Series 99 Operational Risk & Controls — Questions and Answers
Question 1: What is operational risk?
- Stock loss
- Failure in operations (Correct answer)
- Customer loss
- Product reviews
Correct answer: Failure in operations
Operational risk refers to the risk of loss resulting from inadequate or failed internal processes, people, and systems, or from external events. This can include errors in transaction processing, system failures, human mistakes, fraud, or disruptions from natural disasters. Managing operational risk is crucial for a firm's stability and ability to deliver services effectively.
Question 2: What is a common internal control?
- One-person approval
- Separation of duties (Correct answer)
- Verbal approvals
- Outsourcing
Correct answer: Separation of duties
Separation of duties is a fundamental internal control designed to prevent fraud and errors by distributing critical functions among different individuals. This means that no single person has complete control over a transaction from start to finish. For example, the person who authorizes a payment should not be the same person who records it or reconciles the bank statement, reducing the opportunity for misconduct.
Question 3: Why perform audits?
- Train staff
- Detect and verify (Correct answer)
- Avoid taxes
- Simplify forms
Correct answer: Detect and verify
Audits are systematic examinations of an organization's financial records, operations, and compliance with regulations. Their primary purpose is to detect errors, fraud, or non-compliance, and to verify the accuracy and reliability of information. Audits provide an independent assessment, offering assurance to stakeholders that processes are functioning correctly and financial statements are fairly presented.
Question 4: What reduces system risk?
- Emails
- Backups (Correct answer)
- Password resets
- Marketing
Correct answer: Backups
Backups are critical for reducing system risk by creating copies of data and system configurations. In the event of a system failure, data corruption, cyberattack, or disaster, backups allow an organization to restore its information and operations, minimizing downtime and data loss. Regular and secure backups are a cornerstone of any robust disaster recovery and business continuity plan.
Question 5: What is risk mitigation?
- Increase budget
- Reduce impact (Correct answer)
- Write memos
- Hire interns
Correct answer: Reduce impact
Risk mitigation refers to the strategies and actions taken to reduce the likelihood or impact of a potential risk event. It involves identifying risks, assessing their potential consequences, and implementing controls or plans to lessen their severity or probability. The goal is to minimize the negative effects that risks could have on an organization's operations, finances, or reputation.
Question 6: Why document procedures?
- Save paper
- Consistency (Correct answer)
- Add color
- Create roles
Correct answer: Consistency
Documenting procedures is essential for ensuring consistency in how tasks are performed across an organization. Clear, written procedures provide a standardized guide for employees, reducing variations in execution and minimizing errors. This consistency is vital for maintaining quality, efficiency, compliance, and for training new staff effectively.
Question 7: Who monitors control effectiveness?
- HR team
- Audit or risk team (Correct answer)
- Sales team
- Legal advisors
Correct answer: Audit or risk team
The audit or risk team within an organization is specifically tasked with monitoring the effectiveness of internal controls. They conduct independent assessments, reviews, and tests to ensure that controls are operating as intended and are adequately mitigating identified risks. This oversight helps maintain the integrity of operations and compliance with regulatory requirements.
Question 8: What is escalation protocol?
- Bonus plan
- Report process (Correct answer)
- Training test
- Service hours
Correct answer: Report process
Escalation protocol refers to a predefined process for reporting and addressing issues or incidents that cannot be resolved at a lower level. It outlines who should be informed, when, and how, ensuring that critical problems are brought to the attention of appropriate management or specialized teams in a timely manner. This structured reporting helps ensure efficient problem resolution and prevents issues from escalating into larger crises.
Question 9: Why use access controls?
- Improve sales
- Limit access (Correct answer)
- Track ads
- Print labels
Correct answer: Limit access
Access controls are security mechanisms designed to regulate who can view, use, or enter specific resources or areas. Their primary function is to restrict unauthorized individuals from accessing sensitive information, systems, or physical locations. This helps protect data integrity, maintain confidentiality, and prevent misuse within an organization.
What is operational risk?