For the Northern Rock case study, what was the low-probability-high-impact event that was most responsible for the loss event?
Answer : C
Step 1: Understanding the Northern Rock Case Study
Northern Rock was a UK bank that collapsed in 2007 due to its heavy reliance on short-term wholesale funding rather than customer deposits.
When the 2007 financial crisis hit, the inter-bank lending market and commercial paper market froze, cutting off Northern Rock's access to liquidity.
Step 2: Why Option C Is Correct
Northern Rock depended on short-term borrowing to fund long-term mortgage lending.
When the liquidity crisis hit, it couldn't refinance its debt, leading to a bank run and collapse.
The Bank of England had to intervene, and the UK government nationalized Northern Rock in 2008.
Step 3: Why the Other Options Are Incorrect
Option A ('Acquisition of Merrill Lynch') Incorrect because this happened in 2008, after Northern Rock's failure.
Option B ('Withdrawal of Deposit Protection') Incorrect because UK deposit protection remained in place.
Option D ('Real estate exposure in Berlin') Incorrect because Northern Rock's problem was funding liquidity, not real estate losses.
PRMIA Risk Reference Used:
PRMIA Liquidity Risk Management Framework -- Describes how liquidity shocks impact banks like Northern Rock.
Basel III Liquidity Coverage Ratio (LCR) Standards -- Created after Northern Rock to prevent similar liquidity crises.
Final Conclusion:
The collapse of the inter-bank and commercial paper markets was the key low-probability-high-impact event that led to Northern Rock's failure, making Option C the correct answer.
Which of the following best describes the role of the compliance department?
Answer : D
Three Lines of Defense Model
The compliance department functions as the second line of defense, ensuring oversight over the first line's compliance controls.
It does not directly implement controls but monitors and advises on compliance risk management.
Responsibilities of the Compliance Department
Ensures regulatory compliance with laws, policies, and industry standards.
Monitors and enforces risk management controls within business operations.
Provides advisory and training on compliance risks.
Why Answer D is Correct
The first line of defense (business operations) is responsible for executing compliance controls.
The compliance department (second line) provides oversight and governance to ensure compliance adherence.
Why Other Answers Are Incorrect
Option
Explanation
A . The compliance department is responsible for implementing the first line's compliance risk management controls.
Incorrect -- The first line (business units) implement compliance controls, while compliance oversees.
B . The compliance department is responsible for providing oversight over the auditor's implementation of compliance risk management controls.
Incorrect -- Internal audit is part of the third line of defense, not directly overseen by compliance.
C . The compliance department is responsible for providing oversight over the board's implementation of compliance risk management controls.
Incorrect -- The board provides high-level governance; compliance ensures business adherence to regulations.
PRMIA Reference for Verification
PRMIA Governance & Compliance Oversight Framework
Basel Committee's Guidelines on Compliance Risk Management
The DORA act's full name is which of the following?
Answer : D
Definition of DORA
The Digital Operational Resilience Act (DORA) is a regulation by the European Union (EU) aimed at strengthening the digital resilience of financial institutions.
It establishes a regulatory framework for managing information and communication technology (ICT) risks in the financial sector.
Key Objectives of DORA
Ensures that financial institutions can withstand, respond to, and recover from cyber threats and ICT-related disruptions.
Introduces standards for risk management, incident reporting, and third-party ICT risk oversight.
Why Other Answers Are Incorrect
Option
Explanation
A . Domain for Operational Risk Act.
Incorrect -- No such regulation exists under this name.
B . Digital Operational Risk Act.
Incorrect -- The official name is Digital Operational Resilience Act (DORA).
C . Daily Operational Resilience Act.
Incorrect -- DORA is not focused on daily operations but rather long-term digital resilience.
PRMIA Reference for Verification
PRMIA Risk Governance & Digital Resilience Standards
European Commission's Official DORA Regulation
Governance can be defined as which of the following?
Answer : D
Definition of Governance
Governance refers to the framework of policies, principles, and processes used to guide corporate decision-making and strategic direction.
It ensures accountability, transparency, and risk oversight within an organization.
Key Elements of Governance
Risk oversight -- Ensuring risks are properly identified and managed.
Accountability structures -- Defining roles and responsibilities.
Decision-making frameworks -- Establishing policies for long-term corporate success.
Why Other Answers Are Incorrect
Option
Explanation
A . Governance is a structure specifying the daily operation of a firm.
Incorrect -- Governance focuses on high-level corporate oversight, not day-to-day operations.
B . Governance is a structure specifying the ways in which reporting is made to the primary regulator.
Incorrect -- Governance is broader than just regulatory reporting.
C . Governance is being replaced by management in all firms that are regulated.
Incorrect -- Governance and management are separate but complementary; governance provides oversight, while management executes strategy.
PRMIA Reference for Verification
PRMIA 10 Principles of Good Governance
In operational resilience, material customer detriment or significant harm to the customer is which of the following?
Answer : D
Step 1: Definition of Material Customer Detriment
Material customer detriment refers to service disruptions that cause financial loss, inability to access essential services, or significant hardship.
PRMIA and UK FCA Operational Resilience Standards define 'significant harm' as going beyond inconvenience to include monetary or operational distress.
Step 2: Why Option D is Correct
Significant harm occurs when customers face tangible financial or service losses, not just reputational inconvenience.
Regulatory frameworks (e.g., Basel, FCA, PRMIA) require banks to protect customers from material disruptions.
Step 3: Why the Other Options Are Incorrect
Option A ('Low threshold, any complaint') Incorrect because not all complaints indicate material detriment.
Option B ('Inconvenience and reputational damage') Incorrect because true material harm is more than just inconvenience.
Option C ('Financial system resilience') Incorrect because this describes systemic financial stability, not customer impact.
PRMIA Risk Reference Used:
PRMIA Operational Resilience Framework -- Defines material customer detriment.
UK FCA Operational Resilience Guidelines -- Requires firms to minimize severe harm to customers.
Final Conclusion:
Material customer detriment involves actual financial hardship, not just inconvenience, making Option D the correct answer.
In relation to financial crime. OFAC is a definition for which organization?
Answer : D
Step 1: Understanding OFAC
OFAC (Office of Foreign Assets Control) is a U.S. Treasury Department agency responsible for enforcing economic and trade sanctions based on U.S. foreign policy and national security goals.
It prevents financial crime by restricting transactions with sanctioned individuals, entities, and countries.
Step 2: Role of OFAC in Financial Crime Prevention
OFAC administers sanctions to prevent money laundering, terrorism financing, and other illicit activities.
Financial institutions must comply with OFAC regulations to avoid heavy fines and reputational damage.
PRMIA's Financial Crime Risk Guidelines emphasize the importance of OFAC compliance in risk management.
Step 3: Why the Other Options Are Incorrect
Option A ('Office of Financial Asset Control') -- Incorrect wording; OFAC deals with foreign assets, not just financial assets.
Option B ('Office of Foreigner and Other Control') -- OFAC does not regulate foreigners broadly; it targets specific foreign assets and transactions.
Option C ('Office for Asset Control') -- Missing 'Foreign', which is critical to OFAC's function.
PRMIA Risk Reference Used:
PRMIA Financial Crime Risk Management Guidelines -- Emphasizes regulatory compliance with OFAC.
PRMIA Compliance and Sanctions Risk Standards -- Stresses the role of OFAC in preventing illicit financial activities.
Final Conclusion:
OFAC stands for the Office of Foreign Assets Control, making Option D the correct answer.
For the FTX case study, what was the "backdoor" used for?
Answer : B
The FTX collapse involved fraudulent fund mismanagement, where FTX executives created a 'backdoor' to allow Alameda Research (FTX's sister trading firm) to borrow client funds without their consent.
Step 1: The 'Backdoor' in FTX
The backdoor was a hidden code in FTX's system, allegedly created by Sam Bankman-Fried, which allowed Alameda to access customer deposits without triggering alerts to auditors or compliance teams.
Alameda used these funds for risky trading strategies and investments, leading to the eventual collapse of FTX when a liquidity crunch exposed the missing funds.
Step 2: Why the Other Options Are Incorrect
Option A ('allowed a stablecoin to be removed from the ledger and added to the balance sheet')
Incorrect because FTX's fraud involved misuse of customer funds, not just a stablecoin misclassification.
Option C ('allowed currency traders to smooth profits and conceal losses for over two years')
Incorrect because this sounds more like LIBOR-rigging scandals, whereas FTX misappropriated client funds.
Option D ('allowed a rapid pace of acquisitions but poor integration of acquired companies')
Incorrect because FTX's collapse was due to financial fraud, not poor acquisition strategy.
PRMIA Risk Reference Used:
PRMIA Financial Crime Risk Management -- Discusses insider risk and fraudulent misappropriation of funds.
FTX Collapse Reports -- SEC, CFTC, and DOJ filings confirm that Alameda had unauthorized access to client funds.
Final Conclusion:
FTX's backdoor enabled Alameda to take $65 billion in client funds without permission, making Option B the correct answer.