← All CBA Flashcard Decks

Mixed Deck — All CBA Topics Flashcards

100 cards from real CBA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All CBA Topics flashcards as text
  1. A compliance auditor is evaluating a bank's third-party vendor risk management program. According to OCC guidance, who bears ultimate responsibility for ensuring vendor compliance with applicable laws?

    Answer: The bank's board of directors and senior management

    OCC guidance makes clear that the bank's board of directors and senior management retain ultimate responsibility for activities conducted by third-party vendors on the bank's behalf.

  2. Under the Volcker Rule, which activity is generally PROHIBITED for banks and their affiliates?

    Answer: Proprietary trading in securities and certain derivatives for the bank's own account

    The Volcker Rule, part of the Dodd-Frank Act, prohibits banking entities from engaging in short-term proprietary trading of securities for their own profit.

  3. In corporate governance, the 'duty of loyalty' requires bank directors to:

    Answer: Prioritize the interests of the bank over personal or third-party interests

    The duty of loyalty requires directors to act in the best interests of the bank, avoiding self-dealing or conflicts of interest.

  4. An auditor reviewing safe deposit box operations finds that access logs are maintained manually and have gaps. The MOST significant risk is:

    Answer: Inability to detect unauthorized box access

    Incomplete access logs remove the audit trail needed to detect and investigate unauthorized entry to safe deposit boxes.

  5. During an audit of a bank's investment portfolio, an auditor is testing the valuation of U.S. Treasury bonds classified as 'Available-for-Sale' (AFS). Which audit procedure provides the MOST reliable evidence for the valuation of these securities?

    Answer: Comparing the bank's recorded fair value to a quoted price from an active, independent market source.

    AFS securities are carried at fair value. For an actively traded security like a U.S. Treasury bond, the most reliable audit evidence for its valuation is an external, independent source. Comparing the bank's carrying value to a quoted price from an active market (a Level 1 input) provides direct and highly reliable evidence of its fair value. The other procedures test different attributes but do not directly substantiate fair value.

  6. When auditing overdraft protection programs, the auditor should PRIMARILY evaluate whether the program complies with:

    Answer: Regulation E opt-in requirements for ATM and one-time debit transactions

    Regulation E requires banks to obtain affirmative opt-in consent before charging overdraft fees on ATM and one-time debit card transactions.

  7. In a bank's call report (FFIEC 041), which schedule captures loan-level data on past due and nonaccrual loans?

    Answer: Schedule RC-N (Past Due and Nonaccrual)

    Schedule RC-N of the call report specifically captures loans, leases, and debt securities categorized by days past due and nonaccrual status.

  8. Why is documentation important in compliance processes?

    Answer: To provide proof of compliance

    Documentation serves as evidence of compliance with laws and policies, supporting audits and regulatory reviews.

  9. Which metric measures the potential loss on a trading portfolio over a given time horizon at a specified confidence level?

    Answer: Value at Risk (VaR)

    VaR quantifies the maximum expected loss over a specific period at a given confidence level (e.g., 99% over one day).

  10. A bank's internal audit department is evaluating the institution's management of operational risk. According to the Basel Committee on Banking Supervision (BCBS), operational risk includes losses resulting from what?

    Answer: Inadequate or failed internal processes, people, and systems, or from external events.

    The Basel Committee on Banking Supervision (BCBS) defines operational risk as the risk of loss resulting from inadequate or failed internal processes, people, and systems, or from external events. This definition explicitly includes legal risk but excludes strategic and reputational risk. The other choices describe market risk, credit risk, and liquidity risk, respectively.

  11. A bank has identified and classified several large commercial loans as Troubled Debt Restructurings (TDRs). When auditing these loans, the auditor's primary focus should be to ensure that:

    Answer: the concession granted to the borrower has been properly identified and the loan's impairment has been measured and recognized in accordance with accounting principles.

    The key audit and accounting issue for a TDR is its proper recognition and measurement. Under accounting standards (e.g., ASC 310-40), a TDR occurs when a creditor, for economic or legal reasons related to the debtor's financial difficulties, grants a concession to the debtor that it would not otherwise consider. The auditor must verify that these concessions are identified and that the resulting impairment on the loan is correctly calculated (either through the discounted cash flow method or the fair value of collateral) and reflected in the Allowance for Credit Losses (ACL).

  12. A compliance auditor is evaluating a bank's Unfair, Deceptive, or Abusive Acts or Practices (UDAAP) program. Which of the following scenarios most clearly constitutes an 'abusive' practice under Dodd-Frank?

    Answer: A bank taking advantage of consumers' inability to understand a product's material risks

    An abusive practice under Dodd-Frank includes taking unreasonable advantage of consumers' lack of understanding of the material risks or costs of a financial product.

  13. An auditor reviewing a bank's daily cash transaction logs notices a commercial customer, who owns a chain of convenience stores, has multiple employees making separate cash deposits of $9,500 at different branches on the same day. This pattern is a significant red flag for which potential regulatory violation?

    Answer: Structuring transactions to evade Currency Transaction Report (CTR) filing requirements.

    The Bank Secrecy Act (BSA) requires banks to file a Currency Transaction Report (CTR) for cash transactions exceeding $10,000. Structuring is the illegal practice of breaking down a single large transaction into multiple smaller ones to avoid triggering this reporting threshold. The described pattern is a classic example of structuring.

  14. The 'travel rule' in BSA/AML compliance requires banks to pass along certain information when transmitting funds. What is the minimum dollar threshold that triggers this rule?

    Answer: $3,000

    The Travel Rule (31 CFR 103.33) requires that banks include originator and beneficiary information for funds transfers of $3,000 or more.

  15. An auditor reviewing mortgage loan files finds that the bank consistently failed to provide the Loan Estimate within 3 business days of receiving a loan application. Which regulation is violated?

    Answer: Regulation Z (TRID)

    Under TRID (TILA-RESPA Integrated Disclosure rules, Regulation Z), lenders must deliver the Loan Estimate within 3 business days of receiving a completed loan application.

  16. Which scenario would most likely result in a Matters Requiring Attention (MRA) from a bank regulator related to risk management?

    Answer: A bank with no formal process for escalating limit breaches to senior management

    The absence of a formal limit breach escalation process is a material control gap that regulators would cite as requiring prompt corrective action.

  17. When evaluating the independence of a bank's internal audit function, the MOST critical factor is:

    Answer: Whether the internal audit function reports directly to the board's audit committee

    Reporting to the audit committee (rather than management) ensures internal audit can objectively evaluate and report on management's activities without interference.

  18. Under the standardized approach for operational risk capital (Basel III), the Business Indicator Component (BIC) is multiplied by which factor?

    Answer: Internal Loss Modifier (ILM)

    Under Basel III's Standardized Approach, the BIC is multiplied by the Internal Loss Modifier to determine operational risk capital requirements.

  19. An auditor is evaluating the bank's loan loss reserve (CECL) model. Which finding poses the greatest risk to financial statement accuracy?

    Answer: Historical loss data used to calibrate the model predates the bank's current loan portfolio mix by ten years

    Using stale historical loss data that doesn't reflect the current portfolio's risk profile will produce unreliable CECL estimates, potentially causing material misstatement of reserves.

  20. Which control most effectively detects ghost employee schemes in a bank's payroll system?

    Answer: Comparing payroll records against HR personnel files and conducting surprise physical headcounts

    Comparing payroll records to active HR personnel files and performing unannounced physical headcounts effectively identifies ghost employees — fictitious workers added to payroll to divert paychecks.