APRP CORE EXAM TEST QUESTIONS AND ANSWERS
GRADED A+
✔✔Reputation Risk - ✔✔Risk that occurs when negative publicity regarding an
institutions business practices leads to a loss of revenue or litigation. For retail-payment
systems, this risk is linked to consumer expectations regarding the delivery of retail
payment services, and the institutions ability to meet it's regulatory and consumer
protection obligations related to those services.
✔✔Strategic Risk - ✔✔This risk is associated with the financial institution's mission and
future business plans. This risk category includes plans for entering new business lines,
expanding existing services through mergers and acquisitions, and enhancing
infrastructure.
✔✔Systemic Risk - ✔✔This risk occurs when a funds transfer system participant is
unable to settle it's commitments, causing other participants to fail.
✔✔Third-Party Risk - ✔✔This risk most often arises from greater complexity, ineffective
risk management by the bank, and inferior performance by the customer associated
with the lack of direct control of activities.
✔✔Transaction Risk - ✔✔Exchange rate risk associated with the time delay between
entering into a contract and settling it. The greater time differential between entrance
and settlement of the contract, the higher this risk.
✔✔Transit Risk - ✔✔Risk of not successfully moving the payment between the buyer
and the seller, or having the payment altered in some way during the transit process.
✔✔FFIEC (Federal Financial Institutions Examination Council) - ✔✔A formal inter-
agency body empowered to prescribe uniform principles, standards, and report forms
for the federal examination of financial institutions by the Board of Governors of the
Federal Reserve System (FRB), the Federal Deposit Insurance Corporation (FDIC), the
National Credit Union Administration (NCUA) the Office of the Comptroller of the
Currency (OCC), and the Consumer Financial Protection Bureau (CFPB), and to make
recommendations to promote uniformity in the supervision of financial institutions.
✔✔Internal Fraud - ✔✔An act of a type intended to defraud, misappropriate property or
circumvent regulations, the law or company policy. excluding diversity/discrimination
events, which involve at least one internal party.
✔✔External Fraud - ✔✔An act of a type intended to defraud, misappropriate property or
circumvent the law, by a third party.
✔✔Employment Practices and Workplace Safety - ✔✔An act inconsistent with
employment, health or safety laws or agreements, from payment of personal
, injury claims, or from diversity/discrimination events.
✔✔Clients, products, and business practices - ✔✔An unintentional or negligent failure
to meet a professional obligation to specific clients (including
fiduciary and suitability requirements), or from the nature or design of a product.
✔✔Damage to physical assets - ✔✔The loss or damage to physical assets from natural
disaster or other events.
✔✔Business Disruption and System Failures - ✔✔Disruption of business or system
failures.
✔✔Execution, delivery, and process
management - ✔✔Failed transaction processing or process management, from
relations with trade counterparties and
vendors.
✔✔FEMA (Failure Mode and Effect Analysis) - ✔✔Provides a means of identifying and
defining the failure points of a process, assigning steps to prioritizing risk incidents and
defining mitigation plans to risk events.
✔✔Advanced Measurement Approaches (AMA) - ✔✔Provides guidance to enhance
operational risk measurement and management.
✔✔Business Resiliency (ACH) - ✔✔The ability of an organization to quickly adapt to
disruptions while maintaining continuous business operations and safeguarding people,
assets, and brand.
✔✔Business Continuity (ACH) - ✔✔The planning and preparation to ensure that an
ACH participant can either continue to operate its ACH processing systems in the case
of service disruptions.
✔✔Information Security (ACH) - ✔✔The protection of information against unauthorized
access to or modification of ACH information. Protect data integrity by
employing secure storage, limited access to the data, redundancy, audit trails, file
accountability, and file balancing.
✔✔Operational Controls (ACH) - ✔✔Controls include file, date, dollar and processing
limits as well as verification of Third-Party Senders and Originators and information
reporting.
✔✔System Failure - ✔✔Caused by a breakdown in the hardware and/or software
supporting the system.
This may result from design defects, insufficient system capacity to handle transaction
volumes, or
GRADED A+
✔✔Reputation Risk - ✔✔Risk that occurs when negative publicity regarding an
institutions business practices leads to a loss of revenue or litigation. For retail-payment
systems, this risk is linked to consumer expectations regarding the delivery of retail
payment services, and the institutions ability to meet it's regulatory and consumer
protection obligations related to those services.
✔✔Strategic Risk - ✔✔This risk is associated with the financial institution's mission and
future business plans. This risk category includes plans for entering new business lines,
expanding existing services through mergers and acquisitions, and enhancing
infrastructure.
✔✔Systemic Risk - ✔✔This risk occurs when a funds transfer system participant is
unable to settle it's commitments, causing other participants to fail.
✔✔Third-Party Risk - ✔✔This risk most often arises from greater complexity, ineffective
risk management by the bank, and inferior performance by the customer associated
with the lack of direct control of activities.
✔✔Transaction Risk - ✔✔Exchange rate risk associated with the time delay between
entering into a contract and settling it. The greater time differential between entrance
and settlement of the contract, the higher this risk.
✔✔Transit Risk - ✔✔Risk of not successfully moving the payment between the buyer
and the seller, or having the payment altered in some way during the transit process.
✔✔FFIEC (Federal Financial Institutions Examination Council) - ✔✔A formal inter-
agency body empowered to prescribe uniform principles, standards, and report forms
for the federal examination of financial institutions by the Board of Governors of the
Federal Reserve System (FRB), the Federal Deposit Insurance Corporation (FDIC), the
National Credit Union Administration (NCUA) the Office of the Comptroller of the
Currency (OCC), and the Consumer Financial Protection Bureau (CFPB), and to make
recommendations to promote uniformity in the supervision of financial institutions.
✔✔Internal Fraud - ✔✔An act of a type intended to defraud, misappropriate property or
circumvent regulations, the law or company policy. excluding diversity/discrimination
events, which involve at least one internal party.
✔✔External Fraud - ✔✔An act of a type intended to defraud, misappropriate property or
circumvent the law, by a third party.
✔✔Employment Practices and Workplace Safety - ✔✔An act inconsistent with
employment, health or safety laws or agreements, from payment of personal
, injury claims, or from diversity/discrimination events.
✔✔Clients, products, and business practices - ✔✔An unintentional or negligent failure
to meet a professional obligation to specific clients (including
fiduciary and suitability requirements), or from the nature or design of a product.
✔✔Damage to physical assets - ✔✔The loss or damage to physical assets from natural
disaster or other events.
✔✔Business Disruption and System Failures - ✔✔Disruption of business or system
failures.
✔✔Execution, delivery, and process
management - ✔✔Failed transaction processing or process management, from
relations with trade counterparties and
vendors.
✔✔FEMA (Failure Mode and Effect Analysis) - ✔✔Provides a means of identifying and
defining the failure points of a process, assigning steps to prioritizing risk incidents and
defining mitigation plans to risk events.
✔✔Advanced Measurement Approaches (AMA) - ✔✔Provides guidance to enhance
operational risk measurement and management.
✔✔Business Resiliency (ACH) - ✔✔The ability of an organization to quickly adapt to
disruptions while maintaining continuous business operations and safeguarding people,
assets, and brand.
✔✔Business Continuity (ACH) - ✔✔The planning and preparation to ensure that an
ACH participant can either continue to operate its ACH processing systems in the case
of service disruptions.
✔✔Information Security (ACH) - ✔✔The protection of information against unauthorized
access to or modification of ACH information. Protect data integrity by
employing secure storage, limited access to the data, redundancy, audit trails, file
accountability, and file balancing.
✔✔Operational Controls (ACH) - ✔✔Controls include file, date, dollar and processing
limits as well as verification of Third-Party Senders and Originators and information
reporting.
✔✔System Failure - ✔✔Caused by a breakdown in the hardware and/or software
supporting the system.
This may result from design defects, insufficient system capacity to handle transaction
volumes, or