APRP Payments Risk Policy & Governance — Questions and Answers
Question 1: What is the PRIMARY purpose of a payments risk governance framework within a financial institution?
- To establish clear accountability, oversight, and decision-making authority for managing payments risk (Correct answer)
- To eliminate all payment-related losses within the fiscal year
- To reduce compliance staffing costs by consolidating risk functions
- To maximize transaction volume by streamlining approval processes
Correct answer: To establish clear accountability, oversight, and decision-making authority for managing payments risk
A risk governance framework exists to define who is responsible for identifying, managing, and escalating payments risk — ensuring accountability flows from the board down through management to operational staff. It does not aim to eliminate all loss or reduce headcount.
Question 2: In a payments organization, which body typically holds ULTIMATE responsibility for approving the enterprise risk appetite statement?
- The Chief Compliance Officer
- The internal audit department
- The board of directors (Correct answer)
- The ACH operations manager
Correct answer: The board of directors
The board of directors bears ultimate fiduciary responsibility for the organization, including approving the overall risk appetite. Management implements board-approved policies; internal audit provides independent assurance; the CCO oversees day-to-day compliance.
Question 3: Under the 'three lines of defense' model, which group provides INDEPENDENT assurance that risk controls are effective?
- Business unit managers (first line)
- Risk management and compliance functions (second line)
- Internal audit (third line) (Correct answer)
- External regulators
Correct answer: Internal audit (third line)
Internal audit is the third line of defense, providing independent, objective assurance over the effectiveness of risk management and controls. The first line owns and manages risks; the second line oversees and provides guidance; internal audit independently validates both.
Question 4: A payments risk policy document should PRIMARILY define which of the following?
- The dollar limits for every individual customer transaction type
- The scope, objectives, roles, and responsibilities for managing payments risk (Correct answer)
- A complete log of all active fraud investigations
- Technical specifications for the payment processing platform
Correct answer: The scope, objectives, roles, and responsibilities for managing payments risk
Risk policies establish the 'what and who' — scope, objectives, accountability, and high-level requirements. Specific transaction limits belong in procedures or risk appetite statements; fraud logs are operational records; technical specs belong in system documentation.
Question 5: A risk appetite statement in the context of payments risk management is BEST described as:
- A historical report of all payment losses incurred in the prior fiscal year
- A regulatory filing submitted annually to the Consumer Financial Protection Bureau
- A statement articulating how much risk the organization is willing to accept in pursuit of its business objectives (Correct answer)
- A customer-facing disclosure about payment processing fees and security practices
Correct answer: A statement articulating how much risk the organization is willing to accept in pursuit of its business objectives
A risk appetite statement is a forward-looking governance document that defines the level and types of risk senior leadership and the board are willing to tolerate. It guides strategic and operational decisions and is internal, not a regulatory filing or customer disclosure.
Question 6: Which of the following activities is the responsibility of SENIOR MANAGEMENT rather than the board of directors in a payments risk governance structure?
- Approving the organization's overall risk appetite
- Implementing board-approved payments risk policies and procedures (Correct answer)
- Providing independent audit assurance on control effectiveness
- Setting the organization's long-term strategic risk tolerance
Correct answer: Implementing board-approved payments risk policies and procedures
Senior management translates board-approved policies into operational procedures and ensures they are carried out. The board sets and approves risk appetite and strategy; independent audit assurance is the role of internal audit, not management.
What is the PRIMARY purpose of a payments risk governance framework within a financial institution?