← All CBA Flashcard Decks

Risk Management Auditing Flashcards

7 cards from real CBA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Management Auditing flashcards as text
  1. Which audit procedure best tests the effectiveness of a bank's third-party risk management program?

    Answer: Testing whether ongoing monitoring activities are performed and documented for critical vendors

    Effectiveness of third-party risk management is demonstrated through ongoing monitoring of critical vendors, not just initial onboarding.

  2. A bank's fraud risk assessment identifies wire transfer origination as high-risk. Which control is most effective at mitigating this risk?

    Answer: Requiring dual authorization and call-back verification for large wire transfers

    Dual authorization combined with out-of-band call-back verification is the most effective preventive control against fraudulent wire transfers.

  3. When auditing interest rate risk in the banking book (IRRBB), what does an EVE (Economic Value of Equity) measure capture?

    Answer: The present value impact of rate shocks on the bank's entire balance sheet

    EVE measures the change in the economic value of all assets, liabilities, and off-balance-sheet items in response to interest rate shocks.

  4. An auditor discovers that the risk management function reports to the CFO. Under best practices, what concern should be raised?

    Answer: Risk management reporting to the CFO impairs its independence from business line influence

    Best practice and regulatory guidance call for the Chief Risk Officer to report independently to the CEO or board, not through a business-oriented function like the CFO.

  5. Which of the following is an example of a key risk indicator (KRI) for cybersecurity risk?

    Answer: Percentage of systems with overdue critical patch deployments

    The percentage of systems with unpatched critical vulnerabilities is a forward-looking KRI that signals elevated cyber risk before an incident occurs.

  6. In a bank's three lines of defense model, which party is responsible for owning and managing risks day to day?

    Answer: Business line management (first line)

    The first line of defense—business line management—owns, manages, and is accountable for risks inherent in their operations.

  7. When stress testing a loan portfolio, a CBA candidate should understand that a 'severely adverse' scenario is designed to represent which condition?

    Answer: A severe recession with unemployment reaching approximately 10% or higher

    The severely adverse scenario in Federal Reserve stress tests represents a deep recession with significant unemployment increases, typically 10% or more.