Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free PRMIA ORM Certificate - 2023 Update 8020 Exam Questions

Page: 1 / 6 Total 60 questions

Want more questions? Get Premium Access.

Question 1

Two of the four key resources that are regarded as critical to maintain confidence and calibrate Risk Appetite to are?

Correct Answer: B. Net earnings and capital.
Explanation:

Key Resources for Calibrating Risk Appetite

Risk appetite defines how much risk an organization is willing to accept to achieve its objectives.

Two of the most critical resources for maintaining confidence and setting risk appetite are net earnings and capital.

Why Net Earnings and Capital are Critical

Net earnings reflect profitability and financial stability, influencing risk-taking capacity.

Capital ensures that the institution can absorb losses and meet regulatory requirements.

Basel III emphasizes capital adequacy as a core measure of financial resilience.

Why Answer B is Correct

Net earnings support operational stability, while capital determines how much risk an institution can bear.

Both are used to define and calibrate risk appetite levels.

Why Other Answers Are Incorrect

Option

Explanation

A . Capital expenditure and liquidity.

Incorrect -- Capital expenditure is an investment measure, not a direct risk appetite determinant.

C . Strong regulatory assessment and net earnings.

Incorrect -- Regulatory assessments are important but do not directly set risk appetite.

D . Quality human resources and reputation.

Incorrect -- HR and reputation are important for governance but do not directly influence risk capital and earnings stability.

PRMIA Reference for Verification

PRMIA Risk Appetite Framework

Basel III Capital and Earnings Management Guidelines


Question 2

Which of the follow does the risk function typically have responsibility for?

Correct Answer: B. Documenting its activities, typically by developing a Risk Management Manual and set of Risk Policies.
Explanation:

Role of the Risk Function

The risk function is responsible for documenting, monitoring, and overseeing risk policies and frameworks.

It ensures the organization maintains structured risk governance, reporting, and compliance.

Key Responsibilities

Developing Risk Management Manuals to define risk appetite, risk frameworks, and risk governance structures.

Creating Risk Policies that align with regulatory standards and internal controls.

Why Answer B is Correct

The risk function primarily develops, implements, and maintains risk management frameworks, which include formal manuals and policies.

Why Other Answers Are Incorrect

Option

Explanation

A . Documenting its activities, typically by operating and then recording the daily operation of controls.

Incorrect -- The first line of defense (business units) handles daily operational controls, not the risk function.

C . Putting in place the servers, firewalls, and software to ensure cybersecurity.

Incorrect -- Cybersecurity is an IT responsibility, while the risk function oversees cyber risk frameworks.

D . Creating a trial balance, balance sheet statement, and cash flow statement.

Incorrect -- These are financial accounting responsibilities, not risk management duties.

PRMIA Reference for Verification

PRMIA Governance Framework for Risk Management

Basel Risk Management Principles


Question 3

Governance can be defined as which of the following?

Correct Answer: D. Governance is a structure specifying the policies, principles, and procedures for making decisions about corporate direction.
Explanation:

Definition of Governance

Governance refers to the framework of policies, principles, and processes used to guide corporate decision-making and strategic direction.

It ensures accountability, transparency, and risk oversight within an organization.

Key Elements of Governance

Risk oversight -- Ensuring risks are properly identified and managed.

Accountability structures -- Defining roles and responsibilities.

Decision-making frameworks -- Establishing policies for long-term corporate success.

Why Other Answers Are Incorrect

Option

Explanation

A . Governance is a structure specifying the daily operation of a firm.

Incorrect -- Governance focuses on high-level corporate oversight, not day-to-day operations.

B . Governance is a structure specifying the ways in which reporting is made to the primary regulator.

Incorrect -- Governance is broader than just regulatory reporting.

C . Governance is being replaced by management in all firms that are regulated.

Incorrect -- Governance and management are separate but complementary; governance provides oversight, while management executes strategy.

PRMIA Reference for Verification

PRMIA 10 Principles of Good Governance


Question 4

What are the roles of business versus risk management in developing and implementing risk assessments?

Correct Answer: B. The business owns the risk assessment process, while risk management develops the framework, helps facilitate the process, and provides supervision and oversight.
Explanation:

The Principles for Risk Governance, as established by PRMIA (Professional Risk Managers' International Association), emphasize the Three Lines of Defense (3LoD) Model, which is widely used in risk management and governance frameworks.

Business Line Ownership of Risk (First Line of Defense)

The business units are responsible for identifying, assessing, managing, and monitoring risks within their operations.

Since they generate the risks through their activities, they must own the risk assessment process.

This aligns with PRMIA Governance Principles, which state that risk management should be embedded within business operations to ensure proactive risk identification and control.

Risk Management's Role (Second Line of Defense)

The risk management function is not directly responsible for conducting risk assessments but plays a key role in designing and maintaining the risk assessment framework.

This includes setting standards, methodologies, and tools for assessing risks across business functions.

Risk management provides supervision and oversight, ensuring that risk assessments align with organizational policies and regulatory expectations.

Oversight from Senior Management & the Board (Third Line of Defense)

Internal audit (third line of defense) independently reviews and provides assurance that the risk management framework is effective and that risk assessments are conducted properly.

PRMIA's Risk Governance Standards emphasize that internal audit should evaluate the effectiveness of the risk assessment framework without being involved in its direct execution.

Why Other Answers Are Incorrect

Option

Explanation

A . Risk management, in its role as second line of defense, performs the risk assessment process from beginning to end. There is no business line involvement.

Incorrect -- Risk management facilitates and oversees the risk assessment process, but the business must take ownership of the risks it generates.

C . Business owns the risk assessment process so risk management does not play a role in the process.

Incorrect -- While the business owns the process, risk management plays a crucial role in developing the framework, setting policies, and providing oversight.

D . Business management's role in the risk assessment process should be confined to oversight.

Incorrect -- Business management is actively responsible for executing risk assessments, not just overseeing them.

PRMIA Reference for Verification

PRMIA Standards for Risk Governance -- Establishes the Three Lines of Defense and the separation of responsibilities.

PRMIA Risk Management Framework (RMF) Guidelines -- Defines the roles of business and risk management in risk assessment.

PRMIA Enterprise Risk Management Best Practices -- Outlines how risk management facilitates risk assessments while the business retains ownership.

This answer is verified according to PRMIA's official risk governance documents and best practices. Would you like additional clarification or supporting documentation references?


Question 5

Team supervisors are key in the development and maintenance of the risk culture because they are:

Correct Answer: C. Connected with every employee, every day, and can ensure desired behaviors are followed by all.
Explanation:

Team supervisors play a critical role in shaping and maintaining an organization's risk culture. PRMIA's Risk Governance Framework and Risk Culture Principles emphasize that supervisors act as the link between risk policies and frontline employees, ensuring that risk-aware behaviors are consistently followed.

Step 1: Role of Supervisors in Risk Culture Development

Supervisors engage with employees daily, providing guidance on risk-based decision-making.

They reinforce risk policies, standards, and expectations set by senior management.

Supervisors identify behavioral trends that may indicate risk culture weaknesses.

Step 2: Supervisors as Enforcers of Risk Culture

PRMIA's Risk Culture Framework stresses that risk culture must be embedded into daily operations through supervisor-led enforcement.

Supervisors monitor, correct non-compliant behaviors, and provide ongoing risk awareness training.

Their proximity to employees allows them to detect early warning signs of risk issues.

Step 3: Why the Other Options Are Incorrect

Option A: 'More experienced than the employees that report to them.'

Experience alone does not establish or maintain a risk culture.

A risk culture is about behaviors and practices, not just expertise.

Option B: 'Visible to regulators and can describe the firm's risk culture to inspection teams.'

While supervisors may interact with regulators, their primary role is to engage with employees daily rather than acting as spokespersons.

Option D: 'Visible to regulators and can describe the firm's risk culture to their board.'

Boards typically rely on Chief Risk Officers (CROs) or senior executives to communicate risk culture, not direct supervisors.

PRMIA Risk Reference Used:

PRMIA Risk Culture Framework -- Highlights the role of supervisors in ensuring risk-aware behaviors.

PRMIA Risk Governance Framework -- Stresses that frontline supervisors must enforce risk management policies.

PRMIA Risk Awareness Guidelines -- Reinforces daily interaction as a key factor in maintaining a strong risk culture.

Final Conclusion:

Supervisors directly influence employees' behaviors and ensure that risk culture is consistently followed, making Option C the correct answer.


Question 6

Which of the following is not the purpose or benefit of a Risk Appetite statement?

Correct Answer: C. Establishes the maximum risk that the organization can stand.
Explanation:

Step 1: Understanding a Risk Appetite Statement

Risk Appetite is the amount of risk an organization is willing to take to achieve its objectives.

A Risk Appetite Statement (RAS) communicates risk tolerance levels and management expectations.

Step 2: Why Option C is Incorrect

Risk Capacity (not Risk Appetite) defines the maximum risk the firm can withstand.

Risk Appetite is about willingness to take risk, not the absolute limit.

Step 3: Why the Other Options Are Correct

Option A ('Improves risk management standards') Correct, as RAS helps define better risk management.

Option B ('Governing body articulates expectations') Correct, as RAS is approved by the board.

Option D ('Assists strategic discussions') Correct, as RAS guides decision-making.

PRMIA Risk Reference Used:

PRMIA Risk Appetite Framework -- Differentiates between Risk Appetite and Risk Capacity.

Basel III Governance Principles -- Encourages organizations to establish clear risk appetite statements.

Final Conclusion:

Risk Appetite does not establish the maximum risk the firm can withstand---that is Risk Capacity, making Option C the correct answer.


Question 7

Risk Sensitive pricing is required for several good reasons. Which one of the following is not relevant to the Management's evaluation of the correct approach to Risk Sensitive pricing?

Correct Answer: D. To ensure the income targets can be met or exceeded.
Explanation:

Risk-sensitive pricing ensures that financial institutions and businesses properly account for risk in their pricing strategies to maintain stability and sustainability. PRMIA's Risk Pricing and Capital Adequacy Guidelines define the importance of risk-sensitive pricing in ensuring fair compensation for risk exposure and avoiding risk concentration issues.

Step 1: Why Risk-Sensitive Pricing Is Important

Aligns risk with return: Pricing should be designed to reflect the underlying risk and return trade-off.

Protects investors: Investors expect compensation for capital at risk (Option A is correct).

Reinforces risk-aware culture: PRMIA promotes linking incentives to risk-adjusted returns (Option B is correct).

Prevents adverse selection: Proper risk pricing prevents low-quality assets from accumulating (Option C is correct).

Step 2: Why Option D Is Incorrect

Income targets are business-driven, not risk-driven.

Risk-sensitive pricing aims to balance risk and reward, not just maximize revenue.

PRMIA discourages profit-seeking behavior at the expense of risk considerations.

PRMIA Risk Reference Used:

PRMIA Risk Pricing Guidelines -- Defines the principles of risk-sensitive pricing.

PRMIA Risk-Adjusted Return Standards -- Stresses linking incentives to risk-aware decisions.

PRMIA Capital Adequacy Framework -- Highlights the role of risk-sensitive pricing in portfolio management.

Final Conclusion:

Risk-sensitive pricing is designed to align returns with risk exposure, not simply to meet or exceed income targets, making Option D the correct answer.


Question 8

Which of the follow is not included in PRMIA's 10 principles of good governance?

Correct Answer: B. Holding the PRM Designation.
Explanation:

PRMIA's 10 Principles of Good Governance

PRMIA outlines 10 key principles that focus on risk governance, accountability, transparency, and risk management effectiveness.

These principles ensure strong risk governance structures for financial institutions.

Why Answer B is Correct

Holding the PRM Designation (Professional Risk Manager certification) is NOT a governance principle.

While PRMIA promotes risk education, governance principles focus on organizational risk structures, not individual certifications.

Why Other Answers Are Incorrect

Option

Explanation

A . Risk appetite.

Correct -- PRMIA governance principles include establishing a clear risk appetite.

C . External validation.

Correct -- External audits and validation improve governance and risk transparency.

D . Clear accountability.

Correct -- Governance principles emphasize clear accountability at all levels of management.

PRMIA Reference for Verification

PRMIA 10 Principles of Good Governance

Basel Corporate Governance Guidelines for Financial Institutions


Question 9

When a control is found to be ineffective, which of the following steps should be take next?

Correct Answer: B. An action plan should be designed to close the gap.
Explanation:

When a control is found to be ineffective, the primary objective is to remediate the deficiency by implementing corrective measures. PRMIA (Professional Risk Managers' International Association) guidance, aligned with best practices in risk governance, emphasizes a structured approach to handling control deficiencies. Below is a detailed breakdown based on PRMIA risk management principles:

Step 1: Identify and Assess the Ineffective Control

A control is deemed ineffective when it fails to mitigate the identified risks to an acceptable level.

The root cause of the failure must be determined through a Control Effectiveness Review (CER).

PRMIA recommends control testing and incident analysis to assess the severity of the control failure.

Step 2: Develop an Action Plan to Address the Control Deficiency

PRMIA best practices state that risk management should prioritize corrective actions rather than delaying remediation.

The organization must define an action plan to close the gap, which includes:

Revising or strengthening the control mechanisms.

Implementing new controls, if necessary.

Assigning responsibility for remediation to control owners.

Setting deadlines for resolution.

This step aligns with PRMIA's Risk Governance Framework, which emphasizes proactive risk management.

Step 3: Implement Corrective Measures and Monitor Progress

Once an action plan is designed, the organization should execute the corrective actions.

PRMIA's Risk Monitoring Guidelines require regular follow-ups and testing to ensure the control is functioning correctly.

The effectiveness of the remediation should be validated through post-implementation review and ongoing control testing.

Step 4: Re-Assess Risks and Control Effectiveness

Once corrective measures are in place, the organization should re-evaluate risks to confirm that the issue is resolved.

The risk assessment process should be updated to reflect the changes in the control environment.

Why the Other Options Are Incorrect?

Option A: 'Risks should be re-assessed to determine if there is the appropriate level of control assessment.'

While risk re-assessment is a good practice, it does not directly address the ineffective control.

PRMIA guidelines prioritize closing the control gap first before reassessing risks.

Option C: 'The controls should be re-assessed during the next cycle to determine if they are still ineffective.'

Waiting until the next assessment cycle delays remediation, which could expose the organization to unmitigated risks.

PRMIA risk frameworks recommend immediate corrective action when a control is found to be ineffective.

Option D: 'Risks should be re-assessed to determine if there can be an exception for the level of control assessment.'

PRMIA does not support exceptions for ineffective controls unless there is a well-documented risk acceptance process.

A control failure should be remediated rather than seeking exceptions.

PRMIA Risk Reference Used:

PRMIA Risk Governance Framework -- Defines the importance of immediate corrective actions for control failures.

PRMIA Risk Monitoring Guidelines -- Stresses continuous monitoring and validation of controls.

PRMIA Risk Management Standards -- Recommends a structured action plan for ineffective controls.

PRMIA Operational Risk Framework -- Emphasizes the need to close control gaps to maintain a strong risk posture.

Final Conclusion:

According to PRMIA risk management best practices, when a control is found to be ineffective, the best course of action is to design and implement an action plan to remediate the issue (Option B). This approach ensures that the organization mitigates risk promptly and maintains a strong control environment.


Question 10

In operational resilience, what is impact tolerance?

Correct Answer: B. Impact tolerance is a firm's tolerance for disruption to a particular business service.
Explanation:

Impact Tolerance is a key concept in Operational Resilience, defined as the ability of a firm to withstand, respond to, and recover from disruptions. According to PRMIA and global regulatory frameworks (such as the Bank of England's Operational Resilience Framework), impact tolerance is specifically tied to business services rather than processes.

Step 1: Defining Impact Tolerance

Impact tolerance is the maximum acceptable level of disruption to an important business service, beyond which there would be intolerable harm to customers, financial markets, or regulatory obligations.

It is not the same as risk appetite or risk capacity, as those deal with broader organizational risk exposure.

Step 2: Why Business Services Matter

PRMIA defines business services as end-to-end services delivered to clients and stakeholders, such as payments processing, trade execution, or loan approvals.

Disruptions to these services directly impact customers and financial stability, making business service resilience the core focus of impact tolerance.

Step 3: Why the Other Options Are Incorrect

Option A ('tolerance for disruption to a particular business process')

Incorrect because impact tolerance applies to services, not just internal processes.

Option C ('a firm's risk appetite statement')

Incorrect because risk appetite focuses on how much risk a firm is willing to take, while impact tolerance is about surviving disruptions.

Option D ('a firm's risk capacity statement')

Incorrect because risk capacity is the maximum level of risk a firm can bear, which is broader than business service disruptions.

PRMIA Risk Reference Used:

PRMIA Operational Resilience Guidelines -- Defines impact tolerance as a service-based metric.

Bank of England's Operational Resilience Framework -- Establishes impact tolerance as a limit on business service disruption.

Final Conclusion:

Impact tolerance focuses on business services, not just internal processes or risk appetite, making Option B the correct answer.