Certified Bank Auditor (CBA) โ Questions and Answers
Question 1: A bank holds a large portfolio of mortgage-servicing rights (MSRs), which it values using a discounted cash flow model. This model uses significant unobservable inputs, including assumptions about future mortgage prepayment speeds and default rates. According to ASC 820, Fair Value Measurement, these MSRs would be classified in which level of the fair value hierarchy?
- Level 2
- Level 4
- Level 3 (Correct answer)
- Level 1
Correct answer: Level 3
The fair value hierarchy under ASC 820 is based on the observability of inputs used in valuation. Level 1 uses quoted prices in active markets. Level 2 uses other observable inputs. Level 3 uses unobservable inputs, which are inputs developed by the entity using the best information available about assumptions market participants would use. Since the MSR valuation relies on significant unobservable inputs like prepayment speed assumptions, they are classified as Level 3 assets.
Question 2: Which governance document typically defines the scope of authority delegated from the board to senior management?
- Recovery and Resolution Plan
- Capital Adequacy Assessment
- Delegation of Authority Matrix (Correct answer)
- Liquidity Contingency Plan
Correct answer: Delegation of Authority Matrix
A Delegation of Authority Matrix formally specifies which decisions management can make independently versus those requiring board approval.
Question 3: During a CRA compliance audit of a large bank, which performance test carries the greatest weight in the overall CRA rating?
- The Community Development test
- The Investment test
- The Lending test (Correct answer)
- The Service test
Correct answer: The Lending test
For large banks, the Lending test carries the most weight in the overall CRA rating, reflecting that loans are the primary means by which banks help meet community credit needs.
Question 4: During an audit, the auditor finds several significant control deficiencies. After the draft audit report is issued, management provides a response that disagrees with the findings and refuses to develop a corrective action plan. What is the auditor's most appropriate next course of action?
- Accept management's position and close the audit.
- Immediately report the issue to external regulators without further discussion.
- Finalize the report with the original findings and management's response, and escalate the matter to the Audit Committee. (Correct answer)
- Remove the findings from the report to maintain a good relationship with management.
Correct answer: Finalize the report with the original findings and management's response, and escalate the matter to the Audit Committee.
The auditor's responsibility is to report findings objectively. If there is a disagreement with management, especially on significant issues, the matter must be escalated to those charged with governance, which is typically the Audit Committee. The final report should accurately reflect the auditor's findings and include management's official response. The Audit Committee has the ultimate authority to resolve such disputes and ensure appropriate action is taken.
Question 5: A bank's contingency funding plan (CFP) should be tested:
- Periodically and updated to reflect changes in the bank's business and market conditions (Correct answer)
- Once at inception and filed with regulators
- Only when a liquidity crisis is imminent
- Annually by external auditors only
Correct answer: Periodically and updated to reflect changes in the bank's business and market conditions
CFPs must be regularly tested and updated to remain effective; stale plans may fail when actually needed.
Question 6: Under FASB ASC 825, a bank elects the fair value option for certain financial instruments. Which statement is correct regarding audit implications?
- Fair value option elections reduce the complexity of financial statement audits
- The auditor must evaluate the bank's valuation techniques and key assumptions (Correct answer)
- The election is irrevocable and applies to all financial instruments in the same category
- Fair value changes are recognized in other comprehensive income only
Correct answer: The auditor must evaluate the bank's valuation techniques and key assumptions
When the fair value option is elected, the auditor must assess the appropriateness of valuation methodologies, inputs, and assumptions used to determine fair value.
Question 7: Which of the following activities is a primary focus for an auditor when evaluating a bank's compliance with the Community Reinvestment Act (CRA)?
- Evaluating the adequacy of the bank's capital reserves in relation to its risk-weighted assets.
- Assessing the bank's performance in meeting the credit needs of its entire community, including low- and moderate-income (LMI) neighborhoods. (Correct answer)
- Testing the effectiveness of the bank's cybersecurity controls for its online and mobile banking platforms.
- Confirming the accuracy and timeliness of Suspicious Activity Report (SAR) filings.
Correct answer: Assessing the bank's performance in meeting the credit needs of its entire community, including low- and moderate-income (LMI) neighborhoods.
The Community Reinvestment Act (CRA) was enacted to encourage financial institutions to help meet the credit needs of the communities in which they operate, with a particular emphasis on low- and moderate-income (LMI) neighborhoods. A CRA compliance audit, therefore, centers on evaluating the bank's lending, investment, and service performance within its designated assessment areas.
Question 8: Which AML typology involves using multiple businesses or individuals to convert drug proceeds into seemingly legitimate income?
- Black market peso exchange (Correct answer)
- Smurfing
- Round-tripping
- Trade-based money laundering
Correct answer: Black market peso exchange
The Black Market Peso Exchange is a method where drug proceeds in the US are used to purchase goods for export, converting criminal dollars into legitimate pesos through commercial transactions.
Question 9: A bank auditor reviewing ATM operations finds that ATM cassette loading is performed by a single technician with no witness present. Which risk does this control gap MOST directly create?
- System downtime risk
- Regulatory reporting failures
- Network connectivity loss
- Cash skimming or misappropriation (Correct answer)
Correct answer: Cash skimming or misappropriation
Without a witness during cassette loading, a single technician can pocket cash without detection, creating a theft risk.
Question 10: Which of the following is a key component of an effective compliance program?
- Frequent audits only
- Ongoing employee training (Correct answer)
- Outsourcing core operations
- External marketing support
Correct answer: Ongoing employee training
Ongoing employee training ensures that all staff understand and adhere to current laws, regulations, and internal policies.
Question 11: Which of the following best describes residual risk in a bank's risk management framework?
- The risk remaining after management controls and mitigants have been applied (Correct answer)
- The risk assigned to the internal audit function for monitoring
- The total gross risk before any controls are applied
- Risk transferred to a third party through insurance or derivatives
Correct answer: The risk remaining after management controls and mitigants have been applied
Residual risk is the exposure that remains after inherent risk is reduced by the effectiveness of existing controls.
Question 12: A bank IT auditor is testing controls over logical access to the general ledger system. Which test is MOST relevant?
- Reviewing software license counts
- Reviewing physical server room temperature logs
- Verifying that user access is provisioned based on documented job roles and approved by management (Correct answer)
- Testing network cable connections to the server
Correct answer: Verifying that user access is provisioned based on documented job roles and approved by management
Logical access controls must be tied to defined job roles with management approval to ensure the principle of least privilege is enforced.
Question 13: According to regulatory guidance, an effective Compliance Management System (CMS) is built upon several key pillars. Which of the following is considered the foundational component that establishes the 'tone at the top' for compliance?
- Board and management oversight. (Correct answer)
- Comprehensive consumer complaint response procedures.
- The selection of third-party compliance software.
- A detailed schedule for compliance training.
Correct answer: Board and management oversight.
Regulators consistently identify active and engaged board and management oversight as the cornerstone of an effective CMS. This includes demonstrating a clear commitment to compliance, adopting relevant policies, appointing a qualified compliance officer, and allocating sufficient resources to the compliance function.
Question 14: Which scenario BEST illustrates tail risk in banking?
- A 2% quarterly decline in consumer loan originations
- A minor processing error affecting 50 customer accounts
- A systemic financial crisis causing correlated defaults across the entire loan portfolio (Correct answer)
- A 10 basis point rise in short-term interest rates
Correct answer: A systemic financial crisis causing correlated defaults across the entire loan portfolio
Tail risk refers to extreme, low-probability events with severe consequences, such as a systemic crisis causing widespread correlated defaults.
Question 15: Under the Bank Secrecy Act, which of the following scenarios requires a bank to file a Suspicious Activity Report (SAR)?
- A $6,000 wire transfer to a known correspondent bank in Canada
- A $9,000 cash deposit made by a long-standing retail customer
- A series of transactions totaling $15,000 that appear structured to evade CTR reporting (Correct answer)
- A customer who declines to provide income documentation for a mortgage application
Correct answer: A series of transactions totaling $15,000 that appear structured to evade CTR reporting
Structuring transactions to avoid the CTR threshold is itself a federal crime (31 U.S.C. ยง 5324) and always requires SAR filing regardless of the dollar amounts.
Question 16: A bank's credit risk policy requires all commercial loans above $10M to receive an independent credit review before approval. An auditor finds 15% of loans in this tier bypassed the review. This is best classified as:
- An observation only, since the loans may still be performing adequately
- A material weakness because a key preventive control is failing at a material rate (Correct answer)
- A significant control deficiency because the bypass rate is below 20%
- A best-practice gap, since independent reviews are optional under OCC guidelines
Correct answer: A material weakness because a key preventive control is failing at a material rate
A 15% bypass rate on a mandatory pre-approval control for large loans represents a material breakdown in the credit risk governance framework.
Question 17: In many jurisdictions, corporate governance best practices recommend the separation of the Chief Executive Officer (CEO) and Board Chairperson roles. What is the primary governance advantage of this separation?
- It simplifies the day-to-day operational command structure for employees.
- It guarantees that the bank will meet all its regulatory capital requirements.
- It strengthens the board's independence and its ability to provide objective oversight of management. (Correct answer)
- It automatically reduces the operational expenses associated with the board of directors.
Correct answer: It strengthens the board's independence and its ability to provide objective oversight of management.
Separating the roles of CEO and Board Chair avoids concentrating excessive power in one individual. An independent chairperson can lead the board in its primary function of overseeing and evaluating the CEO and management team, which is a fundamental check and balance in a strong governance structure.
Question 18: Which type of bank fraud involves an employee creating fictitious loans to generate fraudulent commissions or misappropriate proceeds?
- Identity theft
- Loan origination fraud (Correct answer)
- Check kiting
- Embezzlement through payroll manipulation
Correct answer: Loan origination fraud
Loan origination fraud occurs when employees create fictitious or unsupported loans to earn commissions or divert loan proceeds for personal gain.
Question 19: Which of the following is the primary objective of a compliance audit focused on the Community Reinvestment Act (CRA)?
- To assess whether the bank is effectively meeting the credit needs of its entire community, including low- and moderate-income neighborhoods. (Correct answer)
- To confirm the accuracy and timeliness of the bank's quarterly financial reports to shareholders.
- To verify that the bank is not engaging in predatory lending practices in any of its operating areas.
- To ensure the bank has adequate controls to prevent money laundering and terrorist financing.
Correct answer: To assess whether the bank is effectively meeting the credit needs of its entire community, including low- and moderate-income neighborhoods.
The Community Reinvestment Act (CRA) was enacted to encourage federally insured banks to meet the credit needs of their entire communities, with a particular focus on low- and moderate-income (LMI) neighborhoods. A CRA audit evaluates the bank's performance in lending, investments, and services within these communities.
Question 20: What is 'say-on-pay' in the context of bank corporate governance?
- The CEO's authority to set compensation for direct reports
- A regulator's right to cap banker bonuses
- The board's power to approve compensation plans
- A shareholder vote on executive compensation packages (Correct answer)
Correct answer: A shareholder vote on executive compensation packages
Say-on-pay gives shareholders an advisory or binding vote on executive compensation, enhancing board accountability.
Question 21: Which of the following is the BEST indicator that a bank's account reconciliation controls are operating effectively?
- All reconciling items are researched and resolved within 30 days (Correct answer)
- The GL balance matches the prior month's balance
- Reconciliations are completed by branch managers monthly
- Reconciliation software produces automated exception reports
Correct answer: All reconciling items are researched and resolved within 30 days
Timely resolution of reconciling items demonstrates that exceptions are investigated and corrected, not just identified.
Question 22: An internal auditor testing dormant account controls discovers that several accounts have been reactivated and funds withdrawn without documented customer contact. This pattern MOST likely suggests:
- A system error in the dormancy classification logic
- Proper exercise of bank lien rights
- Potential employee fraud through unauthorized account reactivation (Correct answer)
- Compliance with state escheatment laws
Correct answer: Potential employee fraud through unauthorized account reactivation
Unauthorized reactivation of dormant accounts followed by withdrawals is a classic pattern of internal employee fraud.
Question 23: When auditing overdraft protection programs, the auditor should PRIMARILY evaluate whether the program complies with:
- FFIEC cybersecurity guidelines
- Regulation E opt-in requirements for ATM and one-time debit transactions (Correct answer)
- The Bank Secrecy Act
- Regulation D reserve requirements
Correct answer: Regulation E opt-in requirements for ATM and one-time debit transactions
Regulation E requires banks to obtain affirmative opt-in consent before charging overdraft fees on ATM and one-time debit card transactions.
Question 24: For a large, publicly traded financial institution, which of the following is MOST likely to be identified by the external auditor as a Critical Audit Matter (CAM) in the auditor's report?
- The review of the bank's compliance with physical security controls at branch locations.
- The valuation of the allowance for credit losses on the loan portfolio. (Correct answer)
- The testing of controls over the reconciliation of correspondent bank accounts.
- The verification of interest income on U.S. Treasury securities classified as held-to-maturity.
Correct answer: The valuation of the allowance for credit losses on the loan portfolio.
A CAM is a matter that involved especially challenging, subjective, or complex auditor judgment. The valuation of the allowance for credit losses, particularly under CECL, fits this definition perfectly. It involves complex models, significant management judgment regarding economic forecasts, and requires extensive audit effort and scrutiny, making it a prime candidate for a CAM.
Question 25: A Certified Bank Auditor is reviewing a bank's liquidity risk management framework. A key component of this framework is liquidity stress testing. Which of the following is a minimum requirement for the planning horizons that must be included in these stress tests according to U.S. federal regulations?
- 30-day, 60-day, 90-day, and 180-day.
- Overnight, 30-day, 90-day, and one-year. (Correct answer)
- Overnight, 7-day, 30-day, and 60-day.
- Weekly, monthly, quarterly, and annually.
Correct answer: Overnight, 30-day, 90-day, and one-year.
U.S. regulations for large banking organizations mandate that liquidity stress tests must be conducted for several time horizons. These must include, at a minimum, an overnight, a 30-day, a 90-day, and a one-year planning horizon, as well as any other horizons relevant to the institution's specific risk profile.
Question 26: A bank auditor reviewing the Net Stable Funding Ratio (NSFR) finds the ratio at 98%. What action is required?
- Disclosure to shareholders only; no regulatory reporting is triggered
- Immediate remediation; the NSFR minimum requirement of 100% is not met (Correct answer)
- No action; 98% exceeds the minimum 90% threshold
- The ratio is acceptable because it is within 5% of the 100% target
Correct answer: Immediate remediation; the NSFR minimum requirement of 100% is not met
The Basel III NSFR must be at least 100% at all times; a ratio below 100% indicates insufficient stable funding relative to required stable funding.
Question 27: The 'travel rule' in BSA/AML compliance requires banks to pass along certain information when transmitting funds. What is the minimum dollar threshold that triggers this rule?
- $5,000
- $10,000
- $1,000
- $3,000 (Correct answer)
Correct answer: $3,000
The Travel Rule (31 CFR 103.33) requires that banks include originator and beneficiary information for funds transfers of $3,000 or more.
Question 28: A bank auditor reviewing the ALCO process would PRIMARILY focus on whether:
- Employee incentive plans comply with HR policy
- Interest rate risk, liquidity risk, and capital adequacy are actively monitored and managed (Correct answer)
- IT infrastructure supports all banking applications
- Marketing strategies are aligned with deposit growth targets
Correct answer: Interest rate risk, liquidity risk, and capital adequacy are actively monitored and managed
The Asset-Liability Committee (ALCO) is responsible for managing interest rate risk, liquidity, and capitalโthe auditor assesses whether that governance is effective.
Question 29: An auditor is assessing a bank's risk appetite framework (RAF). A key attribute of an effective RAF is the clear assignment of roles and responsibilities. Which function is ultimately responsible for providing independent assurance to the board and senior management on the quality and effectiveness of the bank's risk management processes, including the RAF?
- The Asset-Liability Committee (ALCO)
- The internal audit function (Correct answer)
- The business line management
- The Chief Risk Officer (CRO)
Correct answer: The internal audit function
The internal audit function, as the third line of defense, plays a crucial role in providing independent assurance to the board and senior management. Its responsibilities include evaluating the effectiveness of the risk management and internal control systems, which encompasses the risk appetite framework. While the CRO, business lines, and ALCO are all critical to implementing and managing the RAF, internal audit provides the independent review and validation.
Question 30: Which metric measures the potential loss on a trading portfolio over a given time horizon at a specified confidence level?
- Return on Risk-Adjusted Capital (RORAC)
- Value at Risk (VaR) (Correct answer)
- Net Stable Funding Ratio (NSFR)
- Expected Loss (EL)
Correct answer: Value at Risk (VaR)
VaR quantifies the maximum expected loss over a specific period at a given confidence level (e.g., 99% over one day).
Question 31: An auditor is assessing the completeness assertion for off-balance-sheet exposures at a bank. Which procedure is most relevant?
- Recalculating the bank's risk-weighted assets under Basel III
- Testing interest income recorded on funded loans for accuracy
- Confirming outstanding loan balances with borrowers at year-end
- Reviewing unfunded commitment records and comparing to loan origination documentation (Correct answer)
Correct answer: Reviewing unfunded commitment records and comparing to loan origination documentation
Comparing unfunded commitment records to loan agreements ensures that all off-balance-sheet credit exposures are identified and properly disclosed.
Question 32: An auditor reviewing mortgage loan files finds that the bank consistently failed to provide the Loan Estimate within 3 business days of receiving a loan application. Which regulation is violated?
- Regulation B
- Regulation X (RESPA)
- Regulation C
- Regulation Z (TRID) (Correct answer)
Correct answer: Regulation Z (TRID)
Under TRID (TILA-RESPA Integrated Disclosure rules, Regulation Z), lenders must deliver the Loan Estimate within 3 business days of receiving a completed loan application.
Question 33: Which BEST describes the purpose of penetration testing in a bank's IT audit program?
- To test employee computer proficiency
- To simulate real-world attacks and identify exploitable vulnerabilities before malicious actors do (Correct answer)
- To measure network bandwidth capacity
- To validate software licensing compliance
Correct answer: To simulate real-world attacks and identify exploitable vulnerabilities before malicious actors do
Penetration testing proactively identifies vulnerabilities by simulating actual attacker techniques, allowing the bank to remediate weaknesses before they are exploited.
Question 34: Which disclosure is required under ASC 825 (Fair Value Option) when a bank elects to measure its own long-term debt at fair value?
- The cumulative unrealized gain or loss attributable to changes in the bank's own credit risk must be disclosed separately (Correct answer)
- Interest expense on the debt is eliminated from the income statement
- All debt must be reclassified to trading liabilities on the balance sheet face
- The fair value election can be reversed at any subsequent reporting date
Correct answer: The cumulative unrealized gain or loss attributable to changes in the bank's own credit risk must be disclosed separately
ASC 825 requires banks electing the fair value option to separately disclose the portion of fair value changes attributable to changes in their own credit risk, typically in OCI.
Question 35: Which report format is most appropriate when a bank's management engages a CPA firm to report on the design and operating effectiveness of controls at a bank's third-party data processor?
- A compilation report summarizing management's description of the service organization's controls
- A SOC 2 report covering security, availability, and confidentiality trust service criteria
- An agreed-upon procedures report limited to specific user bank transactions
- A SOC 1 Type 2 report covering controls relevant to user entities' financial reporting (Correct answer)
Correct answer: A SOC 1 Type 2 report covering controls relevant to user entities' financial reporting
A SOC 1 Type 2 report evaluates controls at a service organization that are relevant to user entities' internal control over financial reporting, which is what banks need for their data processors.
Question 36: During an audit of ACH operations, an auditor finds the bank lacks a formal return item monitoring process. The PRIMARY exposure is:
- Non-compliance with Check 21 requirements
- Failure to meet Regulation E disclosure timelines
- Increased cost of funds
- Violation of NACHA rules and potential financial loss from undetected unauthorized debits (Correct answer)
Correct answer: Violation of NACHA rules and potential financial loss from undetected unauthorized debits
NACHA rules impose return rate thresholds, and failure to monitor returns can result in financial loss and NACHA sanctions.
Question 37: Under Regulation CC, which of the following hold periods applies to a non-local check deposited by a new account holder (account opened fewer than 30 days)?
- Next business day
- Up to 9 business days (Correct answer)
- 5 business days
- 2 business days
Correct answer: Up to 9 business days
Regulation CC allows banks to impose an exception hold of up to 9 business days for new accounts to mitigate fraud risk.
Question 38: An auditor testing a bank's reconciliation controls finds that the reconciliation is prepared but never reviewed or approved. This represents:
- A significant deficiency due to missing supervisory review
- A design deficiency because the control is incomplete (Correct answer)
- A material weakness because reconciliations are ineffective
- Acceptable practice if discrepancies are below materiality threshold
Correct answer: A design deficiency because the control is incomplete
A reconciliation without supervisory review is a design deficiency because an effective reconciliation control requires both preparation and independent review.
Question 39: Which of the following activities is a key component of an IT governance framework within a financial institution?
- Ensuring that IT strategy is aligned with the bank's overall business strategy and objectives. (Correct answer)
- Installing and configuring antivirus software on all employee workstations.
- Performing penetration testing on external-facing applications.
- Daily reconciliation of nostro accounts.
Correct answer: Ensuring that IT strategy is aligned with the bank's overall business strategy and objectives.
IT governance is about ensuring that IT activities align with and support the business's overall goals. It involves leadership, organizational structures, and processes to ensure that the IT function sustains and extends the organization's strategies and objectives. While penetration testing and antivirus installation are important security operations, and reconciliation is a business process, the strategic alignment of IT with business objectives is the core purpose of IT governance.
Question 40: A bank's Board Risk Committee is reviewing documents as part of its quarterly meeting. Which of the following activities is a core responsibility of this committee?
- Recommending the appointment and remuneration of the external auditor to the full board.
- Overseeing the development and implementation of the bank's risk management framework and recommending the risk appetite for board approval. (Correct answer)
- Managing the bank's investment portfolio to maximize short-term returns.
- Approving individual loan applications that exceed the limits of front-line loan officers.
Correct answer: Overseeing the development and implementation of the bank's risk management framework and recommending the risk appetite for board approval.
The Board Risk Committee is responsible for assisting the board in its oversight of the bank's risk management framework. This includes defining the bank's risk appetite and tolerance levels for ultimate approval by the full board, and ensuring management has effective processes to identify, assess, and manage risks. Appointing the external auditor is the Audit Committee's role, while managing portfolios and approving loans are management functions.
Question 41: A bank's internal audit charter should PRIMARILY document which of the following?
- The purpose, authority, responsibility, and independence of internal audit (Correct answer)
- A list of all findings from the prior year's audit
- The names and qualifications of all internal auditors
- The detailed testing procedures for each audit area
Correct answer: The purpose, authority, responsibility, and independence of internal audit
The internal audit charter formally establishes the function's mandate, defines its authority to access records and personnel, and affirms its independence.
Question 42: Which of the following would be considered a 'red flag' under the FTC's Red Flags Rule when auditing an identity theft prevention program at a bank?
- A notice from a credit agency of a fraud alert on a customer's file (Correct answer)
- A customer requesting a stop payment on a check
- A customer updating their address at account opening
- A deposit of a government-issued check
Correct answer: A notice from a credit agency of a fraud alert on a customer's file
A fraud alert notice from a credit reporting agency is explicitly listed in the Red Flags Rule as a pattern, practice, or activity indicating possible identity theft.
Question 43: The 'three lines of defense' model assigns which role to the internal audit function?
- Third line โ provides independent assurance on the effectiveness of governance and controls (Correct answer)
- Fourth line โ serves as an independent advisor to the board
- First line โ owns and manages risks in business units
- Second line โ provides risk oversight and compliance monitoring
Correct answer: Third line โ provides independent assurance on the effectiveness of governance and controls
Internal audit is the third line of defense, providing independent assurance to the board and senior management on governance, risk management, and control effectiveness.
Question 44: The Chief Audit Executive (CAE) of a large commercial bank is developing the annual audit plan. Which of the following is the MOST critical first step in establishing the scope and priorities for the upcoming audit cycle?
- Conducting a comprehensive, bank-wide risk assessment to identify and rank high-risk areas. (Correct answer)
- Reviewing the findings and recommendations from the prior year's audit reports.
- Evaluating the current staffing levels and technical expertise of the internal audit department.
- Meeting with the Board of Directors' Audit Committee to understand their primary concerns.
Correct answer: Conducting a comprehensive, bank-wide risk assessment to identify and rank high-risk areas.
A risk-based approach is fundamental to modern internal auditing in banking. The initial step should be a comprehensive risk assessment to ensure that audit resources are focused on the areas that pose the greatest threat to the bank's objectives. While prior audit findings, board concerns, and staff capabilities are all important inputs, they are best considered within the context of the overall risk landscape identified by the assessment.
Question 45: Under the Dodd-Frank Act, systemically important financial institutions (SIFIs) are subject to enhanced prudential standards primarily to:
- Limit competition in consumer banking markets
- Standardize internal audit methodologies across large banks
- Maximize shareholder returns during economic expansions
- Reduce the risk that their failure could destabilize the broader financial system (Correct answer)
Correct answer: Reduce the risk that their failure could destabilize the broader financial system
Enhanced prudential standards for SIFIs are designed to reduce systemic risk and prevent the spillover of a large institution's failure.
Question 46: Under the Federal Deposit Insurance Corporation Improvement Act (FDICIA), for insured depository institutions with total assets exceeding a specified threshold, what is the external auditor required to issue an opinion on?
- The accuracy of the bank's quarterly Consolidated Reports of Condition and Income (Call Reports).
- The bank's compliance with all applicable safety and soundness regulations.
- The effectiveness of the bank's enterprise risk management program.
- Management's assessment of the effectiveness of internal control over financial reporting. (Correct answer)
Correct answer: Management's assessment of the effectiveness of internal control over financial reporting.
FDICIA Section 112 requires management of larger institutions to prepare an annual report assessing the effectiveness of the institution's internal control over financial reporting (ICFR). The institution's external auditor is then required to provide a direct examination and attestation report, issuing an opinion on management's assertion regarding ICFR.
Question 47: During a review of a bank's risk management framework, an auditor notes that the board of directors has delegated oversight of risk management activities to an audit committee. Which of the following is a primary responsibility of the audit committee in this role?
- Designing and implementing the bank's internal control system.
- Executing the day-to-day risk mitigation and control activities.
- Setting the bank's overall risk appetite and strategic objectives.
- Ensuring the independence and effectiveness of the internal and external audit functions. (Correct answer)
Correct answer: Ensuring the independence and effectiveness of the internal and external audit functions.
The audit committee's primary role in risk management oversight is to ensure the independence and assess the performance of the internal and external auditors. This provides the board with independent assurance that risk management processes are effective. Day-to-day execution and system design are management's responsibilities, while setting the risk appetite is a core function of the full board of directors.
Question 48: When conducting a fair lending statistical analysis, an auditor compares loan approval rates between similarly qualified minority and non-minority applicants. This methodology is known as:
- Pricing disparity concentration analysis
- Regression-based comparative file review
- Overt discrimination mapping
- Disparate treatment analysis using matched-pair testing (Correct answer)
Correct answer: Disparate treatment analysis using matched-pair testing
Matched-pair testing (disparate treatment analysis) compares outcomes for applicants with substantially similar credit profiles across protected and non-protected classes.
Question 49: How does diversification help in risk management?
- Eliminates all risks
- Reduces risk by spreading exposure (Correct answer)
- Increases return on equity
- Minimizes tax liabilities
Correct answer: Reduces risk by spreading exposure
Diversification spreads investments across various assets, reducing exposure to any single source of risk.
Question 50: A bank's governance framework should include a formal board succession plan primarily because:
- It reduces the need to hold annual general meetings
- Succession planning is only relevant for executive management, not directors
- Planned transitions ensure continuity of oversight expertise and reduce governance gaps (Correct answer)
- Regulators require the same directors to serve for at least 10 years
Correct answer: Planned transitions ensure continuity of oversight expertise and reduce governance gaps
Board succession planning ensures that critical skills and experience are retained and governance continuity is maintained when directors retire or leave.
Question 51: Under the Basel Committee's corporate governance principles, the board of directors is responsible for:
- Approving all individual loan decisions
- Day-to-day operational management
- Setting the bank's risk appetite and overseeing senior management (Correct answer)
- Conducting internal audits independently
Correct answer: Setting the bank's risk appetite and overseeing senior management
The Basel Committee assigns the board responsibility for setting risk appetite and providing effective oversight of senior management.
Question 52: Which risk management technique involves assigning probability distributions to uncertain variables to assess the range of possible outcomes?
- Scenario analysis
- Stress testing
- Monte Carlo simulation (Correct answer)
- Gap analysis
Correct answer: Monte Carlo simulation
Monte Carlo simulation uses random sampling across probability distributions to model the range of possible financial outcomes.
Question 53: During an audit of investment securities, an auditor finds that a bank reclassified securities from available-for-sale (AFS) to held-to-maturity (HTM). What is the primary audit concern?
- Whether the reclassification increases the bank's reported capital ratios
- Whether unrealized gains were appropriately recognized at reclassification
- Whether the bank has the positive intent and ability to hold the securities to maturity (Correct answer)
- Whether the reclassification was approved by the board of directors
Correct answer: Whether the bank has the positive intent and ability to hold the securities to maturity
Reclassification to HTM requires management to demonstrate genuine positive intent and ability to hold securities to maturity, which the auditor must evaluate.
Question 54: Which of the following is a key difference between a compliance risk assessment and a compliance audit?
- A risk assessment identifies and prioritizes compliance risks, while an audit provides independent testing and verification of controls (Correct answer)
- There is no functional difference โ the terms are interchangeable in banking
- A risk assessment tests specific transactions while an audit evaluates policies only
- A compliance audit is performed by management while a risk assessment is performed by internal audit
Correct answer: A risk assessment identifies and prioritizes compliance risks, while an audit provides independent testing and verification of controls
Risk assessments identify and rank potential compliance exposures to guide audit focus, while audits independently test whether controls are operating effectively.
Question 55: During an audit of a bank's interest rate risk management, the auditor finds that the Asset-Liability Committee (ALCO) meets quarterly but last reviewed the interest rate risk limits 18 months ago. This represents a deficiency in:
- Trading book management
- Risk limit governance and periodic review (Correct answer)
- Liquidity stress testing
- Capital adequacy assessment
Correct answer: Risk limit governance and periodic review
Interest rate risk limits should be reviewed at least annually; an 18-month gap indicates a governance breakdown in the ALCO's limit review responsibilities.
Question 56: Which of the following is a key function of a bank's Nominations and Governance Committee?
- Managing relationships with primary regulators on a daily basis
- Approving all new product launches
- Identifying and recommending candidates for board membership (Correct answer)
- Setting the bank's credit underwriting standards
Correct answer: Identifying and recommending candidates for board membership
The Nominations and Governance Committee oversees board composition, succession planning, and governance practices.
Question 57: The regulatory requirement that prohibits banks from engaging in proprietary trading for their own profit using customer deposits is known as the:
- Volcker Rule (Correct answer)
- Glass-Steagall Act provisions
- Basel IV trading book restrictions
- Dodd-Frank Section 165
Correct answer: Volcker Rule
The Volcker Rule, part of Dodd-Frank, restricts banks from proprietary trading and limits their investments in hedge funds and private equity.
Question 58: What is 'account takeover' fraud in the banking context?
- A bank migrating customer accounts to a new core banking platform
- A bank freezing or restricting a delinquent customer's account access
- A fraudster gaining unauthorized control of a customer's account to conduct unauthorized transactions (Correct answer)
- A legitimate corporate acquisition that transfers ownership of banking accounts
Correct answer: A fraudster gaining unauthorized control of a customer's account to conduct unauthorized transactions
Account takeover occurs when a fraudster obtains a legitimate customer's credentials or authentication information and uses them to assume control of the account and conduct unauthorized transactions.
Question 59: Which regulatory body published the 'Principles for Enhancing Corporate Governance' that are widely used as a global benchmark for banks?
- International Monetary Fund (IMF)
- U.S. Securities and Exchange Commission (SEC)
- Basel Committee on Banking Supervision (BCBS) (Correct answer)
- Financial Accounting Standards Board (FASB)
Correct answer: Basel Committee on Banking Supervision (BCBS)
The Basel Committee on Banking Supervision published the Principles for Enhancing Corporate Governance, providing the primary global standard for bank boards.
Question 60: Which type of internal control is BEST suited to prevent a teller from disbursing cash without a corresponding transaction record?
- Preventive control through system-enforced transaction logging (Correct answer)
- Directive control through written teller procedures
- Corrective control through overdraft reversals
- Detective control through daily cash counts
Correct answer: Preventive control through system-enforced transaction logging
A system-enforced transaction log prevents cash disbursements from occurring without a corresponding recorded entry, stopping the error or fraud before it happens.
Question 61: Which regulatory guidance specifically addresses the audit committee's oversight responsibilities for internal controls at U.S. banks?
- FASB ASC 310 on Receivables
- SEC Regulation S-X
- OCC Handbook on Corporate and Risk Governance (Correct answer)
- Basel III Capital Accord
Correct answer: OCC Handbook on Corporate and Risk Governance
The OCC Handbook on Corporate and Risk Governance outlines expectations for board and audit committee oversight of internal controls at national banks.
Question 62: A politically exposed person (PEP) is subject to enhanced due diligence because they:
- Typically conduct high-volume transactions that require extra review
- Pose higher AML risk due to potential for corruption and abuse of public positions (Correct answer)
- Are required by law to disclose all financial accounts
- Are more likely to be targets of identity theft
Correct answer: Pose higher AML risk due to potential for corruption and abuse of public positions
PEPs are considered higher risk because their public positions of trust create vulnerability to corruption, bribery, and misappropriation of public funds.
Question 63: A bank's compliance audit reveals that loan officers have been redlining minority neighborhoods. Which law is most directly violated?
- Gramm-Leach-Bliley Act
- Bank Secrecy Act
- Truth in Lending Act
- Equal Credit Opportunity Act (Correct answer)
Correct answer: Equal Credit Opportunity Act
Redlining violates the Equal Credit Opportunity Act (ECOA), which prohibits discrimination in credit decisions based on race or national origin.
Question 64: Which of the following is a primary objective of auditing IT General Controls (ITGCs) within a financial institution?
- To ensure the accuracy of specific calculations within a loan amortization application.
- To provide reasonable assurance that the overall IT control environment is effective and supports the reliability of application controls. (Correct answer)
- To verify that all employees have completed annual cybersecurity training.
- To test the effectiveness of the bank's marketing campaigns on social media platforms.
Correct answer: To provide reasonable assurance that the overall IT control environment is effective and supports the reliability of application controls.
ITGCs form the foundation of the IT control structure. They are the policies and procedures that apply to all or a large segment of the institution's information systems and help ensure their continued, proper operation. A strong ITGC environment is necessary for application controls (which are specific to individual software) to be effective and reliable. Auditing ITGCs addresses the framework within which applications and data are managed.
Question 65: An internal auditor discovers that a bank's compliance risk assessment does not include an evaluation of newly enacted consumer protection regulations. This gap most directly reflects a failure in:
- Operational loss event reporting
- The regulatory change management process within the compliance risk framework (Correct answer)
- Credit risk quantification
- Market risk hedging strategies
Correct answer: The regulatory change management process within the compliance risk framework
A compliance risk assessment must capture regulatory changes through a structured change management process to ensure new requirements are identified and addressed timely.
Question 66: A bank auditor is reviewing IT controls for a recent merger integration. What is the MOST important IT risk to assess during system consolidation?
- Employee desk phone system compatibility
- Office furniture allocation for the merged entity
- Printer sharing configurations between offices
- Data integrity and the risk of data corruption or loss during migration (Correct answer)
Correct answer: Data integrity and the risk of data corruption or loss during migration
System consolidation during mergers carries high risk of data corruption, data loss, and integrity failures that can affect financial reporting and operations.
Question 67: When auditing interest rate risk in the banking book (IRRBB), what does an EVE (Economic Value of Equity) measure capture?
- The regulatory capital required under Pillar 1 for market risk
- The present value impact of rate shocks on the bank's entire balance sheet (Correct answer)
- The net interest income forecast for the current fiscal year
- The bank's short-term earnings sensitivity to rate changes over the next 12 months
Correct answer: The present value impact of rate shocks on the bank's entire balance sheet
EVE measures the change in the economic value of all assets, liabilities, and off-balance-sheet items in response to interest rate shocks.
Question 68: During an audit, it is noted that a bank's senior executives consistently prioritize short-term profit goals, leading to the dismissal of compliance concerns and a high-pressure sales environment. This observation is MOST indicative of a weakness in which corporate governance element?
- The formal structure of the board's compensation committee.
- The effectiveness of the internal audit charter.
- The adequacy of the bank's business continuity plan.
- The 'tone at the top' set by leadership. (Correct answer)
Correct answer: The 'tone at the top' set by leadership.
'Tone at the top' refers to the ethical climate established by the board and senior management. When leadership demonstrates through their actions and priorities that ethics and compliance are secondary to profits, it creates a poor ethical culture that permeates the organization.
Question 69: A bank's risk appetite statement should primarily be approved and owned by which group?
- Board of directors (Correct answer)
- Chief Risk Officer alone
- External auditors
- Internal audit committee
Correct answer: Board of directors
The board of directors is responsible for approving and owning the bank's risk appetite statement as part of its governance obligations.
Question 70: During a disaster recovery test, a bank's IT systems are restored but customer transaction data is missing for the last 4 hours before the declared disaster. Which metric was NOT achieved?
- Mean Time to Repair (MTTR)
- Recovery Time Objective (RTO)
- System Availability SLA
- Recovery Point Objective (RPO) (Correct answer)
Correct answer: Recovery Point Objective (RPO)
RPO defines the maximum acceptable data loss measured in time; missing 4 hours of transaction data indicates the backup frequency did not meet the defined RPO.
Question 71: Under the Dodd-Frank Act, which agency has primary rulemaking authority for consumer financial protection regulations affecting large banks?
- OCC
- Federal Reserve
- FDIC
- CFPB (Correct answer)
Correct answer: CFPB
The Consumer Financial Protection Bureau (CFPB) was created by Dodd-Frank and holds primary rulemaking authority for consumer financial protection laws applicable to large banks.
Question 72: How does the concept of 'board information asymmetry' threaten effective bank governance?
- Management controlling what information reaches the board can limit effective oversight (Correct answer)
- Directors receiving too much information become overly involved in operations
- Information asymmetry only matters in publicly traded banks, not private ones
- Directors from different backgrounds interpret information differently, causing deadlock
Correct answer: Management controlling what information reaches the board can limit effective oversight
When management filters or selectively presents information to the board, directors cannot provide informed oversight or effective challenge.
Question 73: Which approach under Basel III for credit risk uses external credit ratings to assign risk weights to exposures?
- Standardized Approach (SA) (Correct answer)
- Advanced Measurement Approach (AMA)
- Foundation IRB approach
- Internal Ratings-Based (IRB) approach
Correct answer: Standardized Approach (SA)
The Standardized Approach maps exposures to risk weights based on external credit ratings from recognized rating agencies.
Question 74: In evaluating the design adequacy of a control, an auditor is assessing whether:
- Employees have been trained on how to perform the control
- The control has been operating consistently for at least one year
- Management has documented the control in written policies
- The control, if operating as intended, would effectively mitigate the risk (Correct answer)
Correct answer: The control, if operating as intended, would effectively mitigate the risk
Design adequacy assesses whether a control is theoretically capable of preventing or detecting a misstatement or risk if it operates as intended.
Question 75: What is a red flag during an audit of teller operations?
- Low ATM usage
- Late shift changes
- Frequent cash discrepancies (Correct answer)
- High customer footfall
Correct answer: Frequent cash discrepancies
Frequent cash discrepancies could indicate poor internal controls or potential fraud, requiring immediate investigation.
Question 76: Under RESPA (Real Estate Settlement Procedures Act), which practice is explicitly prohibited?
- Requiring escrow accounts for property taxes and insurance
- Charging origination fees for mortgage loans
- Providing a good faith estimate of settlement costs
- Paying kickbacks or referral fees between settlement service providers (Correct answer)
Correct answer: Paying kickbacks or referral fees between settlement service providers
RESPA Section 8 prohibits the payment or receipt of kickbacks and unearned fees between settlement service providers, such as referral fees between lenders and title companies.
Question 77: The Risk Appetite Statement (RAS) should be MOST closely aligned with:
- The bank's strategic plan and business model (Correct answer)
- Competitor risk benchmarks
- The bank's internal audit plan
- Regulatory capital minimums
Correct answer: The bank's strategic plan and business model
An effective RAS links the amount of risk a bank is willing to accept to achieving its strategic objectives.
Question 78: What does a high debt-to-equity ratio indicate?
- Strong equity base
- Low financial leverage
- Improved liquidity
- Potential financial risk (Correct answer)
Correct answer: Potential financial risk
A high debt-to-equity ratio may indicate higher financial risk due to greater reliance on borrowed funds.
Question 79: Which of the following board compositions would BEST reflect sound corporate governance at a publicly traded bank?
- Majority insider directors with deep operational knowledge
- Majority independent directors with diverse expertise (Correct answer)
- All directors drawn from the financial services industry
- Directors who are also the bank's largest shareholders
Correct answer: Majority independent directors with diverse expertise
A majority of independent directors with varied expertise reduces conflicts of interest and improves objective oversight.
Question 80: Which BEST describes the role of a bank IT auditor when reviewing a new fintech partnership?
- Approving the commercial terms of the partnership agreement
- Setting the fintech partner's information security policies
- Assessing whether adequate due diligence and ongoing monitoring controls exist for the third-party relationship (Correct answer)
- Developing the technical integration specifications
Correct answer: Assessing whether adequate due diligence and ongoing monitoring controls exist for the third-party relationship
IT auditors assess whether the bank has performed adequate due diligence and established ongoing monitoring to manage risks introduced by third-party fintech relationships.
Question 81: A bank's net interest margin (NIM) declines when interest rates rise unexpectedly. This is an example of which risk?
- Liquidity risk
- Credit risk
- Interest rate risk in the banking book (IRRBB) (Correct answer)
- Operational risk
Correct answer: Interest rate risk in the banking book (IRRBB)
IRRBB captures the adverse impact of interest rate movements on a bank's net interest income and economic value.
Question 82: A bank's internal audit department is conducting a review of the Business Continuity Plan (BCP). A key component of this audit is to evaluate the Recovery Time Objective (RTO) and Recovery Point Objective (RPO) for critical systems. What is the primary purpose of the RTO?
- To calculate the total financial cost associated with a system outage.
- To define the target time within which a business process must be restored after a disaster to avoid unacceptable consequences. (Correct answer)
- To determine the maximum amount of data, measured in time, that can be lost after a disruption.
- To specify the minimum frequency for conducting BCP tests and exercises.
Correct answer: To define the target time within which a business process must be restored after a disaster to avoid unacceptable consequences.
The Recovery Time Objective (RTO) is a crucial metric in business continuity planning that defines the maximum acceptable length of time that can elapse before a specific business function must be restored after a disaster or disruption to avoid significant impact on the organization. The RPO, by contrast, relates to the acceptable amount of data loss.
Question 83: A bank auditor is evaluating goodwill impairment testing under ASC 350. Which triggering event would require an interim impairment test between annual testing dates?
- A change in the external auditor assigned to the engagement
- Management's plan to restructure a minor administrative function
- A significant regulatory action that negatively impacts the reporting unit's operations (Correct answer)
- A 5% decline in the bank's stock price during the quarter
Correct answer: A significant regulatory action that negatively impacts the reporting unit's operations
A significant adverse regulatory action is a qualitative triggering event that makes it more likely than not that the fair value of a reporting unit has declined below its carrying amount.
Question 84: Which committee is primarily responsible for overseeing a bank's financial reporting and internal controls?
- Nominations Committee
- Compensation Committee
- Risk Committee
- Audit Committee (Correct answer)
Correct answer: Audit Committee
The Audit Committee is responsible for overseeing financial reporting integrity, internal controls, and external auditor relationships.
Question 85: Which audit procedure best tests the effectiveness of a bank's third-party risk management program?
- Reviewing contracts for standard indemnification clauses
- Confirming that all vendors have completed onboarding paperwork
- Verifying that the procurement team approved all vendor selections
- Testing whether ongoing monitoring activities are performed and documented for critical vendors (Correct answer)
Correct answer: Testing whether ongoing monitoring activities are performed and documented for critical vendors
Effectiveness of third-party risk management is demonstrated through ongoing monitoring of critical vendors, not just initial onboarding.
Question 86: Under U.S. banking regulations, the Federal Reserve's Regulation YY requires large bank holding companies to maintain which governance structure?
- A majority of inside directors on the board
- A Risk Committee of the board composed of independent members (Correct answer)
- A joint audit-risk committee chaired by the CEO
- Separate governance standards for each subsidiary
Correct answer: A Risk Committee of the board composed of independent members
Regulation YY mandates that covered bank holding companies establish a board-level Risk Committee with independent members.
Question 87: A bank discovers its loan loss model systematically underestimates defaults during economic downturns. This is an example of:
- Credit concentration risk
- Model risk (Correct answer)
- Operational risk
- Strategic risk
Correct answer: Model risk
Model risk arises when a model produces inaccurate outputs due to flawed assumptions, errors, or misuse.
Question 88: An auditor is preparing for an audit of a bank's Anti-Money Laundering (AML) compliance program. During the planning phase, which of the following documents would be the MOST important to review first?
- A detailed list of all Suspicious Activity Reports (SARs) filed in the last quarter.
- The previous year's AML audit report and management's response.
- The bank's most recent risk assessment of its money laundering and terrorist financing exposures. (Correct answer)
- The training records and certifications of the bank's AML compliance staff.
Correct answer: The bank's most recent risk assessment of its money laundering and terrorist financing exposures.
The foundation of a risk-based AML audit is understanding the bank's own assessment of its risks. The bank's formal risk assessment will identify high-risk products, services, customers, and geographic locations. Reviewing this document first allows the auditor to understand the bank's risk profile and evaluate whether the audit plan and control testing are appropriately focused on the most significant areas of AML risk.
Question 89: When a bank's external auditor is also providing significant consulting services, this raises a concern about:
- The bank's liquidity coverage ratio
- Auditor independence and objectivity (Correct answer)
- Regulatory capital adequacy
- Dividend payout ratios
Correct answer: Auditor independence and objectivity
Providing consulting services alongside audit work creates a financial dependency that can compromise the auditor's independence.
Question 90: Under the Sarbanes-Oxley Act (SOX) Section 302, which bank officers must certify the accuracy of financial reports?
- All board members collectively
- The Chief Risk Officer and General Counsel
- The Chief Executive Officer and Chief Financial Officer (Correct answer)
- The internal audit director and external audit partner
Correct answer: The Chief Executive Officer and Chief Financial Officer
SOX Section 302 requires the CEO and CFO to personally certify the accuracy of periodic financial reports filed with the SEC.
Question 91: What is 'lapping' in the context of bank employee fraud?
- Stealing cash receipts from one account and covering the shortage with subsequent customer payments (Correct answer)
- Layering transactions through multiple accounts to obscure money laundering
- Duplicating loan applications across multiple financial institutions simultaneously
- Overlapping audit periods to ensure no coverage gaps exist
Correct answer: Stealing cash receipts from one account and covering the shortage with subsequent customer payments
Lapping involves stealing cash or checks from one customer's payment, then covering that shortage with a later customer's payment, creating an ongoing cycle that is difficult to detect without physical reconciliation.
Question 92: Which regulatory framework specifically governs the Community Reinvestment Act (CRA) examination process for large banks?
- OCC Handbook Section 12 CFR 25
- All of the above depending on the chartering authority (Correct answer)
- Federal Reserve Regulation B
- FDIC Part 345 of Title 12
Correct answer: All of the above depending on the chartering authority
CRA regulations are implemented by the OCC (12 CFR 25), Federal Reserve (12 CFR 228), and FDIC (12 CFR 345), each governing their respective supervised institutions.
Question 93: A bank extends $50M in loans but only $30M is immediately funded. The $20M gap represents which type of risk?
- Rollover risk
- Funding gap risk (Correct answer)
- Settlement risk
- Pipeline risk
Correct answer: Funding gap risk
A funding gap arises when committed loan disbursements exceed currently available funding, creating a liquidity shortfall.
Question 94: Under OFAC regulations, what must a bank do when a transaction matches a name on the SDN (Specially Designated Nationals) list?
- Escalate to senior management and decide within 5 days
- Block the transaction, hold the funds, and report to OFAC within 10 business days (Correct answer)
- Reject the transaction and notify the customer immediately
- File a SAR and process the transaction normally
Correct answer: Block the transaction, hold the funds, and report to OFAC within 10 business days
OFAC requires institutions to block transactions involving SDN-listed parties, hold the funds in a segregated account, and file a report with OFAC within 10 business days.
Question 95: An auditor reviewing a bank's BSA program finds that the BSA Officer role has been vacant for 6 months with no documented interim assignment. This is most likely a violation of:
- FFIEC guidance on dual controls
- The BSA requirement for a designated BSA compliance officer (Correct answer)
- FinCEN's SAR filing deadlines
- OFAC sanction regulations requiring dedicated compliance staff
Correct answer: The BSA requirement for a designated BSA compliance officer
The BSA requires all financial institutions to designate a BSA compliance officer; leaving the position vacant without proper interim designation is a direct BSA program deficiency.
Question 96: The 'three lines of defense' model in banking assigns internal audit to which line?
- Second line โ risk management and compliance
- Fourth line โ external oversight
- First line โ operational management
- Third line โ independent assurance (Correct answer)
Correct answer: Third line โ independent assurance
Internal audit represents the third line of defense, providing independent assurance on the effectiveness of the first two lines.
Question 97: What does the term 'skimming' mean in the context of bank employee fraud?
- Falsifying information on a loan application to obtain approval
- Stealing cash or payments before they are recorded in the accounting system (Correct answer)
- Electronically reading customer card data without physical contact
- Transferring small amounts from many customer accounts to a fraudster's account
Correct answer: Stealing cash or payments before they are recorded in the accounting system
Skimming is an 'off-books' fraud scheme where an employee steals cash or payments before any accounting entry is made, making it especially difficult to detect through traditional reconciliation.
Question 98: What is the role of stress testing in risk management?
- To evaluate resilience under adverse scenarios (Correct answer)
- To measure actual performance
- To estimate employee satisfaction
- To test new banking software
Correct answer: To evaluate resilience under adverse scenarios
Stress testing evaluates how a bank would perform under extreme but plausible adverse conditions, helping to prepare and plan.
Question 99: A bank auditor reviewing HMDA data discovers that the bank's denial rate for minority applicants is significantly higher than for similarly qualified white applicants. This is most consistent with:
- Appropriate risk-based underwriting decisions
- Compliance with the Equal Housing Lender requirements
- Statistical noise in a small sample
- Disparate impact or disparate treatment in lending (Correct answer)
Correct answer: Disparate impact or disparate treatment in lending
Disproportionate denial rates for minority applicants relative to similarly qualified non-minorities is a classic indicator of disparate treatment or disparate impact under fair lending laws.
Question 100: What is the primary objective of risk management in banking?
- To increase advertising budget
- To improve employee retention
- To attract new shareholders
- To minimize potential losses and ensure stability (Correct answer)
Correct answer: To minimize potential losses and ensure stability
Risk management aims to identify, assess, and mitigate potential threats that could affect a bank's financial stability and operations.
Question 101: Which stress testing approach requires banks to assess losses based on hypothetical but plausible adverse economic scenarios defined by the regulator?
- Historical simulation
- Supervisory stress test (DFAST/CCAR) (Correct answer)
- Sensitivity analysis
- Reverse stress testing
Correct answer: Supervisory stress test (DFAST/CCAR)
DFAST and CCAR are supervisory stress tests where regulators prescribe adverse scenarios banks must use to assess capital adequacy.
Question 102: In auditing a bank's allowance for loan and lease losses (ALLL), which internal control is MOST important to verify?
- Controls ensuring timely loan disbursement
- Controls over the completeness and accuracy of loan loss estimates (Correct answer)
- Controls preventing new loan originations during economic downturns
- Controls limiting the loan portfolio to investment-grade credits
Correct answer: Controls over the completeness and accuracy of loan loss estimates
Controls over the completeness and accuracy of ALLL estimates directly affect the reliability of a bank's most significant accounting estimate.
Question 103: Which of the following scenarios would most likely trigger heightened supervisory scrutiny for credit concentration risk, according to regulatory guidance?
- A bank's total loans to a single, well-capitalized multinational corporation exceed 15% of the bank's Tier 1 capital.
- A bank's portfolio of agricultural loans comprises 10% of its total capital.
- A bank's portfolio of commercial real estate (CRE) loans exceeds 300% of its total risk-based capital. (Correct answer)
- A bank's portfolio of unsecured consumer loans has grown by 20% in the last year.
Correct answer: A bank's portfolio of commercial real estate (CRE) loans exceeds 300% of its total risk-based capital.
Regulatory guidance flags banks for heightened scrutiny when their commercial real estate (CRE) loan concentrations exceed certain thresholds. One key threshold is when a bank's total CRE loans are greater than 300% of its total risk-based capital, and the portfolio has experienced significant growth. The other options, while representing elements of credit risk, do not align with the specific, widely-cited regulatory thresholds for concentration risk that trigger enhanced supervision.
Question 104: During an audit of a bank's new core banking system implementation, a Certified Bank Auditor is evaluating the System Development Life Cycle (SDLC) process. The auditor's primary objective at the post-implementation review phase is to:
- Confirm that all system changes have been moved to the production environment.
- Ensure that the project was completed within the original budget and timeline.
- Verify that individual user access rights were configured correctly.
- Assess whether the system has met its intended business objectives and user requirements. (Correct answer)
Correct answer: Assess whether the system has met its intended business objectives and user requirements.
The post-implementation review is conducted to determine if the newly developed system has achieved its stated objectives, is functioning as intended, and if users are satisfied. While budget, access rights, and change migration are important aspects of the overall project, the ultimate success of the system is measured by its ability to meet the business needs for which it was built.
Question 105: Which provision of the Volcker Rule most directly impacts a bank compliance auditor's review of trading activities?
- Prohibition on issuing brokered deposits
- Mandatory stress testing requirements
- Restrictions on proprietary trading and certain fund investments (Correct answer)
- Limits on executive compensation
Correct answer: Restrictions on proprietary trading and certain fund investments
The Volcker Rule prohibits banks from engaging in proprietary trading for their own account and restricts ownership interests in hedge funds and private equity funds.
Question 106: In the context of internal controls, 'management override' is dangerous primarily because:
- It slows down operational processes requiring management approval
- It creates additional documentation requirements
- It bypasses established controls and can be used to conceal fraud (Correct answer)
- It increases the cost of compliance for the bank
Correct answer: It bypasses established controls and can be used to conceal fraud
Management override allows executives to circumvent controls, which is a key fraud risk since it can be used to misstate financial results without detection.
Question 107: A key principle of sound corporate governance in banking is the presence of a significant number of independent directors on the board. What is the primary rationale for this requirement?
- To ensure the board is composed exclusively of individuals with prior bank CEO experience.
- To reduce the number of board committees required for effective oversight.
- To provide objective judgment, challenge management's perspectives, and mitigate potential conflicts of interest. (Correct answer)
- To fulfill a requirement that all board members must be major shareholders of the bank.
Correct answer: To provide objective judgment, challenge management's perspectives, and mitigate potential conflicts of interest.
Independent directors are crucial because their detachment from the bank's daily operations allows them to provide unbiased oversight and constructive challenges to management. This independence helps ensure that the board acts in the best interest of all stakeholders, not just management.
Question 108: A bank's treasury desk fails to hedge a large foreign currency receivable, resulting in a $2M loss when the dollar strengthens. This loss is attributable to:
- Credit risk
- Operational risk
- Liquidity risk
- Market risk (Correct answer)
Correct answer: Market risk
Foreign exchange exposure that results in losses due to adverse currency movements is a market risk event.
Question 109: Which assertion is most at risk when auditing a bank's accrued interest receivable balance?
- Classification โ whether accrued interest is presented separately from loan principal
- Existence โ whether recorded accruals relate to actual loan balances outstanding
- Completeness โ whether all loans have been included in the accrual calculation
- Valuation โ whether accruals on non-accrual loans have been reversed appropriately (Correct answer)
Correct answer: Valuation โ whether accruals on non-accrual loans have been reversed appropriately
Non-accrual loans should have interest accruals reversed; failure to do so overstates income and receivables, making valuation the primary risk for accrued interest.
Question 110: An auditor reviewing a bank's IT change management process finds that emergency changes are frequently implemented without post-implementation review. What risk does this create?
- Longer system development cycles
- Increased project costs
- Unauthorized or poorly tested changes may persist in the production environment (Correct answer)
- Higher vendor dependency
Correct answer: Unauthorized or poorly tested changes may persist in the production environment
Without post-implementation reviews, emergency changes may introduce security vulnerabilities or operational errors that remain undetected in production.
Question 111: When a bank sells mortgages and retains the servicing rights, the retained servicing rights create exposure to which specific risk?
- Prepayment risk (Correct answer)
- Settlement risk
- Legal risk
- Funding liquidity risk
Correct answer: Prepayment risk
Mortgage servicing rights lose value when prepayments accelerate (typically when rates fall), creating significant prepayment risk.
Question 112: A bank auditor reviewing credit concentration risk should MOST likely focus on:
- Foreign exchange hedging positions
- Trading book mark-to-market losses
- Intraday liquidity positions
- Large exposures to single borrowers or correlated sectors (Correct answer)
Correct answer: Large exposures to single borrowers or correlated sectors
Credit concentration risk is the exposure to large individual borrowers or highly correlated borrower groups that can cause significant loss.
Question 113: When auditing IT general controls, which area is MOST critical to assess first because weaknesses there can undermine all application controls?
- Change management controls
- Data center physical security
- Access controls and logical security (Correct answer)
- Backup and recovery procedures
Correct answer: Access controls and logical security
Access controls and logical security are foundational IT general controls; compromised access can invalidate the effectiveness of all other controls.
Question 114: Under the OCC's heightened standards for large banks, which governance body bears ultimate responsibility for the bank's risk appetite?
- Board of Directors (Correct answer)
- Executive Management Committee
- Internal Audit Committee
- Chief Risk Officer
Correct answer: Board of Directors
The Board of Directors is ultimately responsible for approving and overseeing the bank's risk appetite framework.
Question 115: An auditor is reviewing a loan modification to determine if it should be classified as a Troubled Debt Restructuring (TDR). Which of the following is a required condition for a loan modification to be classified as a TDR?
- The borrower has missed at least two consecutive payments before the modification was granted.
- The modification involves reducing the principal amount of the loan by at least 10%.
- The bank has granted a concession to the borrower due to the borrower's financial difficulties. (Correct answer)
- The collateral securing the loan has decreased in value by more than 25%.
Correct answer: The bank has granted a concession to the borrower due to the borrower's financial difficulties.
Accounting standards and regulatory guidance define a TDR as a restructuring where two critical conditions are met: (1) the borrower is experiencing financial difficulty, and (2) the creditor (bank) has granted a concession that it would not otherwise consider. The concession can take many forms, such as an interest rate reduction or term extension, not just a principal reduction.
Question 116: Which of the following represents a 'Matters Requiring Attention' (MRA) as opposed to a formal enforcement action in the context of a regulatory compliance examination?
- An examiner's written finding of a compliance weakness that management must address (Correct answer)
- A civil money penalty assessed for BSA violations
- A cease-and-desist order prohibiting specific banking activities
- A consent order requiring capital restoration within 60 days
Correct answer: An examiner's written finding of a compliance weakness that management must address
An MRA is an informal supervisory communication identifying compliance weaknesses, while consent orders, civil money penalties, and cease-and-desist orders are formal enforcement actions.
Question 117: A bank's internal audit department is assessing the effectiveness of its risk management processes. Which activity is LEAST likely to be a direct responsibility of the internal audit function?
- Evaluating the design and operating effectiveness of risk mitigation controls.
- Auditing the processes for identifying, assessing, and monitoring key business risks.
- Providing independent assurance on the accuracy of risk management reporting to the board.
- Setting the bank's overall risk appetite and tolerance levels. (Correct answer)
Correct answer: Setting the bank's overall risk appetite and tolerance levels.
While internal audit plays a crucial role in evaluating risk management processes, it must maintain its independence and objectivity. Setting the bank's risk appetite and tolerance is a key governance responsibility of senior management and the Board of Directors, not the internal audit function. Internal audit's role is to provide assurance that the risk management framework established by management and the board is effective, not to set the risk strategy itself.
Question 118: Which audit procedure is most effective for detecting unrecorded deposit liabilities at a bank?
- Confirming large deposit balances with customers directly
- Comparing current year deposit totals to prior year for unusual fluctuations
- Reviewing interest expense recorded for reasonableness relative to average deposits (Correct answer)
- Tracing deposits from the general ledger to supporting documentation
Correct answer: Reviewing interest expense recorded for reasonableness relative to average deposits
Analytical review of interest expense relative to average deposit balances can reveal if deposits are understated because understated liabilities produce lower-than-expected interest expense.
Question 119: What is the primary objective of an operations audit in banking?
- To increase marketing outreach
- To prepare investment strategies
- To recruit new staff
- To assess operational efficiency and control (Correct answer)
Correct answer: To assess operational efficiency and control
The main goal is to evaluate the efficiency and effectiveness of internal processes and controls within operational functions.
Question 120: What is the purpose of a 'proof of cash' in banking operations audits?
- To verify the physical currency held in vault matches the GL
- To certify branch petty cash fund accuracy
- To reconcile beginning balance, deposits, disbursements, and ending balance across periods (Correct answer)
- To confirm customer deposit slips against teller totals
Correct answer: To reconcile beginning balance, deposits, disbursements, and ending balance across periods
A proof of cash is a four-column reconciliation that validates both beginning/ending balances and total debits/credits for a period.
Question 121: Under the Truth in Savings Act (Regulation DD), when must a bank notify customers of changes to account terms that are adverse to the consumer?
- No advance notice is required
- At least 30 days before the effective date (Correct answer)
- At least 15 days before the effective date
- At least 60 days before the effective date
Correct answer: At least 30 days before the effective date
Regulation DD requires banks to provide at least 30 days' advance notice before implementing changes to account terms that are adverse to the consumer.
Question 122: Under OCC guidance, which of the following is considered a key attribute of an effective bank board?
- Delegating all risk decisions to the CEO
- Maintaining active oversight while respecting management's operational role (Correct answer)
- Limiting board meetings to once per year to reduce disruption
- Micromanaging daily operations to catch errors early
Correct answer: Maintaining active oversight while respecting management's operational role
The OCC expects boards to provide active, informed oversight without crossing into management's operational domain.
Question 123: During an audit of regulatory capital disclosures, an auditor finds that a bank has included certain instruments as Tier 2 capital. Which characteristic would disqualify an instrument from Tier 2 capital under Basel III?
- The instrument contains a call option exercisable by the bank within the first five years (Correct answer)
- The instrument is subordinated to depositors and general creditors
- The instrument was issued with a below-market coupon rate at time of issuance
- The instrument has a fixed maturity date of more than five years
Correct answer: The instrument contains a call option exercisable by the bank within the first five years
Tier 2 capital instruments must not contain incentives to redeem early; a call option exercisable within the first five years creates an effective maturity that disqualifies the instrument.
Question 124: Which federal regulation governs the disclosure of terms and conditions for consumer deposit accounts, including fees and interest rates?
- Regulation CC
- Regulation B
- Regulation DD (Correct answer)
- Regulation Z
Correct answer: Regulation DD
Regulation DD implements the Truth in Savings Act and requires clear disclosure of deposit account terms, including interest rates, fees, and conditions.
Question 125: What role does reconciliation play in banking operations?
- Reducing call center wait time
- Marketing brand image
- Speeding up mortgage approvals
- Balancing internal records with external statements (Correct answer)
Correct answer: Balancing internal records with external statements
Reconciliation ensures that financial records match across systems, preventing discrepancies and maintaining integrity.
Question 126: Which of the following best describes the role of 'shadow directors' in bank governance risk?
- External auditors who shadow the board to assess governance quality
- Individuals who exercise board-level influence without formal appointment, potentially avoiding accountability (Correct answer)
- Non-executive directors who observe but do not vote at board meetings
- Directors who serve on subsidiary boards but not the parent board
Correct answer: Individuals who exercise board-level influence without formal appointment, potentially avoiding accountability
Shadow directors exert control over a bank without formal director status, creating accountability gaps and potential governance failures.
Question 127: A bank issues $100 million in subordinated debt qualifying as Tier 2 capital. After 5 years (2 years before maturity), the regulatory capital credit is:
- 80% of the original amount ($80 million) (Correct answer)
- 20% of the original amount ($20 million)
- Full $100 million
- Zero โ subordinated debt within 5 years of maturity is excluded
Correct answer: 80% of the original amount ($80 million)
Basel III phases out Tier 2 capital instruments during the final 5 years before maturity at 20% per year, so with 2 years remaining, only 40% is recognized โ but with exactly 2 years left the credit is 40%, and at exactly 5 years remaining it starts at 80%.
Question 128: When auditing a bank's network segmentation controls, what is the auditor PRIMARILY assessing?
- Whether network hardware is under warranty
- Whether internet bandwidth is sufficient
- Whether network cables are properly labeled
- Whether sensitive systems are isolated from less-secure network zones (Correct answer)
Correct answer: Whether sensitive systems are isolated from less-secure network zones
Network segmentation isolates sensitive banking systems (e.g., core banking, cardholder data environments) from general networks, limiting the blast radius of a breach.
Question 129: When auditing a bank's loan review function, an auditor should PRIMARILY assess:
- Compliance with the bank's dress code policy
- Whether loan officers have met their production targets
- The bank's marketing strategy for new loan products
- The accuracy of credit risk ratings and adequacy of the allowance for loan losses (Correct answer)
Correct answer: The accuracy of credit risk ratings and adequacy of the allowance for loan losses
A loan review audit focuses on evaluating the integrity of the risk rating system and whether the allowance for loan losses (ALLL/ACL) is adequate and properly calculated.
Question 130: A bank's ALCO has approved a duration gap of +2.5 years. As an auditor, what is your primary concern?
- The bank is positioned to benefit from rising rates, which is always acceptable
- A positive duration gap exposes the bank to falling net interest income if rates rise (Correct answer)
- A positive duration gap means assets reprice faster than liabilities
- Duration gaps are only relevant for investment portfolio management
Correct answer: A positive duration gap exposes the bank to falling net interest income if rates rise
A positive duration gap means asset durations exceed liability durations, causing net interest income to decline when interest rates rise.
Question 131: The Liquidity Coverage Ratio (LCR) requires banks to hold sufficient High-Quality Liquid Assets (HQLA) to survive a stress scenario lasting:
- 30 days (Correct answer)
- 90 days
- 14 days
- 7 days
Correct answer: 30 days
The LCR mandates enough HQLA to cover net cash outflows over a 30-day stress period.
Question 132: An effective risk control self-assessment (RCSA) process requires business units to:
- Outsource risk identification to the internal audit department
- Report directly to external auditors quarterly
- Use only quantitative risk measures
- Identify risks, assess controls, and document residual risk within their own operations (Correct answer)
Correct answer: Identify risks, assess controls, and document residual risk within their own operations
RCSA is a first-line tool where business units take ownership of identifying risks and evaluating the effectiveness of their controls.
Question 133: Under the Bank Secrecy Act, a Currency Transaction Report (CTR) must be filed for cash transactions exceeding:
- $10,000 in a single day (Correct answer)
- $25,000 in a single day
- $50,000 in a single day
- $5,000 in a single day
Correct answer: $10,000 in a single day
CTRs must be filed with FinCEN for each cash transaction (deposit, withdrawal, or exchange) exceeding $10,000 conducted by or on behalf of the same person in a single business day.
Question 134: An auditor is reviewing a bank's Allowance for Credit Losses (ACL) methodology under the Current Expected Credit Losses (CECL) standard. The auditor discovers that the historical loss data used in the model excludes loans from a recently acquired portfolio with a historically higher loss rate. Which of the following audit conclusions is most appropriate?
- The exclusion of relevant historical data may lead to an understatement of the required ACL. (Correct answer)
- The ACL model is acceptable as long as it incorporates reasonable and supportable forecasts.
- The bank's qualitative adjustments are sufficient to compensate for any data omissions.
- The acquired portfolio can be excluded until three years of performance data have been accumulated.
Correct answer: The exclusion of relevant historical data may lead to an understatement of the required ACL.
Under ASC 326 (CECL), the estimate of expected credit losses must be based on all relevant information, including past events and current conditions. Intentionally excluding a portfolio with higher historical losses from the data set used to train the model introduces a bias that will likely result in an ACL that is understated and not representative of the true risk profile of the entire loan portfolio.
Question 135: When a bank auditor identifies that loan loss reserves are systematically below expected loss estimates, this MOST directly indicates a problem with:
- Allowance for Credit Loss (ACL) adequacy (Correct answer)
- Operational risk governance
- Market risk controls
- Capital adequacy reporting
Correct answer: Allowance for Credit Loss (ACL) adequacy
Insufficient loan loss reserves relative to expected losses points to an inadequacy in the Allowance for Credit Loss methodology or application.
Question 136: Under the Truth in Lending Act (TILA), Regulation Z requires lenders to disclose the Annual Percentage Rate (APR) primarily to:
- Satisfy capital adequacy requirements
- Calculate the lender's profitability on the loan
- Determine HMDA reportability of the transaction
- Allow borrowers to compare credit costs across different loan products (Correct answer)
Correct answer: Allow borrowers to compare credit costs across different loan products
TILA's APR disclosure is designed to give borrowers a standardized cost metric so they can meaningfully compare the true cost of credit across different lenders and products.
Question 137: When evaluating a bank's Pillar 2 Internal Capital Adequacy Assessment Process (ICAAP), auditors should assess whether:
- Stress testing is excluded to avoid overstating capital needs
- Capital calculations strictly mirror Pillar 1 standardized approach outputs
- All material risks, including those not captured in Pillar 1, are identified and capitalized (Correct answer)
- The ICAAP is prepared solely by the finance department
Correct answer: All material risks, including those not captured in Pillar 1, are identified and capitalized
ICAAP must capture all material risks including Pillar 2 risks such as concentration risk, IRRBB, and strategic risk that are not fully addressed in Pillar 1.
Question 138: A bank recognizes a $2 million gain on the sale of a branch building. On the statement of cash flows using the indirect method, this gain is treated how?
- Subtracted from net income in the operating section and shown as an investing inflow (Correct answer)
- Added to net income in the operating section
- Disclosed in footnotes only with no statement impact
- Shown only in the financing activities section
Correct answer: Subtracted from net income in the operating section and shown as an investing inflow
Under the indirect method, non-operating gains are removed from operating activities (subtracted) to avoid double-counting, while the full sale proceeds appear as an investing cash inflow.
Question 139: A bank identifies that two of its board directors serve on the board of a major competitor. This situation primarily raises concerns about:
- Excessive director compensation
- Insufficient board diversity
- Non-compliance with capital requirements
- Conflicts of interest and potential breach of fiduciary duty (Correct answer)
Correct answer: Conflicts of interest and potential breach of fiduciary duty
Serving on competitor boards creates conflicts of interest, risks disclosure of confidential information, and may breach fiduciary duties.
Question 140: Under GAAS, when a bank auditor uses the work of an internal auditor, the external auditor must:
- Accept the internal auditor's findings without independent verification to avoid duplication
- Include the internal auditor as a co-signer on the audit report
- Reduce the audit fee proportionally to reflect reliance on internal audit work
- Evaluate the competence, objectivity, and work quality of the internal audit function (Correct answer)
Correct answer: Evaluate the competence, objectivity, and work quality of the internal audit function
AU-C Section 610 requires external auditors to assess internal auditors' competence and objectivity and evaluate the quality of their work before placing reliance on it.
Question 141: In corporate governance, the 'duty of loyalty' requires bank directors to:
- Vote in alignment with the position of the bank's largest shareholder
- Maintain confidentiality of all board discussions for 10 years
- Remain loyal to the bank's founding shareholders regardless of circumstances
- Prioritize the interests of the bank over personal or third-party interests (Correct answer)
Correct answer: Prioritize the interests of the bank over personal or third-party interests
The duty of loyalty requires directors to act in the best interests of the bank, avoiding self-dealing or conflicts of interest.
Question 142: A bank is subject to the Volcker Rule. During an audit, the auditor finds the bank is holding a portfolio of corporate bonds beyond normal inventory needs. What is the primary Volcker Rule concern?
- The bonds may constitute prohibited proprietary trading beyond market-making exemptions (Correct answer)
- The concern is limited to equity securities, not bonds
- Corporate bonds are categorically prohibited under the Volcker Rule
- The holding is permissible as long as the bonds are investment grade
Correct answer: The bonds may constitute prohibited proprietary trading beyond market-making exemptions
The Volcker Rule prohibits proprietary trading in most securities, and holding inventory beyond what is reasonably expected for market-making can indicate non-exempt proprietary positioning.
Question 143: Which sampling method requires the auditor to select every nth item from a population, starting from a random point?
- Cluster sampling
- Judgmental sampling
- Stratified random sampling
- Systematic sampling (Correct answer)
Correct answer: Systematic sampling
Systematic sampling selects items at uniform intervals (every nth item) after a random start, making it efficient for large populations.
Question 144: Which of the following best describes a 'staggered board' structure?
- Directors are appointed exclusively by regulators
- All directors are elected every year at the annual meeting
- Only a fraction of board seats are up for election each year (Correct answer)
- The board rotates leadership among its members monthly
Correct answer: Only a fraction of board seats are up for election each year
A staggered board divides directors into classes elected in different years, providing continuity but potentially entrenching existing directors.
Question 145: How can an internal audit improve banking operations?
- By increasing marketing spend
- By enhancing operational efficiency through recommendations (Correct answer)
- By hiring customer service agents
- By managing external partnerships
Correct answer: By enhancing operational efficiency through recommendations
Audits provide insights and recommendations that strengthen internal controls, improve process efficiency, and ensure compliance.
Question 146: A bank receives a grand jury subpoena for a customer's records. Under the BSA 'tipping off' prohibition, the bank may NOT:
- Consult with legal counsel about the subpoena
- Notify the customer that a SAR was filed regarding their account (Correct answer)
- Produce the requested records to law enforcement
- File a SAR related to the same activity
Correct answer: Notify the customer that a SAR was filed regarding their account
The BSA tipping-off prohibition explicitly forbids notifying a customer (or anyone else) that a SAR has been filed concerning their account.
Question 147: How does executive compensation structure relate to bank governance and risk management?
- Regulators do not have authority to comment on compensation practices
- High fixed salaries always lead to better risk management outcomes
- Short-term bonus incentives can encourage excessive risk-taking misaligned with long-term stability (Correct answer)
- Compensation has no material impact on risk-taking behavior
Correct answer: Short-term bonus incentives can encourage excessive risk-taking misaligned with long-term stability
Poorly structured compensation that rewards short-term profits can incentivize excessive risk-taking, a key governance and systemic risk concern.
Question 148: Which of the following is a required communication from the external auditor to the bank's audit committee?
- A comparative analysis of the bank's performance against its primary competitors.
- An overview of the planned scope and timing of the audit, including significant risks identified. (Correct answer)
- The detailed daily schedule and staff assignments for the audit fieldwork.
- Management's confidential performance reviews for key finance personnel.
Correct answer: An overview of the planned scope and timing of the audit, including significant risks identified.
Auditing standards (such as PCAOB AS 1301) require auditors to communicate an overview of the overall audit strategy to the audit committee. This includes the planned scope, the timing of the audit, and a discussion of the significant risks that were identified during the risk assessment process. This communication ensures the audit committee has proper oversight of the audit process.
Question 149: An auditor is evaluating the bank's loan loss reserve (CECL) model. Which finding poses the greatest risk to financial statement accuracy?
- The model is reviewed and approved by the CFO annually
- Historical loss data used to calibrate the model predates the bank's current loan portfolio mix by ten years (Correct answer)
- The model uses a weighted average of three economic forecast scenarios
- The reasonable and supportable forecast period is 24 months
Correct answer: Historical loss data used to calibrate the model predates the bank's current loan portfolio mix by ten years
Using stale historical loss data that doesn't reflect the current portfolio's risk profile will produce unreliable CECL estimates, potentially causing material misstatement of reserves.
Question 150: During an audit of the lending function, a Certified Bank Auditor discovers a new, unsecured loan extended to one of the bank's directors. The loan has an interest rate significantly below what is offered to the general public for similar loans. Which regulatory requirement should the auditor be most concerned with?
- Regulation Z (Truth in Lending)
- Fair Credit Reporting Act (FCRA)
- Community Reinvestment Act (CRA)
- Regulation O (Loans to Insiders and Their Related Interests) (Correct answer)
Correct answer: Regulation O (Loans to Insiders and Their Related Interests)
Regulation O governs credit extensions to executive officers, directors, and principal shareholders (insiders). A key provision of this regulation is that any credit extended to an insider must be on substantially the same terms as those prevailing at the time for comparable transactions with non-insiders. Offering a preferential interest rate to a director is a classic red flag for a Regulation O violation.
Question 151: Which of the following BEST describes the primary role of a bank's Board of Directors in the institution's corporate governance framework?
- Developing the detailed procedures for the bank's daily operational risk controls.
- Conducting the fieldwork for internal audits of the bank's various departments and functions.
- Executing the bank's day-to-day business strategy and managing departmental staff.
- Approving and overseeing management's implementation of the bank's strategic objectives, risk appetite, and corporate culture. (Correct answer)
Correct answer: Approving and overseeing management's implementation of the bank's strategic objectives, risk appetite, and corporate culture.
According to the Basel Committee on Banking Supervision, the Board has the ultimate responsibility for the bank, which includes approving and overseeing management's implementation of strategic objectives, the governance framework, and corporate culture. The other options describe responsibilities of management or the internal audit function.
Question 152: A bank's loan origination system is configured to prevent a loan officer from processing a loan application that exceeds their authorized lending limit by automatically rejecting the submission. This system feature is an example of which type of internal control?
- Directive
- Preventive (Correct answer)
- Detective
- Corrective
Correct answer: Preventive
Preventive controls are designed to stop an error or irregularity from occurring in the first place. The system's block on exceeding lending limits actively prevents the unauthorized transaction from being completed.
Question 153: A bank's compliance audit reveals that its flood insurance procedures do not include force-placing flood insurance within the required timeframe after a borrower's lapse in coverage. Under the Flood Disaster Protection Act, what is the required force-placement timeframe?
- 60 days after the policy expiration date
- 30 days after sending an initial notice of lapse
- 45 days after sending notice of lapse (Correct answer)
- 90 days after the borrower is notified
Correct answer: 45 days after sending notice of lapse
The Flood Disaster Protection Act requires lenders to force-place flood insurance if the borrower fails to obtain coverage within 45 days of the initial notice.
Question 154: In the context of bank governance, 'constructive challenge' by board members refers to:
- Active, critical questioning of management's assumptions and proposals without being adversarial (Correct answer)
- Challenging regulatory requirements in court proceedings
- Directors voting against all management resolutions as a default position
- Directors filing formal legal objections to management proposals
Correct answer: Active, critical questioning of management's assumptions and proposals without being adversarial
Constructive challenge means directors critically evaluate management information and proposals to improve decisions without undermining collaboration.
Question 155: An internal auditor is reviewing the minutes of the bank's Audit Committee meetings. Which of the following topics would the auditor LEAST expect to be a primary focus of this committee's discussions?
- The performance and independence of the external auditors.
- The adequacy of the bank's internal controls over financial reporting.
- The approval of the bank's new marketing and brand strategy. (Correct answer)
- The review of significant findings from recent internal audits.
Correct answer: The approval of the bank's new marketing and brand strategy.
The Audit Committee's primary duties involve oversight of financial reporting, internal controls, and the internal and external audit functions. Developing and approving a marketing strategy is a management responsibility related to business strategy, not a core governance oversight function of the Audit Committee.
Question 156: During an audit of loan operations, an auditor finds that paid-off loans are not released from collateral within the bank's 30-day policy. The MOST significant risk is:
- Inaccurate interest income accruals
- Violation of collateral concentration limits
- Overstatement of the loan loss reserve
- Customer complaints and potential legal liability (Correct answer)
Correct answer: Customer complaints and potential legal liability
Failing to timely release liens on paid-off collateral exposes the bank to customer lawsuits and reputational harm.
Question 157: What does 'related-party transaction' mean in the context of bank governance?
- A transaction executed on behalf of a family trust by the bank's wealth management division
- A transaction with a foreign correspondent bank
- Any transaction exceeding $10 million in notional value
- A transaction between a bank and a closely affiliated entity such as a director, major shareholder, or their associates (Correct answer)
Correct answer: A transaction between a bank and a closely affiliated entity such as a director, major shareholder, or their associates
Related-party transactions involve insiders or their affiliates, requiring heightened scrutiny to prevent self-dealing and conflicts of interest.
Question 158: An IT auditor is evaluating a bank's controls over API security for open banking integrations. Which control is MOST important to verify?
- The programming language used to build the APIs
- The visual design of the API developer portal
- The physical location of the API gateway servers
- OAuth 2.0 implementation with proper token scoping and expiration controls (Correct answer)
Correct answer: OAuth 2.0 implementation with proper token scoping and expiration controls
OAuth 2.0 with properly scoped and time-limited tokens is the foundational security control for API access management in open banking environments.
Question 159: When auditing IT controls for a bank's automated clearing house (ACH) operations, which control is MOST critical to verify?
- Dual authorization controls for ACH file releases exceeding defined dollar thresholds (Correct answer)
- The color scheme of the ACH processing dashboard
- The number of monitors at each ACH workstation
- The age of ACH processing hardware
Correct answer: Dual authorization controls for ACH file releases exceeding defined dollar thresholds
Dual authorization for high-value ACH files prevents a single individual from initiating and releasing large fund transfers, mitigating fraud and error risk.
Question 160: In AML risk assessment, 'correspondent banking' is considered high risk primarily because:
- Regulators routinely examine correspondent relationships for rate manipulation
- Correspondent accounts generate low fee income relative to compliance costs
- The bank extends services to foreign bank customers it has never directly vetted (Correct answer)
- Correspondent banks are subject to stricter capital requirements
Correct answer: The bank extends services to foreign bank customers it has never directly vetted
Correspondent banking creates nested relationships where a domestic bank serves the customers of a foreign bank without direct knowledge of those end customers' identities or risk profiles.
Question 161: Which component of the COSO Internal Control-Integrated Framework is generally considered the foundation for all other components, encompassing the 'tone at the top' set by the board of directors and senior management?
- Risk Assessment
- Monitoring Activities
- Control Environment (Correct answer)
- Control Activities
Correct answer: Control Environment
The Control Environment sets the tone of an organization, influencing the control consciousness of its people. It is the foundation for all other components of internal control, providing discipline, structure, and ethical values.
Question 162: A bank's teller cash drawer limit is set at $10,000. An auditor finds that several tellers regularly carry $15,000โ$18,000 in their drawers. The PRIMARY audit concern is:
- Excess bonding exposure
- Violation of operational policy limits (Correct answer)
- Inaccurate daily cash counts
- Failure to file Currency Transaction Reports
Correct answer: Violation of operational policy limits
Exceeding established drawer limits violates operational policy and exposes the bank to uncontrolled cash risk.
Question 163: During an IT audit, an auditor discovers that a bank's firewall rules have not been reviewed in 36 months. What is the PRIMARY risk?
- Increased firewall hardware costs
- Difficulty obtaining firewall vendor support
- Slower network performance due to rule bloat
- Outdated rules may permit unauthorized access or retain unnecessary open ports (Correct answer)
Correct answer: Outdated rules may permit unauthorized access or retain unnecessary open ports
Stale firewall rules may allow traffic that should be blocked or retain rules for decommissioned systems, creating unauthorized network access vulnerabilities.
Question 164: Which risk-based approach element requires banks to assess the specific money laundering risks posed by their products, services, customers, and geographic locations?
- Enhanced Due Diligence
- Suspicious Activity Monitoring
- Customer Identification Program
- Risk Assessment (Correct answer)
Correct answer: Risk Assessment
A BSA/AML Risk Assessment evaluates the institution's inherent risk exposure across products, customers, services, and geographies to drive compliance program design.
Question 165: A compliance auditor is evaluating a bank's Unfair, Deceptive, or Abusive Acts or Practices (UDAAP) program. Which of the following scenarios most clearly constitutes an 'abusive' practice under Dodd-Frank?
- Advertising a rate that is offered to qualifying customers
- Failing to disclose a fee that is clearly listed in the account agreement
- Charging a fee for a service the consumer actively requested
- A bank taking advantage of consumers' inability to understand a product's material risks (Correct answer)
Correct answer: A bank taking advantage of consumers' inability to understand a product's material risks
An abusive practice under Dodd-Frank includes taking unreasonable advantage of consumers' lack of understanding of the material risks or costs of a financial product.
Question 166: According to ACFE Occupational Fraud studies, what is the most common category of fraud committed against financial institutions?
- Asset misappropriation (Correct answer)
- Corruption and bribery schemes
- Cyber-enabled fraud
- Financial statement fraud
Correct answer: Asset misappropriation
Asset misappropriation โ which includes theft of cash, checks, inventory, and other assets โ is consistently the most common category of occupational fraud, accounting for the vast majority of reported cases.
Question 167: An auditor is examining the collateral documentation for a portfolio of commercial real estate (CRE) loans. The auditor notes that for several large loans, the most recent property appraisals are over three years old. This finding represents a significant weakness in which area?
- Collateral risk management. (Correct answer)
- Interest rate risk management.
- Liquidity risk monitoring.
- Fair lending compliance.
Correct answer: Collateral risk management.
Collateral is a secondary source of repayment for CRE loans, and its value can fluctuate significantly. Relying on outdated appraisals means the bank may not have an accurate understanding of its current collateral position. If property values have declined, the loan-to-value ratio may be much higher than policy allows, indicating an unacceptably high level of credit risk due to potential under-collateralization. Regulatory guidance requires banks to have processes for obtaining current collateral valuations.
Question 168: A bank's whistleblower policy is best described as a governance mechanism that:
- Requires all complaints to go through the legal department first
- Provides channels for reporting misconduct without fear of retaliation (Correct answer)
- Limits disclosures to only the CEO and CFO
- Penalizes employees who report issues to regulators
Correct answer: Provides channels for reporting misconduct without fear of retaliation
Effective whistleblower policies establish safe, confidential channels for reporting misconduct, a key element of a sound governance culture.
Question 169: What is the primary purpose of a bank's employee fraud hotline?
- To provide an anonymous reporting channel for employees to report suspected fraud without fear of retaliation (Correct answer)
- To allow customers to report dissatisfaction with interest rates and fees
- To collect customer feedback on the quality of digital banking services
- To notify banking regulators directly of suspicious transaction activity
Correct answer: To provide an anonymous reporting channel for employees to report suspected fraud without fear of retaliation
A fraud hotline gives employees and others a confidential, anonymous channel to report suspected wrongdoing, encouraging reporting by protecting the identity and employment status of those who come forward.
Question 170: The Net Stable Funding Ratio (NSFR) was introduced under Basel III to address which specific concern?
- Excessive leverage in the banking system
- Short-term liquidity gaps during a 30-day stress event
- Over-reliance on short-term, unstable funding sources to finance long-term assets (Correct answer)
- Concentration of credit exposures to a single counterparty
Correct answer: Over-reliance on short-term, unstable funding sources to finance long-term assets
The NSFR requires banks to fund long-term assets with stable, longer-term liabilities, reducing structural liquidity risk over a one-year horizon.
Question 171: Why is documentation important in compliance processes?
- To simplify client onboarding
- To meet marketing goals
- To provide proof of compliance (Correct answer)
- To reduce filing space
Correct answer: To provide proof of compliance
Documentation serves as evidence of compliance with laws and policies, supporting audits and regulatory reviews.
Question 172: An auditor reviewing a bank's vendor management program finds that a third-party processor handling credit card data has not been assessed for PCI DSS compliance. What is the primary compliance concern?
- The bank may face sanctions under the Electronic Funds Transfer Act
- The bank retains responsibility for third-party PCI DSS compliance and could face card network penalties for the oversight (Correct answer)
- Only the vendor, not the bank, is liable for PCI DSS violations
- The failure is inconsequential if the vendor has general cybersecurity insurance
Correct answer: The bank retains responsibility for third-party PCI DSS compliance and could face card network penalties for the oversight
Card networks hold banks responsible for ensuring their service providers maintain PCI DSS compliance, and failure to assess vendor compliance exposes the bank to penalties.
Question 173: A bank director who also owns a significant stake in a vendor seeking a major contract with the bank should:
- Disclose the conflict and recuse themselves from related discussions and votes (Correct answer)
- Inform only the CEO and proceed as normal
- Vote in favor to demonstrate commitment to the bank's efficiency
- Negotiate the best deal possible given their industry knowledge
Correct answer: Disclose the conflict and recuse themselves from related discussions and votes
Disclosure and recusal are the required responses to conflicts of interest to preserve the integrity of the board's decision-making.
Question 174: What is the purpose of the statement of cash flows?
- To track net income
- To calculate interest expense
- To show cash movement in and out of the business (Correct answer)
- To assess asset turnover
Correct answer: To show cash movement in and out of the business
It provides information about a company's cash inflows and outflows, categorized into operating, investing, and financing activities.
Question 175: Under GLBA (Gramm-Leach-Bliley Act) Safeguards Rule, banks must implement a comprehensive information security program to protect:
- Publicly available information about the bank's operations
- Nonpublic personal information (NPI) of individual customers (Correct answer)
- Proprietary trading strategies and algorithms
- All financial data held by the bank, including institutional records
Correct answer: Nonpublic personal information (NPI) of individual customers
The GLBA Safeguards Rule specifically requires financial institutions to protect the nonpublic personal information (NPI) of individual consumers from unauthorized access or disclosure.
Question 176: A bank's trading desk sells protection on a corporate bond via a credit default swap (CDS). If the reference entity defaults, the bank faces:
- Market risk offset from the hedge
- Reduced capital requirements
- Basis risk only
- Contingent credit risk from the protection sold (Correct answer)
Correct answer: Contingent credit risk from the protection sold
Selling CDS protection creates contingent credit risk: the bank must pay the notional amount if the reference entity defaults.
Question 177: Which risk management framework is most widely adopted by U.S. banks for enterprise-wide risk governance?
- NIST Cybersecurity Framework
- ISO 31000
- COSO ERM (Correct answer)
- Basel III Pillar 1
Correct answer: COSO ERM
COSO ERM provides a widely adopted enterprise risk management framework that aligns risk with strategy and performance.
Question 178: A bank's Risk Appetite Statement (RAS) should be:
- Drafted exclusively by the Chief Risk Officer without board input
- Treated as confidential and not shared with regulators
- Approved by the board and clearly linked to the bank's strategic plan (Correct answer)
- Updated only when a significant loss event occurs
Correct answer: Approved by the board and clearly linked to the bank's strategic plan
Best practice requires the board to approve the RAS and ensure it is integrated with strategy, capital planning, and compensation.
Question 179: Which of the following is the primary objective of a bank's internal loan review function, which is periodically assessed by the internal audit department?
- To set the interest rates, terms, and fees for new loan products based on market conditions.
- To perform the annual calculation for the Allowance for Credit Losses (ACL) and present it to the board.
- To provide an independent, ongoing assessment of the overall quality of the loan portfolio and the effectiveness of credit risk management. (Correct answer)
- To make new lending decisions and approve credit applications for complex commercial loans.
Correct answer: To provide an independent, ongoing assessment of the overall quality of the loan portfolio and the effectiveness of credit risk management.
The loan review function is a critical component of a bank's credit risk management system. Its main purpose is to provide an independent and objective assessment of the quality of individual loans and the overall loan portfolio. It also evaluates the effectiveness of underwriting, loan administration, and the accuracy of internal risk ratings, serving as a check on the credit-granting process, not as a part of it.
Question 180: A bank enters into interest rate swap agreements designated as fair value hedges. Under ASC 815, the audit of hedge effectiveness requires the auditor to verify:
- That swap counterparties have investment-grade credit ratings from all major agencies
- That documentation of hedging relationships was in place at hedge inception (Correct answer)
- That the hedging strategy was approved by both state and federal bank regulators
- That the notional amount of the swap equals the bank's total deposit liabilities
Correct answer: That documentation of hedging relationships was in place at hedge inception
ASC 815 requires formal hedge documentation to exist at inception, including identification of the hedged item, hedging instrument, risk being hedged, and effectiveness assessment method.
Question 181: An IT auditor is reviewing a bank's data encryption practices. Which finding would be MOST critical to report?
- The encryption algorithm documentation is not updated
- Encryption documentation is stored in a shared drive
- Encryption keys are rotated annually instead of quarterly
- Customer PII is transmitted over internal networks without encryption (Correct answer)
Correct answer: Customer PII is transmitted over internal networks without encryption
Transmitting customer PII without encryption exposes sensitive data to interception and violates regulatory requirements, representing an immediate critical risk.
Question 182: Under COSO's Internal ControlโIntegrated Framework, which component involves an organization's values, ethics, and operating style?
- Information & Communication
- Risk Assessment
- Monitoring Activities
- Control Environment (Correct answer)
Correct answer: Control Environment
The Control Environment is the foundation of internal control and encompasses the organization's tone, values, ethical standards, and management philosophy.
Question 183: What is the primary purpose of a Suspicious Activity Report (SAR) filed with FinCEN?
- To freeze a customer's account pending investigation
- To alert FinCEN to transactions that may involve money laundering or other financial crimes (Correct answer)
- To document the bank's refusal to process a transaction
- To notify law enforcement of confirmed criminal activity
Correct answer: To alert FinCEN to transactions that may involve money laundering or other financial crimes
SARs are intelligence tools that alert FinCEN to suspicious activity that may involve money laundering, fraud, or other financial crimes โ not confirmed crimes.
Question 184: During an audit of a bank's stress testing program, the auditor should evaluate whether stress scenarios are:
- Developed exclusively by external consultants
- Applied only to trading book exposures
- Limited to historical events only to ensure credibility
- Sufficiently severe, plausible, and cover multiple risk types simultaneously (Correct answer)
Correct answer: Sufficiently severe, plausible, and cover multiple risk types simultaneously
Effective stress scenarios must be severe yet plausible and should capture interdependencies across multiple risk types to be meaningful for capital planning.
Question 185: In auditing a bank's consolidated financial statements, which variable interest entity (VIE) scenario requires consolidation by the bank?
- The bank holds a passive equity interest of less than 20% in a trust preferred entity
- The bank has a correspondent banking relationship with the VIE for check clearing services
- The bank's pension trust fund holds assets that exceed the projected benefit obligation
- The bank is the primary beneficiary that absorbs the majority of a VIE's expected losses (Correct answer)
Correct answer: The bank is the primary beneficiary that absorbs the majority of a VIE's expected losses
Under ASC 810, a VIE must be consolidated by the entity that is the primary beneficiary โ the one with power over the VIE's activities and obligation to absorb losses or right to receive benefits.
Question 186: Under the Bank Secrecy Act (BSA), what is the minimum threshold that triggers a Currency Transaction Report (CTR) filing requirement?
- $50,000
- $25,000
- $5,000
- $10,000 (Correct answer)
Correct answer: $10,000
The BSA requires financial institutions to file a CTR for any cash transaction exceeding $10,000 in a single business day.
Question 187: An internal auditor discovers that a bank's reconciliation process for a correspondent bank account, which has a material balance, was not performed for three consecutive months due to employee turnover. This failure means that a material misstatement of the financial statements would not be detected in a timely manner. How should this control failure be classified?
- A material weakness. (Correct answer)
- A significant deficiency.
- A standard control deficiency.
- An acceptable operational risk.
Correct answer: A material weakness.
A material weakness is a deficiency, or a combination of deficiencies, in internal control over financial reporting, such that there is a reasonable possibility that a material misstatement of the entity's financial statements will not be prevented, or detected and corrected, on a timely basis. The failure to reconcile a material account for an extended period directly fits this definition.
Question 188: Which of the following best describes the 'scope limitation' an internal auditor must document when access to key records is denied during a compliance audit?
- An automatic escalation requiring external auditor involvement
- A disclosure in the audit report that certain evidence could not be examined, affecting the conclusions that can be drawn (Correct answer)
- A formal finding that the denied records contain compliance violations
- A notation that the audit was completed without exception
Correct answer: A disclosure in the audit report that certain evidence could not be examined, affecting the conclusions that can be drawn
When auditors cannot access key records, they must document the scope limitation and caveat audit conclusions accordingly, since findings may be incomplete.
Question 189: Which element of a bank's fraud prevention program is most critical for establishing a strong anti-fraud culture?
- Maintaining large fidelity bond insurance coverage for all employee positions
- Scheduling frequent external audits and third-party penetration testing
- Tone at the top โ visible senior management commitment to ethical conduct and zero tolerance for fraud (Correct answer)
- Deploying advanced AI-based data analytics and transaction monitoring software
Correct answer: Tone at the top โ visible senior management commitment to ethical conduct and zero tolerance for fraud
Tone at the top โ management's visible, consistent commitment to ethics and their zero-tolerance enforcement of anti-fraud policies โ is the foundation of an effective anti-fraud culture that influences all employee behavior.
Question 190: What is the primary purpose of internal controls in a bank?
- To reduce employee workload
- To boost customer engagement
- To improve marketing reach
- To ensure regulatory compliance and protect assets (Correct answer)
Correct answer: To ensure regulatory compliance and protect assets
Internal controls are designed to safeguard assets, ensure accurate financial reporting, and promote operational efficiency.
Question 191: During an audit of a bank's enterprise risk management (ERM) framework, an auditor notes that the risk appetite statement is vaguely defined and lacks quantifiable metrics. What is the MOST significant implication of this finding?
- The daily operations of the first line of defense will be inefficient.
- It will be difficult to align strategic decisions with the board's risk tolerance and for audit to assess compliance. (Correct answer)
- The bank may be overspending on third-party audit and consulting services.
- The bank's IT general controls are likely to be ineffective.
Correct answer: It will be difficult to align strategic decisions with the board's risk tolerance and for audit to assess compliance.
A clear, well-defined risk appetite statement with quantitative and qualitative metrics is crucial for guiding strategic decisions and aligning business activities with the board's approved level of risk tolerance. Without it, management lacks clear boundaries for risk-taking, and internal audit has no objective criteria against which to assess whether business units are operating within acceptable risk levels.
Question 192: Which program requires financial institutions to implement risk-based procedures for verifying the identity of customers at account opening?
- Customer Identification Program (CIP) (Correct answer)
- Know Your Customer (KYC) Guidance
- Enhanced Due Diligence (EDD) Policy
- Customer Due Diligence (CDD) Rule
Correct answer: Customer Identification Program (CIP)
The Customer Identification Program (CIP), mandated by the USA PATRIOT Act Section 326, requires banks to collect and verify identifying information from customers when opening accounts.
Question 193: A bank auditor identifies that the operations division uses spreadsheets maintained by a single employee to calculate daily fee income. The BEST control recommendation is to:
- Require the employee to document all formulas in a separate manual
- Migrate fee calculations to a validated, system-based process with access controls (Correct answer)
- Have the external auditor test the spreadsheet quarterly
- Increase the frequency of supervisory review of the spreadsheet
Correct answer: Migrate fee calculations to a validated, system-based process with access controls
System-based calculations with access controls eliminate single-point-of-failure and manipulation risks inherent in end-user-maintained spreadsheets.
Question 194: An auditor reviewing the bank's general ledger suspense account finds 847 items totaling $2.3 million that are more than 60 days old with no resolution documentation. The MOST appropriate audit response is to:
- Accept management's assurance that items will be cleared by year-end
- Expand testing to determine the nature of aged items and assess potential loss exposure (Correct answer)
- Note the finding and recommend quarterly suspense account reviews
- Limit the finding to items exceeding $100,000
Correct answer: Expand testing to determine the nature of aged items and assess potential loss exposure
Aged suspense items with no documentation require expanded testing to determine whether they represent errors, fraud, or potential financial losses.
Question 195: A bank's IT auditor is reviewing the effectiveness of data loss prevention (DLP) controls. Which scenario represents a DLP control FAILURE?
- A bulk file of customer SSNs is successfully emailed to an external personal account (Correct answer)
- An employee's email with an encrypted attachment is flagged for review
- A system blocks an unauthorized USB drive from copying files
- An alert is generated when a user accesses data outside their role
Correct answer: A bulk file of customer SSNs is successfully emailed to an external personal account
Successfully emailing a bulk file of customer SSNs externally indicates the DLP system failed to detect and block the unauthorized exfiltration of sensitive data.
Question 196: During a review of a bank's Business Continuity Plan (BCP), an auditor notes that the plan has not been updated in over three years. The Business Impact Analysis (BIA) is also outdated. Which of the following is the GREATEST risk associated with this finding?
- The recovery strategies may no longer be effective for current critical business operations. (Correct answer)
- The cost of executing the plan may have increased beyond the allocated budget.
- The plan may not be compliant with archival and record retention policies.
- The contact information for key personnel listed in the plan may be incorrect.
Correct answer: The recovery strategies may no longer be effective for current critical business operations.
The primary risk of an outdated BCP and BIA is that the bank's operations, critical systems, and processes may have changed significantly. Therefore, the recovery strategies documented in the plan may no longer be relevant or effective for restoring essential services within their required timeframes (Recovery Time Objectives), potentially leading to significant financial and reputational damage during a disruption.
Question 197: Which financial reporting standard governs the recognition and measurement of a bank's trading securities?
- ASC 948 (Financial Services โ Mortgage Banking)
- ASC 320 (Investments in Debt Securities) (Correct answer)
- ASC 310 (Receivables)
- ASC 815 (Derivatives and Hedging)
Correct answer: ASC 320 (Investments in Debt Securities)
ASC 320 classifies debt securities into trading, AFS, and HTM categories, with trading securities measured at fair value through earnings.
Question 198: An auditor testing the bank's branch reconciliation process discovers that outstanding items older than 90 days are automatically cleared by the system without investigation. This represents a weakness in:
- Teller balancing procedures
- Stale-item management and escheatment controls (Correct answer)
- Anti-money laundering transaction monitoring
- Branch profitability reporting
Correct answer: Stale-item management and escheatment controls
Auto-clearing unresolved outstanding items bypasses investigation requirements and may violate state escheatment laws for unclaimed property.
Question 199: During an audit of a bank's investment portfolio, an auditor is testing the valuation of U.S. Treasury bonds classified as 'Available-for-Sale' (AFS). Which audit procedure provides the MOST reliable evidence for the valuation of these securities?
- Reviewing the minutes from the Asset/Liability Committee (ALCO) meeting where the purchase was discussed.
- Comparing the bank's recorded fair value to a quoted price from an active, independent market source. (Correct answer)
- Analyzing the bank's internal model for projecting future interest rates.
- Recalculating the amortization of the premium or discount on the bonds.
Correct answer: Comparing the bank's recorded fair value to a quoted price from an active, independent market source.
AFS securities are carried at fair value. For an actively traded security like a U.S. Treasury bond, the most reliable audit evidence for its valuation is an external, independent source. Comparing the bank's carrying value to a quoted price from an active market (a Level 1 input) provides direct and highly reliable evidence of its fair value. The other procedures test different attributes but do not directly substantiate fair value.
Question 200: Which Basel III capital ratio uses risk-weighted assets in the denominator?
- Liquidity Coverage Ratio
- Leverage ratio
- Common Equity Tier 1 (CET1) ratio (Correct answer)
- Net Stable Funding Ratio
Correct answer: Common Equity Tier 1 (CET1) ratio
The CET1 ratio is calculated as common equity tier 1 capital divided by total risk-weighted assets.
Certified Bank Auditor (CBA)
The CBA is a professional certification awarded by the Institute of Certified Bankers (ICB), validating expertise in bank auditing across risk management, audit processes, IT, corporate governance, regulatory compliance, and financial auditing.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong โ answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds