Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Which of the Basel Accords, published in 2004, introduced operational risk as a risk subjected to a capital charge?
Introduction of Operational Risk in Basel Accords
Basel I (1988) Focused only on credit risk and market risk; operational risk was not yet included.
Basel II (2004) Introduced operational risk as a separate category, subject to capital requirements.
Basel III (2010) Strengthened capital and liquidity requirements but did not introduce operational risk.
Basel IV (2017, still evolving) Adjusts Basel III reforms but does not introduce operational risk as a new category.
Why Answer B is Correct
Basel II (2004) was the first to introduce operational risk as a risk requiring a capital charge.
Why Other Answers Are Incorrect
Option
Explanation
A . Basel I
Incorrect -- Basel I focused on credit risk and market risk, with no capital requirements for operational risk.
C . Basel III
Incorrect -- Basel III strengthened Basel II but did not introduce operational risk.
D . Basel IV
Incorrect -- Basel IV refines Basel III but does not introduce operational risk as a new capital charge.
PRMIA Reference for Verification
Basel II (2004) Operational Risk Framework
PRMIA Operational Risk Management Guidelines
Which of the following is not the purpose or benefit of a Risk Appetite statement?
Step 1: Understanding a Risk Appetite Statement
Risk Appetite is the amount of risk an organization is willing to take to achieve its objectives.
A Risk Appetite Statement (RAS) communicates risk tolerance levels and management expectations.
Step 2: Why Option C is Incorrect
Risk Capacity (not Risk Appetite) defines the maximum risk the firm can withstand.
Risk Appetite is about willingness to take risk, not the absolute limit.
Step 3: Why the Other Options Are Correct
Option A ('Improves risk management standards') Correct, as RAS helps define better risk management.
Option B ('Governing body articulates expectations') Correct, as RAS is approved by the board.
Option D ('Assists strategic discussions') Correct, as RAS guides decision-making.
PRMIA Risk Reference Used:
PRMIA Risk Appetite Framework -- Differentiates between Risk Appetite and Risk Capacity.
Basel III Governance Principles -- Encourages organizations to establish clear risk appetite statements.
Final Conclusion:
Risk Appetite does not establish the maximum risk the firm can withstand---that is Risk Capacity, making Option C the correct answer.
In operational resilience, material customer detriment or significant harm to the customer is which of the following?
Step 1: Definition of Material Customer Detriment
Material customer detriment refers to service disruptions that cause financial loss, inability to access essential services, or significant hardship.
PRMIA and UK FCA Operational Resilience Standards define 'significant harm' as going beyond inconvenience to include monetary or operational distress.
Step 2: Why Option D is Correct
Significant harm occurs when customers face tangible financial or service losses, not just reputational inconvenience.
Regulatory frameworks (e.g., Basel, FCA, PRMIA) require banks to protect customers from material disruptions.
Step 3: Why the Other Options Are Incorrect
Option A ('Low threshold, any complaint') Incorrect because not all complaints indicate material detriment.
Option B ('Inconvenience and reputational damage') Incorrect because true material harm is more than just inconvenience.
Option C ('Financial system resilience') Incorrect because this describes systemic financial stability, not customer impact.
PRMIA Risk Reference Used:
PRMIA Operational Resilience Framework -- Defines material customer detriment.
UK FCA Operational Resilience Guidelines -- Requires firms to minimize severe harm to customers.
Final Conclusion:
Material customer detriment involves actual financial hardship, not just inconvenience, making Option D the correct answer.
Risk Sensitive pricing is required for several good reasons. Which one of the following is not relevant to the Management's evaluation of the correct approach to Risk Sensitive pricing?
Risk-sensitive pricing ensures that financial institutions and businesses properly account for risk in their pricing strategies to maintain stability and sustainability. PRMIA's Risk Pricing and Capital Adequacy Guidelines define the importance of risk-sensitive pricing in ensuring fair compensation for risk exposure and avoiding risk concentration issues.
Step 1: Why Risk-Sensitive Pricing Is Important
Aligns risk with return: Pricing should be designed to reflect the underlying risk and return trade-off.
Protects investors: Investors expect compensation for capital at risk (Option A is correct).
Reinforces risk-aware culture: PRMIA promotes linking incentives to risk-adjusted returns (Option B is correct).
Prevents adverse selection: Proper risk pricing prevents low-quality assets from accumulating (Option C is correct).
Step 2: Why Option D Is Incorrect
Income targets are business-driven, not risk-driven.
Risk-sensitive pricing aims to balance risk and reward, not just maximize revenue.
PRMIA discourages profit-seeking behavior at the expense of risk considerations.
PRMIA Risk Reference Used:
PRMIA Risk Pricing Guidelines -- Defines the principles of risk-sensitive pricing.
PRMIA Risk-Adjusted Return Standards -- Stresses linking incentives to risk-aware decisions.
PRMIA Capital Adequacy Framework -- Highlights the role of risk-sensitive pricing in portfolio management.
Final Conclusion:
Risk-sensitive pricing is designed to align returns with risk exposure, not simply to meet or exceed income targets, making Option D the correct answer.
How can a chief risk officer encourage the governing body and executive management team to create a stronger risk culture?
A Chief Risk Officer (CRO) plays a crucial role in shaping and strengthening the risk culture within an organization. PRMIA defines risk culture as the shared values, beliefs, knowledge, and understanding about risk that drive behaviors within an institution.
Setting a Clear Vision
The CRO should communicate a vision of risk management that aligns with organizational goals while ensuring that risk-taking remains within acceptable limits.
The vision should be achievable and realistic, rather than overly ambitious, which could incentivize reckless risk-taking.
Embedding Risk Awareness into Decision-Making
A strong risk culture ensures that risk considerations are embedded into business decision-making rather than treated as a separate compliance exercise.
This is supported by PRMIA's Enterprise Risk Management (ERM) Framework, which stresses integrating risk management into strategy and operations.
Avoiding a Blame Culture
A risk-aware organization promotes accountability without fear, enabling employees to report risks without retribution.
Option B (Discourage personal accountability to avoid a blame culture) is incorrect because personal accountability is essential for a healthy risk culture.
Avoiding a Strict, Prescriptive Approach
A set of rigid objectives that must be followed by the executive team (Option C) does not foster a dynamic, evolving risk culture.
Instead, risk culture should be flexible and adaptive to emerging risks.
Balancing Incentives and Consequences
While balancing rewards with penalties (Option D) is part of governance, a strong risk culture is not built solely through fear of punishment.
PRMIA emphasizes positive reinforcement, such as linking risk management behaviors to performance evaluations and incentives.
PRMIA Reference for Verification
PRMIA Risk Governance Framework -- Discusses the role of leadership in shaping risk culture.
PRMIA Standards on Enterprise Risk Management (ERM) -- Covers best practices for embedding risk culture within organizations.
60 questions covering all exam domains, starting from $20
Exam domains verified against: Official PRMIA 8020 exam guide, last checked September 2026.
Measures the skills of Risk Analysts. Covers fundamental concepts of risk governance, management, and assessment. Introduces key principles, regulatory frameworks, and industry best practices for identifying and addressing risks. Key skill measured: Understanding the foundational principles of risk management.
Sample question from this domain above: Q5
Measures the skills of Compliance Officers. Covers policies, structures, and processes that define how organizations oversee risk. Explores regulatory compliance, ethical considerations, and corporate governance frameworks to ensure accountability. Key skill measured: Applying governance frameworks to organizational risk policies.
Measures the skills of Risk Managers. Covers structured approaches for risk identification, evaluation, and mitigation. Includes industry-standard frameworks that guide risk strategy and decision-making. Key skill measured: Establishing a risk management framework for organizations.
Measures the skills of Financial Risk Analysts. Covers methodologies for evaluating risks in different domains, including qualitative and quantitative approaches. Focuses on assessing vulnerabilities, threats, and potential impacts on business operations. Key skill measured: Conducting risk impact analysis for financial threats.
Measures the skills of Risk Data Specialists. Covers the collection, analysis, and communication of risk-related data. Highlights the role of data-driven decision-making in mitigating uncertainties and ensuring compliance. Key skill measured: Interpreting risk data for informed decision-making.
Measures the skills of Quantitative Risk Analysts. Covers mathematical and statistical techniques used to predict risk scenarios. Explores model development, validation, and application in financial and operational risk management. Key skill measured: Applying statistical models for risk prediction.
Measures the skills of Insurance Risk Specialists. Covers strategies for transferring risk through insurance and other financial instruments. Focuses on risk transfer mechanisms, policy structuring, and claims management. Key skill measured: Assessing risk transfer options through insurance.
Measures the skills of Business Risk Consultants. Covers real-world applications of risk management concepts. Examines case studies on risk governance, assessment, and mitigation strategies across different industries. Key skill measured: Analyzing historical risk events for strategic insights.
Common questions about the exam itself