CRB Risk Management & Fraud Prevention 5 — Questions and Answers
Question 1: The 'three lines of defense' model in banking assigns primary responsibility for identifying and managing risk to:
- Internal audit
- Compliance and risk management functions
- Business line management (Correct answer)
- External auditors
Correct answer: Business line management
The first line of defense consists of business line managers and staff who own and manage risks in their day-to-day operations.
Question 2: A customer receives a call from someone claiming to be their bank and is asked to confirm their account number and PIN to prevent fraud. This attack is called:
- Phishing
- Pharming
- Vishing (Correct answer)
- Spoofing
Correct answer: Vishing
Vishing (voice phishing) uses phone calls to trick individuals into revealing sensitive account information by impersonating trusted institutions.
Question 3: Which regulatory requirement mandates that banks establish a written Customer Identification Program (CIP)?
- Gramm-Leach-Bliley Act
- USA PATRIOT Act Section 326 (Correct answer)
- Dodd-Frank Act Title X
- Community Reinvestment Act
Correct answer: USA PATRIOT Act Section 326
Section 326 of the USA PATRIOT Act requires financial institutions to implement a written CIP to verify the identity of customers opening accounts.
Question 4: A bank employee bypasses the dual-control requirement and processes a large wire transfer unilaterally. Which risk management control has failed?
- Segregation of duties (Correct answer)
- Know Your Customer
- Loan-to-value monitoring
- Net interest margin oversight
Correct answer: Segregation of duties
Segregation of duties requires that no single employee can execute a sensitive transaction without another authorized person's involvement, preventing fraud and errors.
Question 5: Operational risk differs from credit risk in that operational risk arises from:
- Borrower default on loan obligations
- Failures in people, processes, systems, or external events (Correct answer)
- Interest rate fluctuations affecting the loan portfolio
- Counterparty inability to meet contractual obligations
Correct answer: Failures in people, processes, systems, or external events
Operational risk is defined by the Basel framework as risk resulting from inadequate or failed internal processes, people, systems, or external events.
Question 6: A retail bank notices a customer consistently depositing cash just under $10,000 to avoid CTR filing. The bank should:
- Continue normal processing as no CTR is required below $10,000
- File a CTR only when deposits exceed $10,000 in aggregate
- File a SAR for structuring and potentially file a CTR for aggregated transactions (Correct answer)
- Freeze the account pending a regulatory review
Correct answer: File a SAR for structuring and potentially file a CTR for aggregated transactions
Structuring to evade CTR reporting is itself a federal crime, and banks must file a SAR when they detect this pattern regardless of individual transaction amounts.
Question 7: Which of the following BEST describes the purpose of an independent model validation in risk management?
- To ensure loan officers follow underwriting guidelines
- To verify that risk models perform as intended and produce reliable outputs (Correct answer)
- To confirm that financial statements comply with GAAP
- To audit branch cash handling procedures
Correct answer: To verify that risk models perform as intended and produce reliable outputs
Model validation is an independent review process that evaluates whether risk models are conceptually sound, correctly implemented, and produce accurate outputs.
The 'three lines of defense' model in banking assigns primary responsibility for identifying and managing risk to: