
[2025] 8020 Exam Dumps, Test Engine Practice Test Questions
Pass 8020 exam [Dec 07, 2025] Updated 62 Questions
NEW QUESTION # 14
Which of the Basel Accords, published in 2004, introduced operational risk as a risk subjected to a capital charge?
- A. Basel IV
- B. Basel I
- C. Basel II
- D. Basel III
Answer: C
Explanation:
Introduction of Operational Risk in Basel Accords
Basel I (1988) → Focused only on credit risk and market risk; operational risk was not yet included.
Basel II (2004) → Introduced operational risk as a separate category, subject to capital requirements.
Basel III (2010) → Strengthened capital and liquidity requirements but did not introduce operational risk.
Basel IV (2017, still evolving) → Adjusts Basel III reforms but does not introduce operational risk as a new category.
Why Answer B is Correct
Basel II (2004) was the first to introduce operational risk as a risk requiring a capital charge.
Why Other Answers Are Incorrect
Option
Explanation:
A . Basel I
Incorrect - Basel I focused on credit risk and market risk, with no capital requirements for operational risk.
C . Basel III
Incorrect - Basel III strengthened Basel II but did not introduce operational risk.
D . Basel IV
Incorrect - Basel IV refines Basel III but does not introduce operational risk as a new capital charge.
PRMIA Reference for Verification
Basel II (2004) Operational Risk Framework
PRMIA Operational Risk Management Guidelines
NEW QUESTION # 15
For the National Australia Bank - FX Options case study, large and unusual transaction activity was a concern for what reason?
- A. Deep-in-the-money options and other complex structured transactions aided in the smoothing of losses.
- B. Deep-in-the-money options and other complex structured transactions aided in the smoothing of profits and losses.
- C. Deep-in-the-money options aided in the smoothing of losses.
- D. Complex structured transactions aided in the smoothing of losses.
Answer: B
Explanation:
The National Australia Bank (NAB) FX Options Case Study is a well-known example of operational risk, fraud, and governance failure.
What Happened?
Traders engaged in unauthorized foreign exchange (FX) options trading, using deep-in-the-money options and other complex instruments.
They manipulated profits and losses to smooth earnings and mislead risk managers and auditors.
Why Answer C is Correct
The traders smoothed both profits and losses to avoid detection and ensure continued trading bonuses.
This aligns with PRMIA's Operational Risk Management Guidelines, which highlight that hidden trading losses and smoothing techniques increase financial crime risk.
Why Other Answers Are Incorrect
Option
Explanation:
A . Complex structured transactions aided in the smoothing of losses.
Incorrect - Smoothing occurred with both profits and losses, not just losses.
B . Deep-in-the-money options and other complex structured transactions aided in the smoothing of losses.
Incorrect - Profits were also manipulated, making this answer incomplete.
D . Deep-in-the-money options aided in the smoothing of losses.
Incorrect - This focuses only on deep-in-the-money options and ignores other structured transactions involved in the fraud.
PRMIA Reference for Verification
PRMIA Fraud and Risk Management Case Studies
Basel Principles on Market Risk and Internal Control Failures
NEW QUESTION # 16
Which of the below is accurate about a risk assessment workshop?
- A. Although workshops will take on their own form; it is best to prepare thoroughly ahead of time.
- B. The workshop should be run spontaneously so that proper discussion can take place.
- C. Compliance experts should not attend the workshop so that proper discussion can take place.
- D. Risk management should not attend the workshop so that proper discussion can take place.
Answer: A
Explanation:
Step 1: What Is a Risk Assessment Workshop?
A risk assessment workshop is a structured session where key stakeholders identify, evaluate, and prioritize risks.
Effective workshops require preparation, clear objectives, and structured discussions to ensure meaningful risk analysis.
Step 2: Why Option B is Correct
PRMIA and best practices recommend thorough preparation, including:
Setting objectives
Defining risk categories
Ensuring participation from risk, compliance, and business units
Providing risk assessment tools/templates
Step 3: Why the Other Options Are Incorrect
Option A ("Run spontaneously") → Incorrect because lack of preparation leads to poor discussions and missed risks.
Option C ("Risk management should not attend") → Incorrect because risk managers provide key expertise to guide discussions.
Option D ("Compliance experts should not attend") → Incorrect because compliance provides regulatory insights essential to risk assessment.
PRMIA Risk Reference Used:
PRMIA Risk Assessment Framework - Recommends structured, well-prepared workshops.
ISO 31000 Risk Management Standard - Supports proactive workshop planning.
Final Conclusion:
Risk assessment workshops should be well-prepared to ensure meaningful discussions and effective risk identification, making Option B the correct answer.
NEW QUESTION # 17
In order for a KRI to be effective it must be:
- A. Qualitative, Consistent Efficient & Repeatable.
- B. Quantitative, Repeatable and Efficient.
- C. Quantitative and Qualitative. Consistent. Efficient & Repeatable.
- D. Quantitative, Consistent and Comparable. Efficient & Repeatable
Answer: C
Explanation:
Definition of an Effective Key Risk Indicator (KRI)
A KRI is a metric used to identify, measure, and monitor emerging risks.
To be effective, KRIs must be both quantitative and qualitative, allowing for a comprehensive risk view.
Key Characteristics of Effective KRIs
Quantitative - Uses numerical data for trend analysis.
Qualitative - Incorporates expert judgment and scenario-based insights.
Consistent - Maintains uniform definitions across reporting periods.
Efficient & Repeatable - Must be easily measured and consistently reported.
Why Other Answers Are Incorrect
Option
Explanation:
B . Qualitative, Consistent, Efficient & Repeatable.
Incorrect - Excludes quantitative aspects, which are essential for KRIs.
C . Quantitative, Consistent, Comparable, Efficient & Repeatable.
Incorrect - While comparison is useful, qualitative factors are missing, making this answer incomplete.
D . Quantitative, Repeatable and Efficient.
Incorrect - Lacks qualitative insights and consistency as key factors for KRIs.
PRMIA Reference for Verification
PRMIA Risk Indicator Guidelines
Basel Committee's Principles on Risk Data and KRI
NEW QUESTION # 18
In operational resilience, what is impact tolerance?
- A. Impact tolerance is a firm's risk capacity statement.
- B. Impact tolerance is a firm's tolerance for disruption to a particular business service.
- C. Impact tolerance is a firm's tolerance for disruption to a particular business process.
- D. Impact tolerance is a firm's risk appetite statement.
Answer: B
NEW QUESTION # 19
An example of Credit Risk events with an Operational Risk component included?
- A. Ponzi Schemes.
- B. Ponzi Schemes & Rogue Trading.
- C. Failure in loan approval process leading to erroneously approved loans.
- D. Rogue Trading.
Answer: B
Explanation:
Step 1: Understanding Credit Risk with an Operational Risk Component
Credit Risk: Risk of loss due to borrower default.
Operational Risk: Risk of loss due to failed internal processes, fraud, or misconduct.
Step 2: Why Option D is Correct
Ponzi Schemes: Fraudulent investment scams disguise credit risk as legitimate lending but collapse when new funds dry up.
Rogue Trading: Traders take unauthorized risks that can lead to credit defaults or massive financial losses.
Step 3: Why the Other Options Are Incorrect
Option A ("Failure in loan approval process") → This is an Operational Risk issue, but does not always create Credit Risk.
Option B ("Ponzi Schemes") → Partially correct, but does not include Rogue Trading, which is also a credit risk-related operational failure.
Option C ("Rogue Trading") → Partially correct, but does not include Ponzi Schemes, which are another key example.
PRMIA Risk Reference Used:
PRMIA Operational Risk Framework - Highlights fraud-based Credit Risk events.
Basel II/III Operational Risk Guidelines - Discusses trading misconduct and credit risk misrepresentation.
Final Conclusion:
Both Ponzi Schemes and Rogue Trading involve credit risk failures caused by operational misconduct, making Option D the correct answer.
NEW QUESTION # 20
In relation to financial crime. OFAC is a definition for which organization?
- A. Office for Asset Control.
- B. Office of Foreigner and other Control.
- C. Office of Financial Asset Control.
- D. Office of Foreign Asset Control.
Answer: D
Explanation:
Step 1: Understanding OFAC
OFAC (Office of Foreign Assets Control) is a U.S. Treasury Department agency responsible for enforcing economic and trade sanctions based on U.S. foreign policy and national security goals.
It prevents financial crime by restricting transactions with sanctioned individuals, entities, and countries.
Step 2: Role of OFAC in Financial Crime Prevention
OFAC administers sanctions to prevent money laundering, terrorism financing, and other illicit activities.
Financial institutions must comply with OFAC regulations to avoid heavy fines and reputational damage.
PRMIA's Financial Crime Risk Guidelines emphasize the importance of OFAC compliance in risk management.
Step 3: Why the Other Options Are Incorrect
Option A ("Office of Financial Asset Control") - Incorrect wording; OFAC deals with foreign assets, not just financial assets.
Option B ("Office of Foreigner and Other Control") - OFAC does not regulate foreigners broadly; it targets specific foreign assets and transactions.
Option C ("Office for Asset Control") - Missing "Foreign", which is critical to OFAC's function.
PRMIA Risk Reference Used:
PRMIA Financial Crime Risk Management Guidelines - Emphasizes regulatory compliance with OFAC.
PRMIA Compliance and Sanctions Risk Standards - Stresses the role of OFAC in preventing illicit financial activities.
Final Conclusion:
OFAC stands for the Office of Foreign Assets Control, making Option D the correct answer.
NEW QUESTION # 21
Internal loss data (ILD) consists of what kind of data?
- A. It consists of scenario data develeloped to calcuate the future operational loss incidents of a bank.
- B. It consists of the Key Risk Indicators of a bank.
- C. It consists of historical operational loss incidents of a bank.
- D. It consists of near miss operational loss incidents of a bank.
Answer: C
Explanation:
Definition of Internal Loss Data (ILD)
Internal Loss Data (ILD) refers to historical records of actual operational losses incurred by a bank.
These losses are used for risk assessment, capital calculations, and trend analysis under Basel III's Operational Risk Framework.
Key Characteristics of ILD
Captures actual past loss events, such as fraud, system failures, and compliance breaches.
Supports the identification of risk trends and weak control areas.
Used for operational risk capital modeling, along with external loss data and scenario analysis.
Why Other Answers Are Incorrect
Option
Explanation:
A . It consists of near miss operational loss incidents of a bank.
Incorrect - ILD captures actual losses, while near misses are reported separately.
C . It consists of the Key Risk Indicators of a bank.
Incorrect - KRIs are forward-looking risk metrics, while ILD focuses on historical data.
D . It consists of scenario data developed to calculate the future operational loss incidents of a bank.
Incorrect - ILD is historical, whereas scenario data is used for predictive analysis.
PRMIA Reference for Verification
Basel III & PRMIA Operational Risk Data Framework
PRMIA Risk Management Standards for ILD
NEW QUESTION # 22
Two of the four key resources that are regarded as critical to maintain confidence and calibrate Risk Appetite to are?
- A. Quality human resources and reputation.
- B. Capital expenditure and liquidity.
- C. Net earnings and capital.
- D. Strong regulatory assessment and net earnings.
Answer: C
Explanation:
Key Resources for Calibrating Risk Appetite
Risk appetite defines how much risk an organization is willing to accept to achieve its objectives.
Two of the most critical resources for maintaining confidence and setting risk appetite are net earnings and capital.
Why Net Earnings and Capital are Critical
Net earnings reflect profitability and financial stability, influencing risk-taking capacity.
Capital ensures that the institution can absorb losses and meet regulatory requirements.
Basel III emphasizes capital adequacy as a core measure of financial resilience.
Why Answer B is Correct
Net earnings support operational stability, while capital determines how much risk an institution can bear.
Both are used to define and calibrate risk appetite levels.
Why Other Answers Are Incorrect
Option
Explanation:
A . Capital expenditure and liquidity.
Incorrect - Capital expenditure is an investment measure, not a direct risk appetite determinant.
C . Strong regulatory assessment and net earnings.
Incorrect - Regulatory assessments are important but do not directly set risk appetite.
D . Quality human resources and reputation.
Incorrect - HR and reputation are important for governance but do not directly influence risk capital and earnings stability.
PRMIA Reference for Verification
PRMIA Risk Appetite Framework
Basel III Capital and Earnings Management Guidelines
NEW QUESTION # 23
In Operational Resilience, which of the following is not an important measure of whether a Business Service can be considered Critical?
- A. Whether a disruption to the provision of the service could exceed risk appetite.
- B. Whether a disruption to the provision of the service could harm market integrity.
- C. Whether a disruption to the provision of the service could threaten a firm's viability.
- D. Whether a disruption to the provision of the service could cause material customer detriment.
Answer: A
Explanation:
Step 1: Definition of a Critical Business Service in Operational Resilience A Critical Business Service is one whose failure could result in severe harm to customers, financial markets, or the firm's viability.
Regulators (e.g., Bank of England, Basel Committee, PRMIA) define three primary factors for identifying critical services:
Customer impact
Market integrity impact
Firm viability impact
Step 2: Why Option C Is Incorrect
Risk appetite is an internal business decision, not an external measure of criticality.
A service can be critical even if its disruption stays within risk appetite.
Criticality is based on external impacts, not just internal risk limits.
Step 3: Why the Other Options Are Correct
Option A ("Material customer detriment") → Correct as customer harm defines critical services.
Option B ("Harm to market integrity") → Correct as market stability is a regulatory priority.
Option D ("Threaten firm viability") → Correct as critical services often determine business survival.
PRMIA Risk Reference Used:
PRMIA Operational Resilience Framework - Defines criteria for critical business services.
Basel Committee Operational Risk Guidelines - Highlights customer, market, and firm viability as resilience factors.
Final Conclusion:
Risk appetite is an internal benchmark, not a measure of critical service designation, making Option C the correct answer.
NEW QUESTION # 24
How can a chief risk officer encourage the governing body and executive management team to create a stronger risk culture?
- A. Balance rewarding success in profitability goals with punishment when there is a failure to achieve goals.
- B. Establish a set of objectives that the board and executive team must adhere to.
- C. Having a vision of achievable but not excessive ambition.
- D. Discourage personal accountability to avoid a blame culture.
Answer: C
Explanation:
A Chief Risk Officer (CRO) plays a crucial role in shaping and strengthening the risk culture within an organization. PRMIA defines risk culture as the shared values, beliefs, knowledge, and understanding about risk that drive behaviors within an institution.
Setting a Clear Vision
The CRO should communicate a vision of risk management that aligns with organizational goals while ensuring that risk-taking remains within acceptable limits.
The vision should be achievable and realistic, rather than overly ambitious, which could incentivize reckless risk-taking.
Embedding Risk Awareness into Decision-Making
A strong risk culture ensures that risk considerations are embedded into business decision-making rather than treated as a separate compliance exercise.
This is supported by PRMIA's Enterprise Risk Management (ERM) Framework, which stresses integrating risk management into strategy and operations.
Avoiding a Blame Culture
A risk-aware organization promotes accountability without fear, enabling employees to report risks without retribution.
Option B (Discourage personal accountability to avoid a blame culture) is incorrect because personal accountability is essential for a healthy risk culture.
Avoiding a Strict, Prescriptive Approach
A set of rigid objectives that must be followed by the executive team (Option C) does not foster a dynamic, evolving risk culture.
Instead, risk culture should be flexible and adaptive to emerging risks.
Balancing Incentives and Consequences
While balancing rewards with penalties (Option D) is part of governance, a strong risk culture is not built solely through fear of punishment.
PRMIA emphasizes positive reinforcement, such as linking risk management behaviors to performance evaluations and incentives.
PRMIA Reference for Verification
PRMIA Risk Governance Framework - Discusses the role of leadership in shaping risk culture.
PRMIA Standards on Enterprise Risk Management (ERM) - Covers best practices for embedding risk culture within organizations.
NEW QUESTION # 25
Stafford Beers Viable System Model (VSM) has several implementation elements. Which of the following is not one of these?
- A. Process
- B. Input
- C. Governance
- D. Output
Answer: B
Explanation:
Stafford Beer's Viable System Model (VSM)
VSM is a cybernetic model designed to analyze and improve organizational structures.
It consists of five core subsystems that define governance and operations.
Why Answer B is Correct
The VSM does not explicitly include "Input" as a key component.
The key elements of VSM include Governance, Process, and Output, but it does not define "Input" as a standalone concept.
Why Other Answers Are Incorrect
Option
Explanation:
A . Governance
Correct - Governance is part of VSM and deals with decision-making and oversight.
C . Process
Correct - Process represents the operational functions within VSM.
D . Output
Correct - Output refers to the results of the system's operations.
PRMIA Reference for Verification
PRMIA Governance and Cybernetic Systems Guidelines
Stafford Beer's Viable System Model Framework
NEW QUESTION # 26
Which of the following are the most relevant ways a firm can ensure they are in line with consumer protection?
- A. Add a consumer protection section to all reports.
- B. Treat customers fairly, place customer interests ahead of its own and keep promises to customers
- C. This risk cannot be managed.
- D. Engage with consumers once there are enough complaints.
Answer: B
Explanation:
Definition of Consumer Protection in Risk Management
Consumer protection ensures ethical business practices, transparency, and regulatory compliance.
It builds trust with customers and reduces legal and reputational risks.
Key Principles of Consumer Protection
Treating customers fairly → Ensures honest and ethical financial services.
Prioritizing customer interests → Prevents conflicts of interest and unfair treatment.
Honoring commitments → Strengthens customer confidence and regulatory trust.
Why Answer C is Correct
Following these principles ensures regulatory compliance, customer satisfaction, and risk mitigation.
Why Other Answers Are Incorrect
Option
Explanation:
A . Engage with consumers once there are enough complaints.
Incorrect - Proactive engagement is essential; waiting for complaints is a reactive and poor risk management approach.
B . Add a consumer protection section to all reports.
Incorrect - Documentation alone does not ensure fair treatment; actions matter more.
D . This risk cannot be managed.
Incorrect - Consumer protection risks can and should be actively managed.
PRMIA Reference for Verification
PRMIA Consumer Protection & Fair Treatment Standards
Financial Conduct Authority (FCA) Consumer Duty Guidelines
NEW QUESTION # 27
For credit risk losses containing operational risk elements that have been historically included in an organizations' credit risk database how should the loss amount be treated?
- A. The loss amount is split into credit and operational risk components.
- B. The entire loss amount is treated as credit risk, but the loss is entered as a memorandum within the operational loss database and not used for capital modeling purposes.
- C. The entire loss amount is treated as credit risk
- D. The entire loss amount is treated as operational risk.
Answer: A
Explanation:
Understanding Credit Risk and Operational Risk Overlap
In some cases, credit risk losses contain elements of operational risk, such as fraud, documentation errors, or IT failures affecting credit transactions.
Basel II and III frameworks require institutions to distinguish between pure credit risk losses and operational risk components within those losses.
Treatment of Losses
The credit-related portion is accounted for under credit risk capital calculations.
The operational risk portion (e.g., fraud-related losses) should be classified separately and included in operational risk databases for risk measurement.
Why Answer C is Correct
Basel III and PRMIA recommend a clear split between credit risk and operational risk components to ensure accurate risk modeling.
If operational risk elements are ignored, an organization may underestimate its true operational risk exposure.
Why Other Answers Are Incorrect
Option
Explanation:
A . The entire loss amount is treated as credit risk.
Incorrect - This ignores operational risk components that should be accounted for separately.
B . The entire loss amount is treated as operational risk.
Incorrect - Credit risk losses are typically dominant in lending-related losses and should not be fully classified as operational risk.
D . The entire loss amount is treated as credit risk, but the loss is entered as a memorandum within the operational loss database and not used for capital modeling purposes.
Incorrect - The operational risk portion must be considered for capital modeling, not just recorded as a memo.
PRMIA Reference for Verification
Basel II & III Guidelines on Credit and Operational Risk Integration
PRMIA Operational Risk Framework
NEW QUESTION # 28
For the Northern Rock case study, what was the low-probability-high-impact event that was most responsible for the loss event?
- A. The Bank of England's withdrawal of Deposit Protection.
- B. Liquidity dried up in the inter-bank and commercial paper markets.
- C. An exposure to real estate funds, heavily concentrated in Berlin.
- D. The acquisition of Merrill Lynch by Bank of America.
Answer: B
Explanation:
Step 1: Understanding the Northern Rock Case Study
Northern Rock was a UK bank that collapsed in 2007 due to its heavy reliance on short-term wholesale funding rather than customer deposits.
When the 2007 financial crisis hit, the inter-bank lending market and commercial paper market froze, cutting off Northern Rock's access to liquidity.
Step 2: Why Option C Is Correct
Northern Rock depended on short-term borrowing to fund long-term mortgage lending.
When the liquidity crisis hit, it couldn't refinance its debt, leading to a bank run and collapse.
The Bank of England had to intervene, and the UK government nationalized Northern Rock in 2008.
Step 3: Why the Other Options Are Incorrect
Option A ("Acquisition of Merrill Lynch") → Incorrect because this happened in 2008, after Northern Rock's failure.
Option B ("Withdrawal of Deposit Protection") → Incorrect because UK deposit protection remained in place.
Option D ("Real estate exposure in Berlin") → Incorrect because Northern Rock's problem was funding liquidity, not real estate losses.
PRMIA Risk Reference Used:
PRMIA Liquidity Risk Management Framework - Describes how liquidity shocks impact banks like Northern Rock.
Basel III Liquidity Coverage Ratio (LCR) Standards - Created after Northern Rock to prevent similar liquidity crises.
Final Conclusion:
The collapse of the inter-bank and commercial paper markets was the key low-probability-high-impact event that led to Northern Rock's failure, making Option C the correct answer.
NEW QUESTION # 29
Which of the following is not an action available to management and the governing body to align the strategy with Risk Capacity.
- A. Reduce scale of risks - shrink balance sheet or activity levels.
- B. Reduce retained earning - by increasing dividends in order to return funds to investors and improve reputation.
- C. Improve quality of risks - pursue lower rewarding risks with better prospects.
- D. Improve retained earnings - by increasing net income or reducing dividends in order to increase risk capacity.
Answer: B
Explanation:
Step 1: Aligning Strategy with Risk Capacity
Risk capacity is the maximum level of risk a firm can bear based on financial resources, earnings, and capital structure.
Management can adjust risk capacity by modifying risk exposure, balance sheet size, or earnings retention.
Step 2: Why Option C Is Incorrect
Increasing dividends reduces retained earnings, which lowers capital reserves and reduces risk capacity.
Firms seeking to improve risk capacity should retain earnings, not distribute them.
Step 3: Why the Other Options Are Correct
Option A ("Reduce scale of risks") → Correct as reducing balance sheet size lowers risk exposure.
Option B ("Improve quality of risks") → Correct as taking on lower-risk assets improves stability.
Option D ("Improve retained earnings") → Correct as more capital increases risk capacity.
PRMIA Risk Reference Used:
PRMIA Capital Management Framework - Defines risk capacity and earnings retention strategies.
Basel III Capital Standards - Stresses retained earnings as a key factor in risk capacity.
Final Conclusion:
Reducing retained earnings through dividends weakens risk capacity, making Option C the correct answer.
NEW QUESTION # 30
What are the objectives of conducting an internal loss investigation?
- A. Increase understanding of root causes, focus attention on remediation, and improve the quality of scenario analysis and risk assessments.
- B. Increase understanding of root causes, focus attention on who caused the issue, and improve the quality of scenario analysis and risk assessments.
- C. Increase understanding of root causes, focus attention on remediation, and ascertain responsibility for the loss event.
- D. This is determined on a case by case basis by the HR team.
Answer: A
Explanation:
tep 1: Purpose of Internal Loss Investigations
Internal loss investigations analyze past loss events to identify root causes, improve controls, and enhance risk assessments.
Step 2: Why Option A Is Correct
Root Cause Analysis: Identifying why the loss occurred.
Focus on Remediation: Implementing corrective measures to prevent recurrence.
Scenario Analysis Improvement: Using lessons learned to enhance risk scenario modeling.
Step 3: Why the Other Options Are Incorrect
Option B ("Focus on who caused the issue") → Incorrect because loss investigations are about systemic issues, not assigning blame.
Option C ("Ascertain responsibility for the loss event") → Incorrect because the focus is on process improvements, not individual accountability.
Option D ("Determined by HR on a case-by-case basis") → Incorrect because HR does not dictate risk investigations-risk and compliance functions do.
PRMIA Risk Reference Used:
PRMIA Operational Risk Framework - Emphasizes loss investigations for systemic risk management.
Basel III Risk Governance Standards - Defines loss event analysis as a key risk management tool.
NEW QUESTION # 31
Process mapping is:
- A. A good visualization tool for understanding where hand-offs and hand-ins may occur.
- B. A useful tool for understanding process intensive activities.
- C. All of the above.
- D. A helpful tool for understanding where control gaps may exist.
Answer: C
Explanation:
Process Mapping is a risk management tool used to visualize workflows, identify inefficiencies, and detect control gaps. PRMIA defines process mapping as an essential operational risk management tool.
Step 1: Understanding Process Mapping
Helps analyze complex, process-intensive activities (Option A).
Reveals control weaknesses that could lead to operational risks (Option B).
Improves hand-offs and collaboration between teams (Option C).
Step 2: Why "All of the Above" is Correct
Process mapping serves multiple risk management purposes, making all listed options valid.
PRMIA Risk Reference Used:
PRMIA Operational Risk Management Guidelines - Recommends process mapping to identify inefficiencies and control gaps.
PRMIA Risk Governance Framework - Encourages visualization tools for process improvement.
Final Conclusion:
Process mapping improves risk awareness, identifies control gaps, and enhances operational workflows, making Option D the correct answer.
NEW QUESTION # 32
Which of the following principles best applies to a compliance function?
- A. The compliance function should be independent of the business (following a three lines of defense model).
- B. The risk function should be outsourced if there is a compliance function.
- C. The compliance function should report to the business (even when following a three lines of defense model).
- D. The compliance function should be outsourced if there is a risk function.
Answer: A
Explanation:
Step 1: Compliance Function and the Three Lines of Defense Model
The Three Lines of Defense (3LoD) model ensures that risk management responsibilities are properly segregated:
First Line: Business units (own and manage risk).
Second Line: Compliance and risk management (independent oversight).
Third Line: Internal audit (provides assurance).
Step 2: Why Compliance Must Be Independent
PRMIA and Basel Compliance Principles state that compliance should not report to business units, as this creates a conflict of interest.
Compliance must be independent to ensure objective oversight of regulatory adherence.
Step 3: Why the Other Options Are Incorrect
Option A ("Report to the business") → Incorrect because compliance must provide independent oversight, not report to business units.
Option C ("Outsource compliance if risk function exists") → Incorrect because compliance and risk functions have distinct roles.
Option D ("Outsource risk if compliance exists") → Incorrect because risk management is a core function, not an outsourcing candidate.
PRMIA Risk Reference Used:
PRMIA Compliance Risk Governance - States compliance must be independent under the Three Lines of Defense model.
Basel Compliance Principles - Recommends separate reporting structures for compliance and business units.
Final Conclusion:
Compliance must be independent from the business to avoid conflicts of interest, making Option B the correct answer.
NEW QUESTION # 33
The acronym ESG can stand for:
- A. Environmental. Strategy, and corporate Governance.
- B. Enhanced Social Governance.
- C. Extra Social Governance.
- D. Environmental. Social and corporate Governance.
Answer: D
Explanation:
Step 1: Definition of ESG
ESG (Environmental, Social, and Corporate Governance) refers to the three core factors used to evaluate a company's sustainability and ethical impact.
ESG is now a key part of risk management, influencing investment decisions, regulatory compliance, and corporate strategy.
Step 2: Breakdown of ESG Components
Environmental (E): Climate change, carbon emissions, resource management.
Social (S): Diversity & inclusion, labor rights, community engagement.
Governance (G): Board structure, executive pay, corporate ethics.
Step 3: Why the Other Options Are Incorrect
Option A ("Environmental, Strategy, and Corporate Governance")
Incorrect because Strategy is not part of ESG.
Option C ("Enhanced Social Governance")
Incorrect because ESG covers more than just social governance.
Option D ("Extra Social Governance")
Incorrect as it does not align with the recognized ESG definition.
PRMIA Risk Reference Used:
PRMIA ESG Risk Management Guidelines - Defines ESG factors as Environmental, Social, and Governance.
PRI (Principles for Responsible Investment) - Aligns ESG with financial risk management.
NEW QUESTION # 34
Which of the following principles is critical when creating the optimum policy range and content'?
- A. Policies should be divided into a large number of short topics to enhance accessibility.
- B. Hard copies of a new policy should be placed in a central library of governance documents at the CRO's home.
- C. Policy owners must ensure that policies are read by the regulator and then the shareholders.
- D. New policies should be accompanied by Citable training for the target audience and added to the content of new employee training.
Answer: D
Explanation:
Best Practices for Policy Development
Policies should be clearly written, well-structured, and accompanied by training to ensure employees understand their responsibilities.
PRMIA governance principles emphasize the need for training to enhance compliance and operational effectiveness.
Why Answer D is Correct
Training ensures policy adoption and understanding across the organization.
Integrating policies into new employee training helps embed governance and compliance culture.
Why Other Answers Are Incorrect
Option
Explanation:
A . Policies should be divided into a large number of short topics to enhance accessibility.
Incorrect - While policies should be structured for readability, excessive fragmentation can lead to confusion and inefficiency.
B . Policy owners must ensure that policies are read by the regulator and then the shareholders.
Incorrect - Policies are internal governance tools, not primarily for regulators or shareholders.
C . Hard copies of a new policy should be placed in a central library of governance documents at the CRO's home.
Incorrect - Policies should be centrally available within the organization, not at a personal location.
PRMIA Reference for Verification
PRMIA Governance Best Practices
ISO 31000 Risk Management Standards
NEW QUESTION # 35
Risk Capacity for a bank is defined as the:
- A. Ability to suffer an extreme event with an orderly wind up with only shareholders losing money.
- B. Amount of risk the regulator sets for the bank.
- C. Amount of risk the bank wishes to take.
- D. Ability to withstand an extreme event and make a profit.
Answer: A
Explanation:
Step 1: Definition of Risk Capacity
Risk Capacity refers to the maximum level of risk a bank can absorb while still maintaining orderly operations or, in extreme cases, conducting an orderly resolution.
PRMIA and Basel III define risk capacity as a bank's ability to absorb losses in a crisis without systemic consequences.
Step 2: Why Option D Is Correct
The ultimate test of a bank's risk capacity is whether it can survive an extreme shock without harming depositors or financial markets.
Regulators ensure that a bank can be wound up in an orderly manner so that only shareholders lose money, while depositors and creditors remain protected under resolution planning frameworks.
Step 3: Why the Other Options Are Incorrect
Option A ("Amount of risk the bank wishes to take")
Incorrect because this describes Risk Appetite, not Risk Capacity.
Option B ("Amount of risk the regulator sets for the bank")
Incorrect because regulators set capital requirements, but the bank's actual risk capacity is based on its own capital structure and business model.
Option C ("Ability to withstand an extreme event and make a profit")
Incorrect because risk capacity is about survival, not profit-making during extreme events.
PRMIA Risk Reference Used:
Basel III Risk Capacity Standards - Defines the ability to absorb losses during crises.
PRMIA Risk Governance Framework - Describes how banks should manage risk capacity through capital buffers.
Final Conclusion:
Banks must be able to withstand an extreme event and conduct an orderly wind-up if necessary, ensuring that only shareholders bear the loss, making Option D the correct answer.
NEW QUESTION # 36
ISO 27000 relates to what topic / area?
- A. Information Security Systems.
- B. International Risk Management.
- C. Environmental, social, and governance (ESG) investing.
- D. Auditing of financial controls.
Answer: A
Explanation:
Step 1: Definition of ISO 27000
ISO 27000 is a global standard for information security management systems (ISMS), issued by the International Organization for Standardization (ISO).
It provides a framework for protecting sensitive information through policies, controls, and risk management practices.
Step 2: Why Option B Is Correct
ISO 27001 (part of ISO 27000 series) is one of the most widely recognized certifications for information security governance.
It sets guidelines on risk assessment, incident response, and data protection.
Step 3: Why the Other Options Are Incorrect
Option A ("ESG investing")
Incorrect because ISO 27000 deals with cybersecurity, not environmental, social, and governance (ESG) issues.
Option C ("International Risk Management")
Incorrect because ISO 27000 focuses on information security, not general risk management.
Option D ("Auditing of financial controls")
Incorrect because financial auditing standards (e.g., SOX, COSO) are separate from information security standards.
PRMIA Risk Reference Used:
ISO 27000 Series Documentation - Defines cybersecurity risk management practices.
PRMIA IT Risk Governance Framework - Reference ISO 27001 as a cybersecurity standard.
NEW QUESTION # 37
......
PRMIA 8020 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
PRMIA 8020 Real 2025 Braindumps Mock Exam Dumps: https://torrentpdf.validvce.com/8020-exam-collection.html
