Jul 17, 2025 Newest 8020 Exam Dumps – Achieve Success in Actual 8020 Exam [Q13-Q37]

Share

Jul 17, 2025 Newest 8020 Exam Dumps – Achieve Success in Actual 8020 Exam

Updated PRMIA 8020 Dumps – Check Free 8020 Exam Dumps (2025)


PRMIA 8020 Exam Syllabus Topics:

TopicDetails
Topic 1
  • Risk Modeling: This section of the exam measures the skills of Quantitative Risk Analysts and covers mathematical and statistical techniques used to predict risk scenarios. It explores model development, validation, and application in financial and operational risk management. A key skill measured is applying statistical models for risk prediction.
Topic 2
  • Risk Management Framework: This section of the exam measures the skills of Risk Managers and covers the development and implementation of structured approaches for risk identification, evaluation, and mitigation. It includes industry-standard frameworks that guide risk strategy and decision-making. A key skill measured is establishing a risk management framework for organizations.
Topic 3
  • Risk Information: This section of the exam measures the skills of Risk Managers and covers the collection, analysis, and communication of risk-related data. It highlights the role of data-driven decision-making in mitigating uncertainties and ensuring compliance. A key skill measured is interpreting risk data for informed decision-making.
Topic 4
  • Insurance Mitigation: This section of the exam measures the skills of Insurance Risk Managers and covers strategies for transferring risk through insurance and other financial instruments. It focuses on risk transfer mechanisms, policy structuring, and claims management. A key skill measured is assessing risk transfer options through insurance.
Topic 5
  • Risk Governance: This section of the exam measures the skills of Compliance Officers and covers the policies, structures, and processes that define how organizations oversee risk. It explores regulatory compliance, ethical considerations, and corporate governance frameworks to ensure accountability. A key skill measured is applying governance frameworks to organizational risk policies.
Topic 6
  • Introduction: This section of the exam measures the skills of Risk Analysts and covers fundamental concepts of risk governance, management, and assessment. It introduces key principles, regulatory frameworks, and industry best practices for identifying and addressing risks. A key skill measured is understanding the foundational principles of risk management.
Topic 7
  • Case Studies: This section of the exam measures the skills of Business Risk Consultants and covers real-world applications of risk management concepts. It examines case studies on risk governance, assessment, and mitigation strategies across different industries. A key skill measured is analyzing historical risk events for strategic insights.

 

NEW QUESTION # 13
The DORA act's full name is which of the following?

  • A. Domain for Operational Risk Act.
  • B. Digital Operational Risk Act.
  • C. Digital Operational Resilience Act.
  • D. Daily Operational Resilience Act.

Answer: C

Explanation:
Definition of DORA
The Digital Operational Resilience Act (DORA) is a regulation by the European Union (EU) aimed at strengthening the digital resilience of financial institutions.
It establishes a regulatory framework for managing information and communication technology (ICT) risks in the financial sector.
Key Objectives of DORA
Ensures that financial institutions can withstand, respond to, and recover from cyber threats and ICT-related disruptions.
Introduces standards for risk management, incident reporting, and third-party ICT risk oversight.
Why Other Answers Are Incorrect
Option
Explanation:
A . Domain for Operational Risk Act.
Incorrect - No such regulation exists under this name.
B . Digital Operational Risk Act.
Incorrect - The official name is Digital Operational Resilience Act (DORA).
C . Daily Operational Resilience Act.
Incorrect - DORA is not focused on daily operations but rather long-term digital resilience.
PRMIA Reference for Verification
PRMIA Risk Governance & Digital Resilience Standards
European Commission's Official DORA Regulation


NEW QUESTION # 14
In relation to financial crime. OFAC is a definition for which organization?

  • A. Office of Financial Asset Control.
  • B. Office of Foreigner and other Control.
  • C. Office for Asset Control.
  • D. Office of Foreign Asset Control.

Answer: D

Explanation:
Step 1: Understanding OFAC
OFAC (Office of Foreign Assets Control) is a U.S. Treasury Department agency responsible for enforcing economic and trade sanctions based on U.S. foreign policy and national security goals.
It prevents financial crime by restricting transactions with sanctioned individuals, entities, and countries.
Step 2: Role of OFAC in Financial Crime Prevention
OFAC administers sanctions to prevent money laundering, terrorism financing, and other illicit activities.
Financial institutions must comply with OFAC regulations to avoid heavy fines and reputational damage.
PRMIA's Financial Crime Risk Guidelines emphasize the importance of OFAC compliance in risk management.
Step 3: Why the Other Options Are Incorrect
Option A ("Office of Financial Asset Control") - Incorrect wording; OFAC deals with foreign assets, not just financial assets.
Option B ("Office of Foreigner and Other Control") - OFAC does not regulate foreigners broadly; it targets specific foreign assets and transactions.
Option C ("Office for Asset Control") - Missing "Foreign", which is critical to OFAC's function.
PRMIA Risk Reference Used:
PRMIA Financial Crime Risk Management Guidelines - Emphasizes regulatory compliance with OFAC.
PRMIA Compliance and Sanctions Risk Standards - Stresses the role of OFAC in preventing illicit financial activities.
Final Conclusion:
OFAC stands for the Office of Foreign Assets Control, making Option D the correct answer.


NEW QUESTION # 15
In Operational Resilience, which of the following is not an important measure of whether a Business Service can be considered Critical?

  • A. Whether a disruption to the provision of the service could cause material customer detriment.
  • B. Whether a disruption to the provision of the service could harm market integrity.
  • C. Whether a disruption to the provision of the service could threaten a firm's viability.
  • D. Whether a disruption to the provision of the service could exceed risk appetite.

Answer: D

Explanation:
Step 1: Definition of a Critical Business Service in Operational Resilience A Critical Business Service is one whose failure could result in severe harm to customers, financial markets, or the firm's viability.
Regulators (e.g., Bank of England, Basel Committee, PRMIA) define three primary factors for identifying critical services:
Customer impact
Market integrity impact
Firm viability impact
Step 2: Why Option C Is Incorrect
Risk appetite is an internal business decision, not an external measure of criticality.
A service can be critical even if its disruption stays within risk appetite.
Criticality is based on external impacts, not just internal risk limits.
Step 3: Why the Other Options Are Correct
Option A ("Material customer detriment") → Correct as customer harm defines critical services.
Option B ("Harm to market integrity") → Correct as market stability is a regulatory priority.
Option D ("Threaten firm viability") → Correct as critical services often determine business survival.
PRMIA Risk Reference Used:
PRMIA Operational Resilience Framework - Defines criteria for critical business services.
Basel Committee Operational Risk Guidelines - Highlights customer, market, and firm viability as resilience factors.
Final Conclusion:
Risk appetite is an internal benchmark, not a measure of critical service designation, making Option C the correct answer.


NEW QUESTION # 16
Confidence Accounting can be defined as:

  • A. An approach that encourages companies and audit firms to have diverse boards.
  • B. An approach that encourages companies and audit firms to use regular statements in their Al software.
  • C. An approach that encourages companies and audit firms to stop using figures and maths.
  • D. An approach that encourages companies and audit firms to use ranges, rather than discrete numbers, for major accounting entries.

Answer: D

Explanation:
Definition of Confidence Accounting
Confidence Accounting challenges traditional accounting by introducing probability distributions and ranges rather than fixed numbers for financial reporting.
This approach improves transparency and risk awareness by acknowledging uncertainty in financial figures.
Why Answer B is Correct
Encourages using ranges (confidence intervals) instead of discrete values to better reflect uncertainty.
Used in risk-sensitive industries where financial estimates vary due to external factors (e.g., credit risk, market fluctuations).
Why Other Answers Are Incorrect
Option
Explanation:
A . An approach that encourages companies and audit firms to have diverse boards.
Incorrect - Board diversity is unrelated to Confidence Accounting.
C . An approach that encourages companies and audit firms to use regular statements in their AI software.
Incorrect - AI may use probability models, but Confidence Accounting is an accounting methodology, not an AI approach.
D . An approach that encourages companies and audit firms to stop using figures and maths.
Incorrect - Confidence Accounting still relies on mathematical models; it does not eliminate numerical analysis.
PRMIA Reference for Verification
PRMIA Financial Risk Reporting Standards
IFRS (International Financial Reporting Standards) Guidelines on Probability-Based Accounting


NEW QUESTION # 17
For the National Australia Bank - FX Options case study, large and unusual transaction activity was a concern for what reason?

  • A. Deep-in-the-money options and other complex structured transactions aided in the smoothing of losses.
  • B. Deep-in-the-money options aided in the smoothing of losses.
  • C. Complex structured transactions aided in the smoothing of losses.
  • D. Deep-in-the-money options and other complex structured transactions aided in the smoothing of profits and losses.

Answer: D

Explanation:
The National Australia Bank (NAB) FX Options Case Study is a well-known example of operational risk, fraud, and governance failure.
What Happened?
Traders engaged in unauthorized foreign exchange (FX) options trading, using deep-in-the-money options and other complex instruments.
They manipulated profits and losses to smooth earnings and mislead risk managers and auditors.
Why Answer C is Correct
The traders smoothed both profits and losses to avoid detection and ensure continued trading bonuses.
This aligns with PRMIA's Operational Risk Management Guidelines, which highlight that hidden trading losses and smoothing techniques increase financial crime risk.
Why Other Answers Are Incorrect
Option
Explanation:
A . Complex structured transactions aided in the smoothing of losses.
Incorrect - Smoothing occurred with both profits and losses, not just losses.
B . Deep-in-the-money options and other complex structured transactions aided in the smoothing of losses.
Incorrect - Profits were also manipulated, making this answer incomplete.
D . Deep-in-the-money options aided in the smoothing of losses.
Incorrect - This focuses only on deep-in-the-money options and ignores other structured transactions involved in the fraud.
PRMIA Reference for Verification
PRMIA Fraud and Risk Management Case Studies
Basel Principles on Market Risk and Internal Control Failures


NEW QUESTION # 18
How can a chief risk officer encourage the governing body and executive management team to create a stronger risk culture?

  • A. Discourage personal accountability to avoid a blame culture.
  • B. Establish a set of objectives that the board and executive team must adhere to.
  • C. Having a vision of achievable but not excessive ambition.
  • D. Balance rewarding success in profitability goals with punishment when there is a failure to achieve goals.

Answer: C

Explanation:
A Chief Risk Officer (CRO) plays a crucial role in shaping and strengthening the risk culture within an organization. PRMIA defines risk culture as the shared values, beliefs, knowledge, and understanding about risk that drive behaviors within an institution.
Setting a Clear Vision
The CRO should communicate a vision of risk management that aligns with organizational goals while ensuring that risk-taking remains within acceptable limits.
The vision should be achievable and realistic, rather than overly ambitious, which could incentivize reckless risk-taking.
Embedding Risk Awareness into Decision-Making
A strong risk culture ensures that risk considerations are embedded into business decision-making rather than treated as a separate compliance exercise.
This is supported by PRMIA's Enterprise Risk Management (ERM) Framework, which stresses integrating risk management into strategy and operations.
Avoiding a Blame Culture
A risk-aware organization promotes accountability without fear, enabling employees to report risks without retribution.
Option B (Discourage personal accountability to avoid a blame culture) is incorrect because personal accountability is essential for a healthy risk culture.
Avoiding a Strict, Prescriptive Approach
A set of rigid objectives that must be followed by the executive team (Option C) does not foster a dynamic, evolving risk culture.
Instead, risk culture should be flexible and adaptive to emerging risks.
Balancing Incentives and Consequences
While balancing rewards with penalties (Option D) is part of governance, a strong risk culture is not built solely through fear of punishment.
PRMIA emphasizes positive reinforcement, such as linking risk management behaviors to performance evaluations and incentives.
PRMIA Reference for Verification
PRMIA Risk Governance Framework - Discusses the role of leadership in shaping risk culture.
PRMIA Standards on Enterprise Risk Management (ERM) - Covers best practices for embedding risk culture within organizations.


NEW QUESTION # 19
What are some of the deficiencies associated with bottom-up Key Risk Indicators?

  • A. Lack of granularity.
  • B. Not reported frequently enough.
  • C. Causal affects that are not adequately understood.
  • D. Mandates from a board that are too restrictive to implement.

Answer: C

Explanation:
Definition of Bottom-Up Key Risk Indicators (KRIs)
Bottom-up KRIs are generated from operational-level data rather than high-level strategic indicators.
They are useful for monitoring localized risks but may fail to capture broad risk drivers.
Key Deficiencies of Bottom-Up KRIs
Lack of clarity on causal relationships - These indicators may detect risk trends but fail to explain root causes.
Focus on micro-level risks - They may miss systemic or enterprise-wide risk interactions.
Why Answer B is Correct
Bottom-up KRIs may indicate changes in risk levels but lack insight into the underlying causes, leading to reactive rather than proactive risk management.
Why Other Answers Are Incorrect
Option
Explanation:
A . Mandates from a board that are too restrictive to implement.
Incorrect - Board mandates apply to top-down governance, not bottom-up KRIs.
C . Not reported frequently enough.
Incorrect - Reporting frequency is an issue but not the primary deficiency; rather, it's the lack of causal insight.
D . Lack of granularity.
Incorrect - Bottom-up KRIs tend to be highly detailed (granular), making this answer incorrect.
PRMIA Reference for Verification
PRMIA Key Risk Indicator Best Practices
Basel Committee's Risk Measurement and Reporting Framework


NEW QUESTION # 20
For the Northern Rock case study, what was the low-probability-high-impact event that was most responsible for the loss event?

  • A. The Bank of England's withdrawal of Deposit Protection.
  • B. The acquisition of Merrill Lynch by Bank of America.
  • C. An exposure to real estate funds, heavily concentrated in Berlin.
  • D. Liquidity dried up in the inter-bank and commercial paper markets.

Answer: D

Explanation:
Step 1: Understanding the Northern Rock Case Study
Northern Rock was a UK bank that collapsed in 2007 due to its heavy reliance on short-term wholesale funding rather than customer deposits.
When the 2007 financial crisis hit, the inter-bank lending market and commercial paper market froze, cutting off Northern Rock's access to liquidity.
Step 2: Why Option C Is Correct
Northern Rock depended on short-term borrowing to fund long-term mortgage lending.
When the liquidity crisis hit, it couldn't refinance its debt, leading to a bank run and collapse.
The Bank of England had to intervene, and the UK government nationalized Northern Rock in 2008.
Step 3: Why the Other Options Are Incorrect
Option A ("Acquisition of Merrill Lynch") → Incorrect because this happened in 2008, after Northern Rock's failure.
Option B ("Withdrawal of Deposit Protection") → Incorrect because UK deposit protection remained in place.
Option D ("Real estate exposure in Berlin") → Incorrect because Northern Rock's problem was funding liquidity, not real estate losses.
PRMIA Risk Reference Used:
PRMIA Liquidity Risk Management Framework - Describes how liquidity shocks impact banks like Northern Rock.
Basel III Liquidity Coverage Ratio (LCR) Standards - Created after Northern Rock to prevent similar liquidity crises.
Final Conclusion:
The collapse of the inter-bank and commercial paper markets was the key low-probability-high-impact event that led to Northern Rock's failure, making Option C the correct answer.


NEW QUESTION # 21
What are some of the properties of Bottom-Up KRIs?

  • A. Selected by local management: tied to internal loss events at the legal entity, country, business and / or product level, reported daily, weekly or monthly.
  • B. Are not used due to changes in regulations.
  • C. Selected by local management, based on key controls or weaknesses identified by audit reports, reported on quarterly.
  • D. Seated by senior management: tied to internal loss events at the legal entity, country, business and / or product level, reported.
    daily, weekly or monthly.

Answer: A

Explanation:
Definition of Bottom-Up KRIs
Bottom-Up Key Risk Indicators (KRIs) are identified at the operational level, focusing on localized risks within business units.
They are tied to actual internal loss events and reported frequently (daily, weekly, or monthly) to capture ongoing trends.
Key Properties of Bottom-Up KRIs
Selected by local management → Ensures relevance to specific business areas.
Tied to internal loss events → Helps in tracking risk patterns within specific legal entities, countries, or business units.
Reported frequently → Allows for timely risk detection and mitigation.
Why Answer D is Correct
Bottom-up KRIs focus on localized risk exposure and are monitored frequently to track operational changes.
Why Other Answers Are Incorrect
Option
Explanation:
A . Seated by senior management: tied to internal loss events at the legal entity, country, business, and/or product level, reported daily, weekly, or monthly.
Incorrect - Senior management sets top-down KRIs, while bottom-up KRIs are managed locally.
B . Selected by local management, based on key controls or weaknesses identified by audit reports, reported quarterly.
Incorrect - While audit reports are useful, bottom-up KRIs are based on loss events, not just audit findings. Quarterly reporting is too infrequent.
C . Are not used due to changes in regulations.
Incorrect - Bottom-up KRIs remain essential despite regulatory changes.
PRMIA Reference for Verification
PRMIA Risk Indicator Best Practices
Basel Committee's Risk Measurement and Reporting Guidelines


NEW QUESTION # 22
Which of the follow is not included in PRMIA's 10 principles of good governance?

  • A. Holding the PRM Designation.
  • B. External validation.
  • C. Risk appetite.
  • D. Clear accountability.

Answer: A

Explanation:
PRMIA's 10 Principles of Good Governance
PRMIA outlines 10 key principles that focus on risk governance, accountability, transparency, and risk management effectiveness.
These principles ensure strong risk governance structures for financial institutions.
Why Answer B is Correct
Holding the PRM Designation (Professional Risk Manager certification) is NOT a governance principle.
While PRMIA promotes risk education, governance principles focus on organizational risk structures, not individual certifications.
Why Other Answers Are Incorrect
Option
Explanation:
A . Risk appetite.
Correct - PRMIA governance principles include establishing a clear risk appetite.
C . External validation.
Correct - External audits and validation improve governance and risk transparency.
D . Clear accountability.
Correct - Governance principles emphasize clear accountability at all levels of management.
PRMIA Reference for Verification
PRMIA 10 Principles of Good Governance
Basel Corporate Governance Guidelines for Financial Institutions


NEW QUESTION # 23
For the FTX case study, what was the "backdoor" used for?

  • A. It allowed currency traders to smooth profits and conceal losses for over two years.
  • B. It allowed a stable coin to be removed from the ledger and added to the balance sheet.
  • C. It allowed trading firm Alameda to borrow S65 billion of clients' money from the exchange without their permission.
  • D. It allowed a rapid pace of acquisitions but poor integration of acquired companies.

Answer: C

Explanation:
The FTX collapse involved fraudulent fund mismanagement, where FTX executives created a "backdoor" to allow Alameda Research (FTX's sister trading firm) to borrow client funds without their consent.
Step 1: The "Backdoor" in FTX
The backdoor was a hidden code in FTX's system, allegedly created by Sam Bankman-Fried, which allowed Alameda to access customer deposits without triggering alerts to auditors or compliance teams.
Alameda used these funds for risky trading strategies and investments, leading to the eventual collapse of FTX when a liquidity crunch exposed the missing funds.
Step 2: Why the Other Options Are Incorrect
Option A ("allowed a stablecoin to be removed from the ledger and added to the balance sheet") Incorrect because FTX's fraud involved misuse of customer funds, not just a stablecoin misclassification.
Option C ("allowed currency traders to smooth profits and conceal losses for over two years") Incorrect because this sounds more like LIBOR-rigging scandals, whereas FTX misappropriated client funds.
Option D ("allowed a rapid pace of acquisitions but poor integration of acquired companies") Incorrect because FTX's collapse was due to financial fraud, not poor acquisition strategy.
PRMIA Risk Reference Used:
PRMIA Financial Crime Risk Management - Discusses insider risk and fraudulent misappropriation of funds.
FTX Collapse Reports - SEC, CFTC, and DOJ filings confirm that Alameda had unauthorized access to client funds.
Final Conclusion:
FTX's backdoor enabled Alameda to take $65 billion in client funds without permission, making Option B the correct answer.


NEW QUESTION # 24
Which of the Basel Accords, published in 2004, introduced operational risk as a risk subjected to a capital charge?

  • A. Basel II
  • B. Basel I
  • C. Basel IV
  • D. Basel III

Answer: A

Explanation:
Introduction of Operational Risk in Basel Accords
Basel I (1988) → Focused only on credit risk and market risk; operational risk was not yet included.
Basel II (2004) → Introduced operational risk as a separate category, subject to capital requirements.
Basel III (2010) → Strengthened capital and liquidity requirements but did not introduce operational risk.
Basel IV (2017, still evolving) → Adjusts Basel III reforms but does not introduce operational risk as a new category.
Why Answer B is Correct
Basel II (2004) was the first to introduce operational risk as a risk requiring a capital charge.
Why Other Answers Are Incorrect
Option
Explanation:
A . Basel I
Incorrect - Basel I focused on credit risk and market risk, with no capital requirements for operational risk.
C . Basel III
Incorrect - Basel III strengthened Basel II but did not introduce operational risk.
D . Basel IV
Incorrect - Basel IV refines Basel III but does not introduce operational risk as a new capital charge.
PRMIA Reference for Verification
Basel II (2004) Operational Risk Framework
PRMIA Operational Risk Management Guidelines


NEW QUESTION # 25
For which of the following reasons did the Turnbull Report have a significant impact on risk governance?

  • A. It was the first report to require a board to take specific account of risks and control systems for risks.
  • B. It was the first report to list the board as a proposed governance structure.
  • C. It defined the concept of risk governance for the insurance industry.
  • D. It was a report that led to the establishment of the US Federal Reserve.

Answer: A

Explanation:
Step 1: What Is the Turnbull Report?
The Turnbull Report (1999) was a UK corporate governance report that set risk management expectations for boards.
It required companies to assess and manage risks effectively as part of corporate governance.
Step 2: Why Option C is Correct
Turnbull was the first report to mandate that boards must consider risk management in corporate governance.
This report established risk assessment as a board-level responsibility.
Step 3: Why the Other Options Are Incorrect
Option A ("Defined risk governance for insurance") → Incorrect because Turnbull applied to all sectors, not just insurance.
Option B ("First report to propose board structure") → Incorrect because corporate boards existed long before Turnbull.
Option D ("Led to the US Federal Reserve") → Incorrect because the Federal Reserve was established in 1913, long before Turnbull.
PRMIA Risk Reference Used:
PRMIA Corporate Governance Guidelines - Highlights Turnbull's role in board-level risk oversight.
UK Corporate Governance Code - Turnbull contributed to defining board risk responsibilities.
Final Conclusion:
The Turnbull Report was the first to require boards to consider risks in corporate governance, making Option C the correct answer.


NEW QUESTION # 26
The The Task Force on Climate-related Financial Disclosures (TCFD) was founded by which body?

  • A. The Financial Stability Board (FSB).
  • B. The European Commission (EC).
  • C. The World Bank (WB).
  • D. The United Nations (UN).

Answer: A

Explanation:
Step 1: What is the TCFD?
The Task Force on Climate-related Financial Disclosures (TCFD) was established to develop climate-related financial risk disclosure recommendations to help investors, lenders, and regulators make informed decisions.
Step 2: Who Founded the TCFD?
The Financial Stability Board (FSB), an international organization that monitors and makes recommendations about the global financial system, founded the TCFD in 2015.
The FSB recognized climate risk as a financial stability issue and launched the TCFD to standardize reporting.
Step 3: Why the Other Options Are Incorrect
Option A ("World Bank") → Incorrect because the World Bank supports climate initiatives but did not create the TCFD.
Option B ("United Nations") → Incorrect because the UN has climate programs like the UNFCCC, but not the TCFD.
Option D ("European Commission") → Incorrect because the EC develops its own sustainability regulations (e.g., SFDR, CSRD), separate from the TCFD.
PRMIA Risk Reference Used:
PRMIA Climate Risk Guidelines - Cites FSB's role in founding the TCFD.
FSB Official Reports (2015) - Confirms that the FSB established the TCFD.
Final Conclusion:
The FSB founded the TCFD in 2015, making Option C the correct answer.


NEW QUESTION # 27
Which of the following statements best defines the properties of top-down key risk indicators?

  • A. Selected by senior management, tied to material external and internal loss exposures and scenarios, and used to manage changes in the business environment, especially under periods of stress.
  • B. Can only be selected by the board in line with risk ratings.
  • C. Selected by senior management, used to manage changes in the business environment especially under periods of stress, and reported on a daily basis.
  • D. Selected by junior management, used to manage changes in the business environment especially under periods of stress, and reported on an annual basis

Answer: A

Explanation:
Definition of Key Risk Indicators (KRIs)
KRIs are quantitative metrics used to monitor risk levels and detect early warning signs of potential risk events.
Top-down KRIs are identified at the senior management level and focus on enterprise-wide risk exposure.
Key Properties of Top-Down KRIs
Selected by senior management to ensure alignment with strategic objectives.
Tied to material external and internal loss exposures to capture critical financial, operational, and strategic risks.
Used to manage changes in the business environment to ensure proactive risk response, especially under stress conditions.
Why Other Answers Are Incorrect
Option
Explanation:
B . Selected by senior management, used to manage changes in the business environment, especially under periods of stress, and reported on a daily basis.
Incorrect - Top-down KRIs are not reported daily; they are monitored periodically (e.g., quarterly).
C . Selected by junior management, used to manage changes in the business environment, especially under periods of stress, and reported on an annual basis.
Incorrect - Junior management does not define top-down KRIs; senior management does. Also, annual reporting is too infrequent.
D . Can only be selected by the board in line with risk ratings.
Incorrect - The board provides oversight, but senior risk management selects KRIs, not just the board.
PRMIA Reference for Verification
PRMIA Risk Indicator Guidelines
Basel Committee on Banking Supervision (BCBS) Principles for Effective Risk Data Aggregation


NEW QUESTION # 28
How should Near Misses and Opportunity Costs be treated within Operational Risk?

  • A. Recorded and Analyzed. Used in calculation of Operational Risk Capital.
  • B. Ignored.
  • C. Reported, Recorded and Analyzed, Used in calculation of Operational Risk Capital.
  • D. Reported. Recorded and Analyzed. Not Used in calculation of Operational Risk Capital.

Answer: D

Explanation:
Near Misses in Operational Risk
A near miss is an event that could have led to a loss but was avoided or mitigated before actual financial impact occurred.
PRMIA emphasizes that near misses should be reported, recorded, and analyzed because they provide valuable insights into potential vulnerabilities in risk controls.
However, since they did not result in actual financial losses, they are not included in the calculation of Operational Risk Capital.
Opportunity Costs in Operational Risk
Opportunity costs refer to the loss of potential gains due to missed strategic opportunities.
These are not directly quantifiable as operational risk losses and are not included in Operational Risk Capital calculations.
PRMIA's Operational Risk Framework states that operational risk is about actual losses rather than theoretical costs.
Why Other Answers Are Incorrect
Option
Explanation:
A . Ignored.
Incorrect - Near misses and opportunity costs provide valuable insights into operational risk, so they should never be ignored.
B . Recorded and Analyzed. Used in calculation of Operational Risk Capital.
Incorrect - While they should be recorded and analyzed, they are not included in Operational Risk Capital calculations because they do not result in actual losses.
D . Reported, Recorded, and Analyzed, Used in calculation of Operational Risk Capital.
Incorrect - Reporting, recording, and analysis are correct, but they should not be included in capital calculations.
PRMIA Reference for Verification
PRMIA Operational Risk Management Standards - Defines near misses and opportunity costs.
Basel II & III Operational Risk Framework - Outlines the principles of operational risk capital calculations.


NEW QUESTION # 29
What are the objectives of conducting an internal loss investigation?

  • A. Increase understanding of root causes, focus attention on remediation, and ascertain responsibility for the loss event.
  • B. This is determined on a case by case basis by the HR team.
  • C. Increase understanding of root causes, focus attention on who caused the issue, and improve the quality of scenario analysis and risk assessments.
  • D. Increase understanding of root causes, focus attention on remediation, and improve the quality of scenario analysis and risk assessments.

Answer: D

Explanation:
tep 1: Purpose of Internal Loss Investigations
Internal loss investigations analyze past loss events to identify root causes, improve controls, and enhance risk assessments.
Step 2: Why Option A Is Correct
Root Cause Analysis: Identifying why the loss occurred.
Focus on Remediation: Implementing corrective measures to prevent recurrence.
Scenario Analysis Improvement: Using lessons learned to enhance risk scenario modeling.
Step 3: Why the Other Options Are Incorrect
Option B ("Focus on who caused the issue") → Incorrect because loss investigations are about systemic issues, not assigning blame.
Option C ("Ascertain responsibility for the loss event") → Incorrect because the focus is on process improvements, not individual accountability.
Option D ("Determined by HR on a case-by-case basis") → Incorrect because HR does not dictate risk investigations-risk and compliance functions do.
PRMIA Risk Reference Used:
PRMIA Operational Risk Framework - Emphasizes loss investigations for systemic risk management.
Basel III Risk Governance Standards - Defines loss event analysis as a key risk management tool.


NEW QUESTION # 30
When a control is found to be ineffective, which of the following steps should be take next?

  • A. The controls should be re-assessed during the next cycle to determine if they are still ineffective.
  • B. Risks should be re-assessed to determine if there can be an exception for the level of control assessment.
  • C. Risks should be re-assessed to determine if there is the appropriate level of control assessment.
  • D. An action plan should be designed to close the gap.

Answer: D

Explanation:
When a control is found to be ineffective, the primary objective is to remediate the deficiency by implementing corrective measures. PRMIA (Professional Risk Managers' International Association) guidance, aligned with best practices in risk governance, emphasizes a structured approach to handling control deficiencies. Below is a detailed breakdown based on PRMIA risk management principles:
Step 1: Identify and Assess the Ineffective Control
A control is deemed ineffective when it fails to mitigate the identified risks to an acceptable level.
The root cause of the failure must be determined through a Control Effectiveness Review (CER).
PRMIA recommends control testing and incident analysis to assess the severity of the control failure.
Step 2: Develop an Action Plan to Address the Control Deficiency
PRMIA best practices state that risk management should prioritize corrective actions rather than delaying remediation.
The organization must define an action plan to close the gap, which includes:
Revising or strengthening the control mechanisms.
Implementing new controls, if necessary.
Assigning responsibility for remediation to control owners.
Setting deadlines for resolution.
This step aligns with PRMIA's Risk Governance Framework, which emphasizes proactive risk management.
Step 3: Implement Corrective Measures and Monitor Progress
Once an action plan is designed, the organization should execute the corrective actions.
PRMIA's Risk Monitoring Guidelines require regular follow-ups and testing to ensure the control is functioning correctly.
The effectiveness of the remediation should be validated through post-implementation review and ongoing control testing.
Step 4: Re-Assess Risks and Control Effectiveness
Once corrective measures are in place, the organization should re-evaluate risks to confirm that the issue is resolved.
The risk assessment process should be updated to reflect the changes in the control environment.
Why the Other Options Are Incorrect?
Option A: "Risks should be re-assessed to determine if there is the appropriate level of control assessment." While risk re-assessment is a good practice, it does not directly address the ineffective control.
PRMIA guidelines prioritize closing the control gap first before reassessing risks.
Option C: "The controls should be re-assessed during the next cycle to determine if they are still ineffective." Waiting until the next assessment cycle delays remediation, which could expose the organization to unmitigated risks.
PRMIA risk frameworks recommend immediate corrective action when a control is found to be ineffective.
Option D: "Risks should be re-assessed to determine if there can be an exception for the level of control assessment." PRMIA does not support exceptions for ineffective controls unless there is a well-documented risk acceptance process.
A control failure should be remediated rather than seeking exceptions.
PRMIA Risk Reference Used:
PRMIA Risk Governance Framework - Defines the importance of immediate corrective actions for control failures.
PRMIA Risk Monitoring Guidelines - Stresses continuous monitoring and validation of controls.
PRMIA Risk Management Standards - Recommends a structured action plan for ineffective controls.
PRMIA Operational Risk Framework - Emphasizes the need to close control gaps to maintain a strong risk posture.
Final Conclusion:
According to PRMIA risk management best practices, when a control is found to be ineffective, the best course of action is to design and implement an action plan to remediate the issue (Option B). This approach ensures that the organization mitigates risk promptly and maintains a strong control environment.


NEW QUESTION # 31
Which of the following is a correct statement about control rating scales?

  • A. A control rating scale should consider both control effectiveness and control performance.
  • B. They are enhanced by the use of software that includes inherent risk.
  • C. A control rating scale should consider control effectiveness but not control performance.
  • D. A control rating scale should consider neither control effectiveness or control performance.

Answer: A

Explanation:
Definition of Control Rating Scales
Control rating scales measure the effectiveness and performance of risk management controls.
They help organizations evaluate control strength and identify weaknesses.
Key Components
Control effectiveness → Measures how well the control mitigates risks.
Control performance → Assesses whether the control operates as designed in practice.
Why Answer C is Correct
Both effectiveness and performance are crucial for assessing control reliability.
A control may be designed effectively but fail in execution, making both factors essential.
Why Other Answers Are Incorrect
Option
Explanation:
A . They are enhanced by the use of software that includes inherent risk.
Incorrect - Software can improve ratings, but control scales are based on evaluation criteria, not just software tools.
B . A control rating scale should consider control effectiveness but not control performance.
Incorrect - Ignoring performance could lead to misjudging actual control reliability.
D . A control rating scale should consider neither control effectiveness nor control performance.
Incorrect - This would render the control rating scale useless.
PRMIA Reference for Verification
PRMIA Governance and Control Framework
Basel Operational Risk Management Guidelines


NEW QUESTION # 32
Compliance departments traditionally provide policy, oversight, and set the standards for monitoring personal dealing. Which control below would assist in implementing such policies?

  • A. Outsourcing of the policy writing to an accounting firm at least once every 5 years.
  • B. A list of approved suppliers that have been added to the outsourcing policy.
  • C. Outsourcing of the policy writing to an accounting firm at least once every 3 years.
  • D. Watch lists of stocks that are not allowed to be traded for a period of time, for instance, ahead of a securities offering that the firm is managing.

Answer: D

Explanation:
Definition of DORA
The Digital Operational Resilience Act (DORA) is a regulation by the European Union (EU) aimed at strengthening the digital resilience of financial institutions.
It establishes a regulatory framework for managing information and communication technology (ICT) risks in the financial sector.
Key Objectives of DORA
Ensures that financial institutions can withstand, respond to, and recover from cyber threats and ICT-related disruptions.
Introduces standards for risk management, incident reporting, and third-party ICT risk oversight.
Why Other Answers Are Incorrect
Option
Explanation:
A . Domain for Operational Risk Act.
Incorrect - No such regulation exists under this name.
B . Digital Operational Risk Act.
Incorrect - The official name is Digital Operational Resilience Act (DORA).
C . Daily Operational Resilience Act.
Incorrect - DORA is not focused on daily operations but rather long-term digital resilience.
PRMIA Reference for Verification
PRMIA Risk Governance & Digital Resilience Standards
European Commission's Official DORA Regulation


NEW QUESTION # 33
Process mapping is:

  • A. All of the above.
  • B. A useful tool for understanding process intensive activities.
  • C. A helpful tool for understanding where control gaps may exist.
  • D. A good visualization tool for understanding where hand-offs and hand-ins may occur.

Answer: A

Explanation:
Process Mapping is a risk management tool used to visualize workflows, identify inefficiencies, and detect control gaps. PRMIA defines process mapping as an essential operational risk management tool.
Step 1: Understanding Process Mapping
Helps analyze complex, process-intensive activities (Option A).
Reveals control weaknesses that could lead to operational risks (Option B).
Improves hand-offs and collaboration between teams (Option C).
Step 2: Why "All of the Above" is Correct
Process mapping serves multiple risk management purposes, making all listed options valid.
PRMIA Risk Reference Used:
PRMIA Operational Risk Management Guidelines - Recommends process mapping to identify inefficiencies and control gaps.
PRMIA Risk Governance Framework - Encourages visualization tools for process improvement.
Final Conclusion:
Process mapping improves risk awareness, identifies control gaps, and enhances operational workflows, making Option D the correct answer.


NEW QUESTION # 34
Two of the four key resources that are regarded as critical to maintain confidence and calibrate Risk Appetite to are?

  • A. Net earnings and capital.
  • B. Capital expenditure and liquidity.
  • C. Quality human resources and reputation.
  • D. Strong regulatory assessment and net earnings.

Answer: A

Explanation:
Key Resources for Calibrating Risk Appetite
Risk appetite defines how much risk an organization is willing to accept to achieve its objectives.
Two of the most critical resources for maintaining confidence and setting risk appetite are net earnings and capital.
Why Net Earnings and Capital are Critical
Net earnings reflect profitability and financial stability, influencing risk-taking capacity.
Capital ensures that the institution can absorb losses and meet regulatory requirements.
Basel III emphasizes capital adequacy as a core measure of financial resilience.
Why Answer B is Correct
Net earnings support operational stability, while capital determines how much risk an institution can bear.
Both are used to define and calibrate risk appetite levels.
Why Other Answers Are Incorrect
Option
Explanation:
A . Capital expenditure and liquidity.
Incorrect - Capital expenditure is an investment measure, not a direct risk appetite determinant.
C . Strong regulatory assessment and net earnings.
Incorrect - Regulatory assessments are important but do not directly set risk appetite.
D . Quality human resources and reputation.
Incorrect - HR and reputation are important for governance but do not directly influence risk capital and earnings stability.
PRMIA Reference for Verification
PRMIA Risk Appetite Framework
Basel III Capital and Earnings Management Guidelines


NEW QUESTION # 35
In relation to the template for writing policy documents, which one of the following pairings of requirements is correct? A well designed policy will include:

  • A. To whom and in what form exceptions should be sought and the general exemptions e.g. areas to which the policy does not apply
  • B. A list of exceptions for the family of board members.
  • C. To whom the policy applies to and how an additional management report should be allocated to.
  • D. A list of acceptable fonts and margin types.

Answer: A

Explanation:
Step 1: Key Elements of a Well-Designed Policy Document
A well-designed policy should include:
Scope - Who the policy applies to.
Exception Handling - How and where exceptions should be requested.
Accountability - Who is responsible for enforcement.
Step 2: Why Option C is Correct
A policy must clearly define exceptions and the process for requesting them.
It should also define areas where the policy does not apply to avoid confusion.
Step 3: Why the Other Options Are Incorrect
Option A ("List of exceptions for board members' families") → Incorrect because policies should apply consistently to all stakeholders.
Option B ("List of acceptable fonts and margin types") → Incorrect because formatting is secondary to content clarity.
Option D ("To whom the policy applies and an additional management report") → Incorrect because policy scope should not include unnecessary reports.
PRMIA Risk Reference Used:
PRMIA Policy Writing Guidelines - Defines policy structure and exception handling.
ISO 19600 Compliance Management Standard - Supports clear, well-documented policies.
Final Conclusion:
A well-designed policy clearly defines exceptions and their handling process, making Option C the correct answer.


NEW QUESTION # 36
In operational resilience, material customer detriment or significant harm to the customer is which of the following?

  • A. This is when disruption to a service results in not just an inconvenience to a customer, but a material cost or hardship.
  • B. This is the ability of a financial system to continue to function, even in the face of significant disruption or financial shocks.
  • C. This has a low threshold and refers to any inconvenience to a customer that results in a complaint.
  • D. This is when disruption to a service results in an inconvenience to a customer and damage to the firm's reputation.

Answer: A

Explanation:
Step 1: Definition of Material Customer Detriment
Material customer detriment refers to service disruptions that cause financial loss, inability to access essential services, or significant hardship.
PRMIA and UK FCA Operational Resilience Standards define "significant harm" as going beyond inconvenience to include monetary or operational distress.
Step 2: Why Option D is Correct
Significant harm occurs when customers face tangible financial or service losses, not just reputational inconvenience.
Regulatory frameworks (e.g., Basel, FCA, PRMIA) require banks to protect customers from material disruptions.
Step 3: Why the Other Options Are Incorrect
Option A ("Low threshold, any complaint") → Incorrect because not all complaints indicate material detriment.
Option B ("Inconvenience and reputational damage") → Incorrect because true material harm is more than just inconvenience.
Option C ("Financial system resilience") → Incorrect because this describes systemic financial stability, not customer impact.
PRMIA Risk Reference Used:
PRMIA Operational Resilience Framework - Defines material customer detriment.
UK FCA Operational Resilience Guidelines - Requires firms to minimize severe harm to customers.
Final Conclusion:
Material customer detriment involves actual financial hardship, not just inconvenience, making Option D the correct answer.


NEW QUESTION # 37
......

Actual 8020 Exam Recently Updated Questions with Free Demo: https://www.exams4collection.com/8020-latest-braindumps.html

Valid 8020 exam with PRMIA Real Exam Questions: https://drive.google.com/open?id=1fT4nhgEmXoTuZixeahyuCUuiHhbQe_QW