Free Questions › CTP › Financial, Regulatory and Operational Risk
Free CTP Financial, Regulatory and Operational Risk Practice Questions & Answers
82 exam-style Financial, Regulatory and Operational Risk questions. Pick your answer, hit Check answer, and see the worked solution — free to start, no signup.
100% free · No login to startQuestion 1
What is the primary purpose of a corporate investment policy statement?
Select an option first.
Correct answer: C — To define permissible instruments, credit-quality limits, and approval authorities for investing surplus cash
Explanation: An investment policy statement establishes the framework governing how surplus funds may be invested, including eligible instruments, maturity and concentration limits, minimum credit ratings, and who is authorized to act. It cannot guarantee returns because market conditions vary, and it does not set dividends or eliminate board governance.
Question 2
In a well-designed treasury policy, the three primary objectives for managing short-term investments are typically prioritized in which order?
Select an option first.
Correct answer: A — Safety, liquidity, then yield
Explanation: Standard treasury practice prioritizes preservation of principal (safety) first, then availability of funds when needed (liquidity), and only then maximization of return (yield). Pursuing yield ahead of safety exposes the firm to credit and market losses that undermine the core purpose of holding operating cash.
Question 3
Which document typically specifies the maximum dollar amount an individual treasury employee may approve for a wire transfer without a second approver?
Select an option first.
Correct answer: B — The approval authority matrix (delegation of authority)
Explanation: An approval authority matrix, or delegation of authority, defines dollar thresholds and the number of approvers required at each level. It is a core internal control that enforces segregation of duties and prevents any single person from moving large sums unilaterally.
Question 4
A risk management policy that permits derivatives only to reduce identified exposures, and prohibits their use to take speculative positions, is best described as authorizing derivatives for what purpose?
Select an option first.
Correct answer: B — Hedging
Explanation: Restricting derivatives to reducing identified exposures is the definition of a hedging mandate. Most corporate risk policies explicitly prohibit speculation, requiring that every derivative be linked to an underlying business exposure such as interest-rate, currency, or commodity price risk.
Question 5
Which of the following is typically an element of a treasury operational procedure rather than a high-level policy?
Select an option first.
Correct answer: B — The step-by-step instructions for confirming and releasing a wire in the banking portal
Explanation: Procedures are the detailed, task-level instructions that implement a policy, such as the specific steps to confirm and release a wire. Risk appetite, tenor limits, and delegation of authority are policy-level decisions set by governance bodies.
Get the full CTP question bank — free
Drop your email and we'll send you fresh CTP practice questions, fully worked solutions and exam-deadline reminders. No spam — unsubscribe in one click.
Want to save your score and take a full mock exam? Create a free account →
Question 6
An escalation procedure in a treasury policy primarily defines:
Select an option first.
Correct answer: A — When and to whom a limit breach or exception must be reported for resolution
Explanation: Escalation procedures specify the triggers, timing, and recipients for reporting limit breaches, exceptions, or unusual events so they are addressed by the appropriate level of authority. This ensures problems reach decision-makers quickly rather than being absorbed silently at the operating level.
Question 7
Positive pay is a bank service designed primarily to detect:
Select an option first.
Correct answer: B — Altered, forged, or counterfeit checks presented against the account
Explanation: Positive pay matches checks presented for payment against a company-supplied issue file of check numbers, amounts, and payees, flagging exceptions for review. It is a core control against altered, forged, or counterfeit check fraud and is unrelated to FX or card interchange.
Question 8
Business email compromise (BEC) fraud most commonly succeeds by:
Select an option first.
Correct answer: D — Impersonating an executive or vendor to induce an employee to send a fraudulent payment or change payment instructions
Explanation: BEC relies on social engineering: fraudsters pose as a trusted executive or supplier and use urgent, plausible emails to trick employees into wiring funds or updating banking details. The attack targets human trust and process gaps rather than technical encryption weaknesses.
Question 9
A control requiring two separate individuals to approve a payment before it is released is known as:
Select an option first.
Correct answer: B — Dual control (dual authorization)
Explanation: Dual control requires two authorized individuals to act on a transaction, ensuring no single person can release a payment alone. This reduces the risk of both error and fraud and is a foundational payment control distinct from reconciliation or account structures.
Question 10
Which service allows a company to block all ACH debits to an account except those from pre-authorized originators?
Select an option first.
Correct answer: D — ACH positive pay / ACH debit filter (block)
Explanation: ACH debit filters or blocks let a company specify which originators (by company ID and often dollar limit) are permitted to debit an account, rejecting all others or routing them to exception review. This directly defends against unauthorized ACH debit fraud.
Question 11
Reverse positive pay differs from standard positive pay in that:
Select an option first.
Correct answer: A — The bank pays all checks and the company must review presented items and instruct the bank to return unwanted ones
Explanation: In reverse positive pay the burden shifts to the company: the bank presents the list of items and the company must identify and return unauthorized checks, with unreviewed items typically paid by default. This is generally weaker than standard positive pay, where mismatches default to non-payment pending review.
Question 12
A counterparty credit limit is best described as:
Select an option first.
Correct answer: B — The maximum exposure a firm is willing to have to a single counterparty
Explanation: A counterparty credit limit caps the firm's total permitted exposure to one counterparty, controlling concentration and default risk. It reflects the firm's assessment of that counterparty's creditworthiness and its own risk appetite.
Question 13
In credit-rating terminology, which of the following is considered the lowest investment-grade rating?
Select an option first.
Correct answer: C — BBB- / Baa3
Explanation: BBB-/Baa3 is the lowest rung of investment grade; anything below it (BB+/Ba1 and lower) is speculative or non-investment grade. Many investment policies set BBB- or A- as the minimum acceptable rating for counterparties or instruments.
Question 14
A credit default swap (CDS) spread widening on a counterparty is generally interpreted as:
Select an option first.
Correct answer: A — Deteriorating creditworthiness / higher perceived default risk
Explanation: A wider CDS spread means the market demands more premium to insure against that counterparty's default, signaling deteriorating credit quality. Treasury teams monitor CDS spreads as a real-time, forward-looking complement to slower-moving agency ratings.
Question 15
Operational risk in a treasury context is best defined as the risk of loss resulting from:
Select an option first.
Correct answer: B — Inadequate or failed internal processes, people, systems, or external events
Explanation: Operational risk stems from failures in processes, people, and systems or from external events such as disasters and fraud, as distinguished from market or credit risk. This definition, consistent with Basel guidance, underpins controls, redundancy, and business continuity planning.
Question 16
A Business Continuity Plan (BCP) is primarily intended to:
Select an option first.
Correct answer: D — Ensure the organization can maintain or quickly resume critical functions after a disruptive event
Explanation: A BCP focuses on sustaining or rapidly restoring critical business functions following disruptions such as natural disasters, cyberattacks, or outages. It addresses continuity of operations rather than yield optimization or pricing decisions.
Question 17
In disaster recovery planning, the Recovery Time Objective (RTO) represents:
Select an option first.
Correct answer: D — The targeted duration within which a business process must be restored after a disruption
Explanation: RTO is the maximum tolerable time to restore a process or system after an outage. It is distinct from the Recovery Point Objective (RPO), which measures acceptable data loss; together they drive backup and redundancy design.
Question 18
The Recovery Point Objective (RPO) primarily addresses:
Select an option first.
Correct answer: C — How much data loss, measured as a time interval, is acceptable
Explanation: RPO defines the maximum acceptable data loss expressed as a point in time to which data must be recoverable, effectively dictating backup frequency. A one-hour RPO, for example, requires backups at least hourly so no more than an hour of data is lost.
Question 19
Cross-training treasury staff on critical processes primarily mitigates which risk?
Select an option first.
Correct answer: D — Key-person (single point of failure) operational risk
Explanation: Cross-training ensures that if a key employee is unavailable, others can perform essential treasury functions, reducing dependence on any single individual. This addresses key-person operational risk rather than market-related exposures.
Question 20
A business impact analysis (BIA) is used in continuity planning primarily to:
Select an option first.
Correct answer: D — Identify critical processes and the financial and operational impact of their disruption over time
Explanation: A BIA identifies which processes are critical, how quickly they must be recovered, and the escalating impact of downtime, thereby informing RTOs, RPOs, and resource priorities. It is the analytical foundation on which the continuity and recovery strategy is built.
Question 21
Interchange is best described as:
Select an option first.
Correct answer: D — A fee set by the card networks and paid by the merchant's acquirer to the card-issuing bank on each transaction
Explanation: Interchange is the fee, established by the card networks, that the acquiring (merchant) bank pays to the card-issuing bank for each card transaction, and it is passed on to the merchant as part of its processing costs. It is the largest component of a merchant's cost of card acceptance.
Question 22
PCI DSS (Payment Card Industry Data Security Standard) primarily aims to:
Select an option first.
Correct answer: C — Protect cardholder data through security requirements for entities that store, process, or transmit it
Explanation: PCI DSS is a set of security standards designed to protect cardholder data across all organizations that store, process, or transmit it. Compliance reduces the risk of data breaches and the associated fines and reputational harm, but it does not set pricing or guarantee profits.
Question 23
A chargeback occurs when:
Select an option first.
Correct answer: B — A cardholder disputes a transaction and the amount is reversed back from the merchant
Explanation: A chargeback is a forced reversal of a card transaction initiated when a cardholder disputes it, returning the funds from the merchant to the cardholder pending resolution. Excessive chargebacks can trigger penalties and higher processing costs for the merchant.
Question 24
A purchasing card (p-card) program is primarily used to:
Select an option first.
Correct answer: C — Streamline and control low-value, high-volume purchases while capturing spend data
Explanation: P-card programs efficiently handle numerous small-dollar purchases, reducing purchase-order and invoice processing while providing controls such as merchant category and spending limits plus detailed reporting. They improve procurement efficiency rather than manage market risk.
Question 25
The Basel III Liquidity Coverage Ratio (LCR) requires banks to hold enough high-quality liquid assets (HQLA) to cover net cash outflows over what stress horizon?
Select an option first.
Correct answer: D — 30 days
Explanation: The LCR requires banks to maintain HQLA sufficient to survive a 30-calendar-day severe liquidity stress scenario. It is calculated as HQLA divided by total net cash outflows over 30 days and must be at least 100%.
Question 26
Know Your Customer (KYC) requirements are primarily intended to:
Select an option first.
Correct answer: C — Verify customer identities and understand their activities to prevent money laundering and illicit finance
Explanation: KYC obligates financial institutions to verify identity, assess risk, and monitor activity to detect and deter money laundering, terrorist financing, and other illicit use. It is a foundational element of AML compliance programs.
Question 27
OFAC (Office of Foreign Assets Control) compliance requires U.S. persons and companies to:
Select an option first.
Correct answer: D — Screen transactions and counterparties against sanctions lists and block or reject prohibited dealings
Explanation: OFAC administers U.S. economic sanctions, requiring firms to screen counterparties and transactions against lists such as the SDN list and to block or reject prohibited transactions. Violations can result in significant civil and criminal penalties, including strict-liability fines.
Question 28
Under the Sarbanes-Oxley Act (SOX), Section 404 primarily requires:
Select an option first.
Correct answer: B — Management to assess and report on the effectiveness of internal control over financial reporting
Explanation: SOX Section 404 requires management (and, for many companies, the external auditor) to assess and report on the effectiveness of internal control over financial reporting. This drives documentation and testing of controls, including many within treasury operations.
Question 29
Value at Risk (VaR) is best described as:
Select an option first.
Correct answer: B — An estimate of the maximum expected loss over a given horizon at a specified confidence level under normal conditions
Explanation: VaR estimates the loss that is not expected to be exceeded over a specified horizon at a given confidence level (for example, 95% or 99%) under normal market conditions. It is a probabilistic measure and does not represent an absolute worst case, which is why stress testing supplements it.
Question 30
Sensitivity analysis in risk measurement involves:
Select an option first.
Correct answer: C — Measuring how a portfolio or exposure's value changes when a single risk factor moves by a specified amount
Explanation: Sensitivity analysis isolates one risk factor, such as an interest rate or exchange rate, and measures the resulting change in value while holding others constant. Common examples include DV01 for rates and delta for options, providing intuitive, single-factor risk insight.
More free CTP topics
Ten questions in
- The ones you miss are saved as a drill you can repeat
- Your place is kept, on this device and any other
- A streak, if that is the thing that gets you back tomorrow
Every question on this page stays free and open either way.