify the identity of individuals who own 25% or more of a legal entity customer.
Question 14: Which of the following BEST describes the concept of 'risk appetite' in a bank's compliance framework?
- The number of regulatory violations a bank has incurred in the prior year
- The minimum capital ratio required by the bank's primary regulator
- The maximum financial loss a bank can absorb before insolvency
- The amount and type of compliance risk the bank is willing to accept in pursuit of its objectives (Correct answer)
Correct answer: The amount and type of compliance risk the bank is willing to accept in pursuit of its objectives
Risk appetite defines the level and types of risk the bank's board is willing to tolerate, guiding decision-making and compliance risk management strategies.
Question 15: Which of the following describes the relationship between risk appetite and an internal audit plan for a bank?
- The audit plan and risk appetite are developed independently by the internal audit function.
- The audit plan dictates the bank's risk appetite.
- Risk appetite is irrelevant to the development of the audit plan.
- The audit plan is designed to provide assurance that risks are managed within the bank's established risk appetite. (Correct answer)
Correct answer: The audit plan is designed to provide assurance that risks are managed within the bank's established risk appetite.
A bank's board of directors establishes the risk appetite, which is the amount and type of risk the bank is willing to accept in pursuit of its objectives. The internal audit plan is then developed to focus on areas of highest risk and provide independent assurance to the board that these risks are being identified and managed effectively and within the stated appetite.
Question 16: A bank IT auditor finds that developers have access to the production environment. What control deficiency does this represent?
- A lack of segregation of duties between development and production (Correct answer)
- A bandwidth allocation issue
- A violation of software licensing terms
- An inadequate testing environment
Correct answer: A lack of segregation of duties between development and production
Developers with production access can introduce unauthorized code changes or access sensitive data, violating the segregation of duties principle.
Question 17: An IT auditor is evaluating a bank's controls over API security for open banking integrations. Which control is MOST important to verify?
- OAuth 2.0 implementation with proper token scoping and expiration controls (Correct answer)
- The physical location of the API gateway servers
- The programming language used to build the APIs
- The visual design of the API developer portal
Correct answer: OAuth 2.0 implementation with proper token scoping and expiration controls
OAuth 2.0 with properly scoped and time-limited tokens is the foundational security control for API access management in open banking environments.
Question 18: Which of the following best describes a 'staggered board' structure?
- Only a fraction of board seats are up for election each year (Correct answer)
- The board rotates leadership among its members monthly
- Directors are appointed exclusively by regulators
- All directors are elected every year at the annual meeting
Correct answer: Only a fraction of board seats are up for election each year
A staggered board divides directors into classes elected in different years, providing continuity but potentially entrenching existing directors.
Question 19: Under the Community Reinvestment Act (CRA), federal regulators evaluate a bank's record of meeting credit needs in its:
- Nationwide branch network
- Foreign correspondent banking relationships
- Wholesale banking division
- Assessment area, typically its local communities (Correct answer)
Correct answer: Assessment area, typically its local communities
CRA evaluations focus on how well a bank serves the credit needs of its defined assessment area, which encompasses the communities where it operates.
Question 20: A bank auditor reviewing credit concentration risk should MOST likely focus on:
- Foreign exchange hedging positions
- Intraday liquidity positions
- Large exposures to single borrowers or correlated sectors (Correct answer)
- Trading book mark-to-market losses
Correct answer: Large exposures to single borrowers or correlated sectors
Credit concentration risk is the exposure to large individual borrowers or highly correlated borrower groups that can cause significant loss.
Question 21: In evaluating a bank's market risk model, an auditor notes the model uses a 99% confidence level and a 10-day holding period. Under Basel rules, what does exceeding four backtesting exceptions in a year trigger?
- An increase in the VaR capital multiplier (from the 'green zone' to a higher zone) (Correct answer)
- Mandatory model replacement within 60 days
- A requirement to switch to the historical simulation method
- Immediate suspension of the bank's trading activities
Correct answer: An increase in the VaR capital multiplier (from the 'green zone' to a higher zone)
More than four backtesting exceptions in 250 trading days moves the bank from the green zone and triggers an increase in the regulatory VaR multiplication factor.
Question 22: Under the IIA Standards, internal auditors must maintain independence from the activities they audit. This independence is BEST achieved by:
- Reporting functionally to the audit committee rather than management (Correct answer)
- Having auditors specialize in areas they previously worked in
- Limiting audit scope to low-risk business units
- Rotating audit assignments every two years
Correct answer: Reporting functionally to the audit committee rather than management
Functional reporting to the audit committee ensures internal audit is not subordinate to the management whose activities it reviews, preserving independence.
Question 23: A Certified Bank Auditor is planning an audit of the bank's cybersecurity incident response plan. Which audit test would BEST assess the plan's practical effectiveness?
- Verifying that the plan includes an up-to-date contact list for all incident response team members.
- Ensuring the plan is stored in a secure, access-controlled location both on-site and off-site.
- Reviewing the results and lessons learned from a recent tabletop exercise or simulation drill. (Correct answer)
- Confirming the plan has been reviewed and approved by the Board of Directors within the last year.
Correct answer: Reviewing the results and lessons learned from a recent tabletop exercise or simulation drill.
While plan approval, accurate contact lists, and secure storage are important compliance checks, the best way to assess the *effectiveness* of an incident response plan is to see how it performs in practice. Reviewing the outcomes of a tabletop exercise or a full simulation drill provides concrete evidence of the team's preparedness, identifies gaps in the plan, and demonstrates the bank's ability to respond to an actual incident.
Question 24: Which regulatory body published the 'Principles for Enhancing Corporate Governance' that are widely used as a global benchmark for banks?
- International Monetary Fund (IMF)
- Financial Accounting Standards Board (FASB)
- U.S. Securities and Exchange Commission (SEC)
- Basel Committee on Banking Supervision (BCBS) (Correct answer)
Correct answer: Basel Committee on Banking Supervision (BCBS)
The Basel Committee on Banking Supervision published the Principles for Enhancing Corporate Governance, providing the primary global standard for bank boards.
Question 25: When a bank's external auditor is also providing significant consulting services, this raises a concern about:
- Dividend payout ratios
- The bank's liquidity coverage ratio
- Auditor independence and objectivity (Correct answer)
- Regulatory capital adequacy
Correct answer: Auditor independence and objectivity
Providing consulting services alongside audit work creates a financial dependency that can compromise the auditor's independence.
Question 26: Which control is MOST effective at detecting kiting schemes in a bank's demand deposit operations?
- Daily proof and balancing of teller transactions
- Customer signature verification on checks
- Automated clearing house file audits
- Float analysis and interbank account reconciliation (Correct answer)
Correct answer: Float analysis and interbank account reconciliation
Float analysis and interbank reconciliation reveal artificially inflated balances created by exploiting check clearing delays.
Question 27: When evaluating the independence of a bank's internal audit function, the MOST critical factor is:
- The educational credentials of the chief audit executive
- Whether the internal audit function reports directly to the board's audit committee (Correct answer)
- The size of the internal audit department relative to the bank's assets
- Whether external auditors also review internal audit's work
Correct answer: Whether the internal audit function reports directly to the board's audit committee
Reporting to the audit committee (rather than management) ensures internal audit can objectively evaluate and report on management's activities without interference.
Question 28: In credit risk management, Loss Given Default (LGD) measures:
- The bank's expected profit on a loan after accounting for default
- The probability that a borrower will default within one year
- The outstanding exposure at the time of default
- The proportion of exposure the bank loses if the borrower defaults (Correct answer)
Correct answer: The proportion of exposure the bank loses if the borrower defaults
LGD represents the fraction of the exposure that is not recovered after a default, net of collateral and recoveries.
Question 29: In corporate governance, the 'duty of loyalty' requires bank directors to:
- Vote in alignment with the position of the bank's largest shareholder
- Remain loyal to the bank's founding shareholders regardless of circumstances
- Prioritize the interests of the bank over personal or third-party interests (Correct answer)
- Maintain confidentiality of all board discussions for 10 years
Correct answer: Prioritize the interests of the bank over personal or third-party interests
The duty of loyalty requires directors to act in the best interests of the bank, avoiding self-dealing or conflicts of interest.
Question 30: Which of the following best describes the 'scope limitation' an internal auditor must document when access to key records is denied during a compliance audit?
- A notation that the audit was completed without exception
- A disclosure in the audit report that certain evidence could not be examined, affecting the conclusions that can be drawn (Correct answer)
- An automatic escalation requiring external auditor involvement
- A formal finding that the denied records contain compliance violations
Correct answer: A disclosure in the audit report that certain evidence could not be examined, affecting the conclusions that can be drawn
When auditors cannot access key records, they must document the scope limitation and caveat audit conclusions accordingly, since findings may be incomplete.
Question 31: A bank outsources its data center operations. Under OCC guidance, who retains ULTIMATE responsibility for the security of customer data?
- The data center's insurance provider
- The bank itself (Correct answer)
- The Federal Reserve
- The outsourced data center vendor
Correct answer: The bank itself
OCC guidance makes clear that banks cannot outsource their regulatory responsibilities β the bank retains ultimate accountability for data security even when operations are outsourced.
Certified Bank Auditor (CBA)
The CBA is a professional certification awarded by the Institute of Certified Bankers (ICB), validating expertise in bank auditing across risk management, audit processes, IT, corporate governance, regulatory compliance, and financial auditing.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong β answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds