Series 99 Operational Risk & Controls 5 — Questions and Answers
Question 1: A broker-dealer's cybersecurity policy requires all employees to use multi-factor authentication (MFA). This is BEST classified as which type of operational control?
- Detective control
- Corrective control
- Preventive control (Correct answer)
- Compensating control
Correct answer: Preventive control
MFA is a preventive control because it stops unauthorized access before it can occur, rather than detecting or correcting problems after the fact.
Question 2: Under SEC Regulation SCI, which firms are required to establish, maintain, and enforce written policies for their systems?
- All registered investment advisers
- SCI entities including certain exchanges, clearing agencies, ATSs, and plan processors (Correct answer)
- Only foreign broker-dealers operating in the US
- Exclusively FINRA member firms with fewer than 50 employees
Correct answer: SCI entities including certain exchanges, clearing agencies, ATSs, and plan processors
Regulation SCI applies to SCI entities — national securities exchanges, registered clearing agencies, ATSs, plan processors, and exempt clearing agencies — requiring robust systems compliance and integrity policies.
Question 3: A control gap analysis at a broker-dealer identifies that the firm has no procedure for reviewing electronic communications of registered persons. This represents:
- An acceptable cost-saving measure
- A regulatory risk and operational control deficiency requiring remediation (Correct answer)
- A best practice recognized by FINRA
- A standard industry approach for small firms
Correct answer: A regulatory risk and operational control deficiency requiring remediation
FINRA requires firms to review electronic correspondence of registered persons; the absence of such a procedure is a serious control deficiency and regulatory violation.
Question 4: Which of the following BEST describes 'tail risk' in the context of operational risk management?
- The risk that a securities trade will fail to settle
- The risk of low-probability but high-severity events that fall outside normal risk models (Correct answer)
- The risk associated with the last trade of the trading day
- The risk of customer attrition at the end of a contract period
Correct answer: The risk of low-probability but high-severity events that fall outside normal risk models
Tail risk refers to extreme, low-probability events with severe consequences that are not adequately captured by standard probability distributions.
Question 5: A broker-dealer's anti-money laundering (AML) program fails to flag a series of structuring transactions. This failure MOST directly represents:
- Market risk exposure
- An operational control failure with legal and regulatory consequences (Correct answer)
- A credit risk event requiring capital reserves
- A normal exception in retail banking operations
Correct answer: An operational control failure with legal and regulatory consequences
Failure of AML controls to detect structuring is an operational control failure that can result in BSA/FinCEN violations, fines, and reputational damage.
Question 6: When a broker-dealer outsources its clearing functions to a correspondent firm, the introducing firm's operational risk:
- Is completely transferred to the clearing firm
- Is eliminated because clearing is no longer the firm's responsibility
- Remains partially with the introducing firm, which must still supervise and monitor the clearing relationship (Correct answer)
- Is reduced to zero as long as a clearing agreement is signed
Correct answer: Remains partially with the introducing firm, which must still supervise and monitor the clearing relationship
Outsourcing does not eliminate operational risk; the introducing firm retains responsibility for supervising the clearing relationship and ensuring the correspondent meets its obligations.
Question 7: Which of the following scenarios BEST illustrates 'concentration risk' from an operational perspective?
- A firm that holds a diversified portfolio of securities across many sectors
- A firm that relies on a single technology vendor for all its critical trading infrastructure (Correct answer)
- A firm that employs registered representatives across multiple states
- A firm that clears trades for customers in multiple asset classes
Correct answer: A firm that relies on a single technology vendor for all its critical trading infrastructure
Operational concentration risk occurs when a firm depends heavily on a single vendor, system, or process, creating a single point of failure that could disrupt all operations.
A broker-dealer's cybersecurity policy requires all employees to use multi-factor authentication (MFA).
This is BEST classified as which type of operational control?