APRP Operational Risk Management 1 — Questions and Answers
Question 1: Which of the following best defines operational risk in the context of payment processing?
- Risk of loss from inadequate internal processes, people, systems, or external events (Correct answer)
- Risk arising from fluctuations in foreign exchange rates
- Risk of a counterparty defaulting on a financial obligation
- Risk associated with changes in interest rates affecting payment costs
Correct answer: Risk of loss from inadequate internal processes, people, systems, or external events
Operational risk in payments is the risk of loss resulting from inadequate or failed internal processes, people, and systems, or from external events.
Question 2: A payment processor experiences repeated transaction failures due to an undocumented manual workaround used by staff. Which operational risk category does this represent?
- External fraud
- Process failure (Correct answer)
- System outage
- Vendor default
Correct answer: Process failure
Undocumented manual workarounds represent a process failure risk, as the lack of formal procedures creates inconsistency and potential for error.
Question 3: What is the primary purpose of a Business Continuity Plan (BCP) for a payment organization?
- To maximize transaction throughput during peak hours
- To ensure critical payment operations can continue during and after a disruptive event (Correct answer)
- To document all payment fraud cases for regulatory reporting
- To outline marketing strategies for new payment products
Correct answer: To ensure critical payment operations can continue during and after a disruptive event
A BCP ensures that critical payment operations can be maintained or quickly restored during and after a disruptive event such as a system failure or natural disaster.
Question 4: Which metric is used to describe the maximum acceptable amount of time a payment system can be offline before causing serious business impact?
- Recovery Point Objective (RPO)
- Recovery Time Objective (RTO) (Correct answer)
- Mean Time Between Failures (MTBF)
- Service Level Agreement (SLA) uptime percentage
Correct answer: Recovery Time Objective (RTO)
Recovery Time Objective (RTO) defines the maximum acceptable downtime before resuming normal operations after a disruption.
Question 5: An APRP candidate is reviewing a risk register for a card payment network. What is the purpose of documenting residual risk?
- To identify new risks not yet assessed
- To show the risk remaining after controls have been applied (Correct answer)
- To calculate the gross exposure before any mitigations
- To list all historical fraud incidents for trend analysis
Correct answer: To show the risk remaining after controls have been applied
Residual risk is the level of risk that remains after existing controls and mitigations have been applied to the inherent risk.
Question 6: Which of the following is an example of a key risk indicator (KRI) specifically relevant to payment operations?
- Quarterly revenue from payment processing fees
- Number of failed authentication attempts per day (Correct answer)
- Annual employee satisfaction survey scores
- Total marketing spend on payment product campaigns
Correct answer: Number of failed authentication attempts per day
The number of failed authentication attempts per day is a KRI because it provides an early warning signal of potential fraud or system abuse in payment operations.
Which of the following best defines operational risk in the context of payment processing?