← All APRP Flashcard Decks

Risk Assessment & Mitigation Flashcards

6 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Risk Assessment & Mitigation flashcards as text
  1. What is a payment risk assessment?

    Answer: A systematic evaluation of threats, vulnerabilities, and potential impacts to the payment system and its stakeholders

    Payment risk assessment identifies and evaluates threats (fraud, cyber attacks, operational failures), assesses vulnerabilities in systems and processes, and quantifies potential financial and reputational impacts.

  2. What is a chargeback and how does it impact merchants?

    Answer: A transaction reversal initiated by the cardholder's bank, resulting in the merchant losing the sale amount plus fees

    Chargebacks reverse transactions, with merchants losing the sale revenue, goods/services, and paying chargeback fees. Excessive chargebacks can result in higher processing rates or account termination.

  3. What is the role of velocity checking in payment risk management?

    Answer: Monitoring the frequency and speed of transactions to detect unusual patterns that may indicate fraud

    Velocity checks monitor transaction frequency, amount, and timing patterns to identify potential fraud — such as multiple rapid transactions on the same card or from the same IP address.

  4. What is the purpose of a fraud investigation?

    Answer: To determine whether a suspected fraudulent transaction is confirmed fraud, gather evidence, and prevent future occurrences

    Fraud investigations verify whether fraud occurred, identify perpetrators, document evidence for potential prosecution, recover losses where possible, and identify system improvements to prevent recurrence.

  5. What is cyber insurance for payment companies?

    Answer: Insurance coverage protecting against financial losses from cyber attacks, data breaches, and system failures

    Cyber insurance covers financial losses from data breaches (notification costs, legal fees, regulatory fines), business interruption from cyber attacks, and third-party liability for compromised customer data.

  6. What is the principle of defense in depth for payment security?

    Answer: Multiple layers of security controls so that if one layer fails, others continue to protect the system

    Defense in depth employs multiple security layers (firewalls, encryption, access controls, monitoring, physical security) so that no single point of failure can compromise the entire payment system.