โ† All APRP Flashcard Decks

Risk Assessment & Mitigation Flashcards

7 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Assessment & Mitigation flashcards as text
  1. A payments organization wants to reduce inherent credit risk from merchants without exiting the relationship. Which mitigation tool is MOST directly targeted at this goal?

    Answer: Establishing a rolling reserve funded from merchant settlement proceeds

    A rolling reserve withholds a percentage of merchant proceeds to create a buffer that covers potential chargebacks or losses without terminating the relationship.

  2. In the NIST Cybersecurity Framework, which function focuses on developing and implementing activities to limit or contain the impact of a cybersecurity event?

    Answer: Respond

    The 'Respond' function in the NIST CSF covers activities to contain the impact of an incident, including response planning, communications, and mitigation.

  3. Which card brand program places merchants at risk of fines and additional scrutiny when they persistently exceed dispute ratio thresholds?

    Answer: The Visa Dispute Monitoring Program (VDMP) and Mastercard Excessive Chargeback Program (ECP)

    VDMP (Visa) and ECP (Mastercard) impose graduated fines and may lead to merchant disqualification when chargeback thresholds are repeatedly breached.

  4. What is the primary purpose of scenario analysis in operational risk assessment for a payments firm?

    Answer: To estimate potential losses from severe but plausible events not captured in historical loss data

    Scenario analysis helps organizations estimate the potential impact of rare, high-severity events (e.g., major cyberattack) for which historical loss data may be insufficient.

  5. A financial institution identifies that a payment gateway vendor's contract lacks a right-to-audit clause. This gap creates PRIMARILY which type of risk?

    Answer: Third-party/vendor risk with compliance and oversight implications

    Without a right-to-audit clause, the institution cannot independently verify the vendor's controls, creating blind spots in third-party risk management and potential regulatory exposure.

  6. Which technique involves systematically identifying all the ways a process could fail and then prioritizing those failures by severity and detectability?

    Answer: Failure Mode and Effects Analysis (FMEA)

    FMEA evaluates each potential failure mode, rates its severity, occurrence probability, and detectability to calculate a Risk Priority Number (RPN) for prioritization.

  7. For a US payments organization, which regulatory body has primary supervisory authority over unfair, deceptive, or abusive acts or practices (UDAAP) in consumer financial products?

    Answer: The Consumer Financial Protection Bureau (CFPB)

    The CFPB holds primary UDAAP authority over most consumer financial products and services under the Dodd-Frank Act.