FRM Part II · FRM Exam Part II · Risk Mitigation
A bank's operational risk team reviews a payments process in which the same employee can create a new beneficiary, approve the payment and release the funds. Which control principle is most directly breached?
Segregation of duties is breached. One employee creating the beneficiary, approving and releasing the payment can commit and hide errors or fraud alone. Separating initiation, authorization and execution among different people is the standard preventive control for this weakness.
- ASegregation of dutiesCorrect
- BDefense in depth
- CRisk transfer through insurance
- DKey risk indicator thresholding
Explanation
Segregation of duties requires that initiation, authorization and execution of a transaction be performed by different people so that no single individual can commit and conceal an error or fraud. Here one employee controls the whole chain. Insurance and KRI thresholds do not address this design weakness.
Did you get it right without looking?
One question tells you little. A timed set on Risk Mitigation shows your real accuracy, how long you take and where you lose marks.
More Risk Mitigation questions
- A bank wants to reduce its capital requirement by recognizing insurance as a mitigant under an advanced internal modelling approach. Which f…
- A bank classifies its systems into tiers. A risk manager proposes giving the payment-processing system, which would cause severe losses with…
- A bank outsources its loan-servicing platform to a vendor that itself relies on a single cloud provider. The bank's risk committee wants to …
- A payments bank is drafting its business continuity plan for its card-authorisation service. Which measure defines the maximum amount of dat…
- A bank relies on a single cloud provider for its core trading platform. A risk manager is asked to address concentration risk in this third-…
- A bank's operations team reviews its payment-release process. A single clerk can create a new beneficiary, approve the payment and release f…