โ† All CCB Flashcard Decks

Operational Risk & Control Testing Flashcards

7 cards from real CCB practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Operational Risk & Control Testing flashcards as text
  1. A compliance officer discovers that a control test was performed using a sample size of 5 out of 10,000 transactions. What is the primary concern?

    Answer: The sample size is insufficient for statistical reliability

    A sample of 5 from 10,000 transactions is statistically too small to draw reliable conclusions about the effectiveness of the control.

  2. Which control testing approach involves reviewing documentation, logs, and records without directly observing the process?

    Answer: Inspection testing

    Inspection testing involves examining documents, records, and reports to verify that a control exists and has been applied.

  3. A company's key risk indicator (KRI) for trade error rates exceeds its threshold for three consecutive months. What should the compliance team do first?

    Answer: Conduct a root cause analysis to identify the underlying issue

    A persistent KRI breach requires a root cause analysis to understand why the control is failing before any corrective action is taken.

  4. In the context of operational risk, what does a 'near miss' event represent?

    Answer: An event that could have caused a loss but did not

    A near miss is an event where a loss was averted, often through luck or a compensating control, and it signals a real underlying risk.

  5. Which of the following best describes a 'compensating control'?

    Answer: An alternative control that mitigates risk when the primary control is absent or weak

    A compensating control is a secondary safeguard designed to reduce risk when a primary control cannot be fully implemented.

  6. An operational risk assessment reveals that a critical process relies on a single employee with no backup. This is best categorized as which type of risk?

    Answer: Key person risk (a form of operational risk)

    Dependence on a single person without succession planning is a key person risk, which falls under operational risk related to human resources.

  7. What is the purpose of a control self-assessment (CSA)?

    Answer: To enable business units to evaluate the effectiveness of their own controls

    A CSA is a process by which management and staff identify and evaluate risks and controls within their own business units.