FRM Part II · FRM Exam Part II · Risk Mitigation
Internal audit finds that a bank's access-review control is well designed but was not performed in two of the last four quarters. How should this control be rated?
The control has effective design but deficient operating effectiveness. A well-designed access review that is skipped in half of the quarters does not consistently achieve its objective, so the failure lies in execution, not in how the control was designed.
- ADesign effective but operating effectiveness deficientCorrect
- BDesign deficient but operating effectiveness satisfactory
- CFully effective because the design is sound
- DNot applicable because it is a detective control
Explanation
Control testing separates design effectiveness (whether the control, if performed, would meet its objective) from operating effectiveness (whether it was performed consistently). Missing half the executions is an operating failure despite a sound design.
Did you get it right without looking?
One question tells you little. A timed set on Risk Mitigation shows your real accuracy, how long you take and where you lose marks.
More Risk Mitigation questions
- A firm is designing scenario testing for operational resilience. Which scenario design best tests resilience of a critical service rather th…
- A bank wants its annual continuity testing to provide the strongest evidence that critical staff and systems can actually perform under a se…
- A bank assesses a key control that addresses a risk with inherent annual expected loss of USD 20 million. Testing shows the control is effec…
- A bank buys an operational risk insurance policy with a per-event deductible of USD 5 million and a per-event limit of USD 40 million. A sin…
- A bank's payments platform supports a critical business service. Management sets a statement of the maximum disruption it is willing to tole…
- A bank outsources its payment processing to a single provider. Risk management is concerned that a failure of the provider would halt paymen…