โ† All CCB Flashcard Decks

Operational Risk & Control Testing Flashcards

7 cards from real CCB practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Operational Risk & Control Testing flashcards as text
  1. A compliance officer reviews a control testing workpaper and notices the tester documented 'no exceptions found' but did not retain evidence of the sample reviewed. What is the main deficiency?

    Answer: The test conclusion is not supportable without evidence of work performed

    Without retaining evidence of the sample reviewed, the testing conclusion cannot be independently verified or supported in the event of an audit or review.

  2. Which of the following best describes the 'four-eyes principle' in operational risk control?

    Answer: Requiring two independent individuals to review and approve a critical transaction or decision

    The four-eyes principle mandates that at least two people must independently review and authorize significant actions to reduce the risk of errors or fraud.

  3. A bank's operational risk team is categorizing a loss event where a rogue trader bypassed internal controls to hide trading losses. Under Basel event type classifications, this falls under:

    Answer: Internal Fraud

    Unauthorized trading by an employee to conceal losses is classified as Internal Fraud under Basel operational risk event type categories.

  4. What is the primary purpose of an operational risk control inventory?

    Answer: To catalogue all controls mapped to specific risks so gaps and redundancies can be identified

    A control inventory provides a comprehensive list of controls linked to risks, enabling organizations to spot where coverage is missing or where controls overlap unnecessarily.

  5. When performing a 'test of design' for an operational control, a compliance officer is evaluating whether:

    Answer: The control, if operating as intended, would effectively mitigate the identified risk

    A test of design assesses whether the control is conceptually capable of addressing the risk, separate from whether it is actually being performed.

  6. A compliance manager is tasked with assessing operational risk in a newly launched digital payment product. Which framework component should be completed first?

    Answer: Risk and control self-assessment (RCSA) for the new product

    An RCSA should be conducted at product launch to identify and assess the inherent risks and evaluate whether existing controls are adequate before operations begin.

  7. Under the COSO ERM framework, which component focuses on an organization's policies, procedures, and mechanisms to ensure that risk responses are carried out effectively?

    Answer: Control Activities

    Control Activities under COSO ERM are the policies and procedures that help ensure management's risk responses are executed effectively across the organization.