Auditing Risk Management Flashcards
7 cards from real CBA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Auditing Risk Management flashcards as text
An internal auditor discovers that a bank's compliance risk assessment does not include an evaluation of newly enacted consumer protection regulations. This gap most directly reflects a failure in:
Answer: The regulatory change management process within the compliance risk framework
A compliance risk assessment must capture regulatory changes through a structured change management process to ensure new requirements are identified and addressed timely.
When evaluating a bank's Pillar 2 Internal Capital Adequacy Assessment Process (ICAAP), auditors should assess whether:
Answer: All material risks, including those not captured in Pillar 1, are identified and capitalized
ICAAP must capture all material risks including Pillar 2 risks such as concentration risk, IRRBB, and strategic risk that are not fully addressed in Pillar 1.
A bank's risk management audit reveals that front-office traders can both execute trades and update the risk system positions without segregation of duties. This creates the highest risk of:
Answer: Unauthorized trading and concealment of losses similar to rogue trader incidents
Without segregation between trade execution and position recording, traders can conceal unauthorized or losing positions, as seen in high-profile rogue trader cases.
Which of the following is a key indicator that a bank's risk culture may be weak, even if documented policies appear adequate?
Answer: Employees routinely bypass risk controls citing business pressure, and near-misses are rarely reported
A weak risk culture is evidenced by behavioral patterns such as control bypass under business pressure and low near-miss reporting, regardless of how strong policies appear on paper.
Under the OCC's guidance on risk governance, the Chief Risk Officer (CRO) should have which of the following characteristics to ensure effectiveness?
Answer: Independence from business lines, direct board access, and authority to escalate risk concerns
An effective CRO must be independent from revenue-generating units, have direct access to the board, and possess authority to escalate risk concerns without business line interference.
When auditing a bank's business continuity and disaster recovery program from a risk management perspective, the most critical element to verify is:
Answer: That BCP/DR plans are tested regularly, results documented, and gaps remediated
Regular testing with documented results and timely gap remediation is the cornerstone of an effective BCP/DR program; untested plans provide false assurance.
A bank auditor is assessing the effectiveness of the bank's risk-adjusted return on capital (RAROC) framework. Which finding would indicate the framework is NOT effectively influencing business decisions?
Answer: Loan pricing decisions are made without reference to RAROC hurdle rates
If loan pricing ignores RAROC hurdle rates, the framework is not embedded in actual business decision-making, undermining its purpose of aligning risk-taking with shareholder value.