
[Oct-2025] Pass 8020 Exam in First Attempt Updated 8020 Exam Questions
PRM Certification Dumps 8020 Exam for Full Questions - Exam Study Guide
PRMIA 8020 Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
NEW QUESTION # 29
Risk and compliance functions often work together; which of the following best desribes the issue with a "zero risk appetite"?
- A. It means that there can be a risk self assessment workshop for the compliance department.
- B. A zero risk appetite is illegal under all known regulations.
- C. It will result in a compliance investigation conducted by the first line.
- D. An organization may decide that it will accept a certain level of outstanding compliance issues and thus will breach such an appetite statement.
Answer: D
Explanation:
Understanding Zero Risk Appetite in Compliance
A zero risk appetite means the organization does not tolerate any compliance breaches.
However, in real-world risk management, it is often impractical to have zero risk exposure.
Some compliance violations may occur despite strong controls, making a strict zero-risk stance unrealistic.
Why Answer C is Correct
If an organization adopts a zero risk appetite for compliance, any compliance issue, even minor ones, would breach this policy.
This contradicts practical risk management, which allows for some residual risk while maintaining controls.
Why Other Answers Are Incorrect
Option
Explanation:
A . A zero risk appetite is illegal under all known regulations.
Incorrect - It is not illegal, but it is impractical in many industries.
B . It means that there can be a risk self-assessment workshop for the compliance department.
Incorrect - Self-assessments are part of compliance but do not define zero risk appetite issues.
D . It will result in a compliance investigation conducted by the first line.
Incorrect - Investigations are typically conducted by the second or third line of defense (compliance or audit), not the first line.
PRMIA Reference for Verification
PRMIA Risk Appetite Guidelines
Basel & ISO 31000 Risk Management Frameworks
NEW QUESTION # 30
Two of the four key resources that are regarded as critical to maintain confidence and calibrate Risk Appetite to are?
- A. Capital expenditure and liquidity.
- B. Strong regulatory assessment and net earnings.
- C. Net earnings and capital.
- D. Quality human resources and reputation.
Answer: C
Explanation:
Key Resources for Calibrating Risk Appetite
Risk appetite defines how much risk an organization is willing to accept to achieve its objectives.
Two of the most critical resources for maintaining confidence and setting risk appetite are net earnings and capital.
Why Net Earnings and Capital are Critical
Net earnings reflect profitability and financial stability, influencing risk-taking capacity.
Capital ensures that the institution can absorb losses and meet regulatory requirements.
Basel III emphasizes capital adequacy as a core measure of financial resilience.
Why Answer B is Correct
Net earnings support operational stability, while capital determines how much risk an institution can bear.
Both are used to define and calibrate risk appetite levels.
Why Other Answers Are Incorrect
Option
Explanation:
A . Capital expenditure and liquidity.
Incorrect - Capital expenditure is an investment measure, not a direct risk appetite determinant.
C . Strong regulatory assessment and net earnings.
Incorrect - Regulatory assessments are important but do not directly set risk appetite.
D . Quality human resources and reputation.
Incorrect - HR and reputation are important for governance but do not directly influence risk capital and earnings stability.
PRMIA Reference for Verification
PRMIA Risk Appetite Framework
Basel III Capital and Earnings Management Guidelines
NEW QUESTION # 31
What are some of the properties of Bottom-Up KRIs?
- A. Seated by senior management: tied to internal loss events at the legal entity, country, business and / or product level, reported.
daily, weekly or monthly. - B. Are not used due to changes in regulations.
- C. Selected by local management: tied to internal loss events at the legal entity, country, business and / or product level, reported daily, weekly or monthly.
- D. Selected by local management, based on key controls or weaknesses identified by audit reports, reported on quarterly.
Answer: C
Explanation:
Definition of Bottom-Up KRIs
Bottom-Up Key Risk Indicators (KRIs) are identified at the operational level, focusing on localized risks within business units.
They are tied to actual internal loss events and reported frequently (daily, weekly, or monthly) to capture ongoing trends.
Key Properties of Bottom-Up KRIs
Selected by local management → Ensures relevance to specific business areas.
Tied to internal loss events → Helps in tracking risk patterns within specific legal entities, countries, or business units.
Reported frequently → Allows for timely risk detection and mitigation.
Why Answer D is Correct
Bottom-up KRIs focus on localized risk exposure and are monitored frequently to track operational changes.
Why Other Answers Are Incorrect
Option
Explanation:
A . Seated by senior management: tied to internal loss events at the legal entity, country, business, and/or product level, reported daily, weekly, or monthly.
Incorrect - Senior management sets top-down KRIs, while bottom-up KRIs are managed locally.
B . Selected by local management, based on key controls or weaknesses identified by audit reports, reported quarterly.
Incorrect - While audit reports are useful, bottom-up KRIs are based on loss events, not just audit findings. Quarterly reporting is too infrequent.
C . Are not used due to changes in regulations.
Incorrect - Bottom-up KRIs remain essential despite regulatory changes.
PRMIA Reference for Verification
PRMIA Risk Indicator Best Practices
Basel Committee's Risk Measurement and Reporting Guidelines
NEW QUESTION # 32
For the FTX case study, what was the "backdoor" used for?
- A. It allowed trading firm Alameda to borrow S65 billion of clients' money from the exchange without their permission.
- B. It allowed a rapid pace of acquisitions but poor integration of acquired companies.
- C. It allowed a stable coin to be removed from the ledger and added to the balance sheet.
- D. It allowed currency traders to smooth profits and conceal losses for over two years.
Answer: A
Explanation:
The FTX collapse involved fraudulent fund mismanagement, where FTX executives created a "backdoor" to allow Alameda Research (FTX's sister trading firm) to borrow client funds without their consent.
Step 1: The "Backdoor" in FTX
The backdoor was a hidden code in FTX's system, allegedly created by Sam Bankman-Fried, which allowed Alameda to access customer deposits without triggering alerts to auditors or compliance teams.
Alameda used these funds for risky trading strategies and investments, leading to the eventual collapse of FTX when a liquidity crunch exposed the missing funds.
Step 2: Why the Other Options Are Incorrect
Option A ("allowed a stablecoin to be removed from the ledger and added to the balance sheet") Incorrect because FTX's fraud involved misuse of customer funds, not just a stablecoin misclassification.
Option C ("allowed currency traders to smooth profits and conceal losses for over two years") Incorrect because this sounds more like LIBOR-rigging scandals, whereas FTX misappropriated client funds.
Option D ("allowed a rapid pace of acquisitions but poor integration of acquired companies") Incorrect because FTX's collapse was due to financial fraud, not poor acquisition strategy.
PRMIA Risk Reference Used:
PRMIA Financial Crime Risk Management - Discusses insider risk and fraudulent misappropriation of funds.
FTX Collapse Reports - SEC, CFTC, and DOJ filings confirm that Alameda had unauthorized access to client funds.
Final Conclusion:
FTX's backdoor enabled Alameda to take $65 billion in client funds without permission, making Option B the correct answer.
NEW QUESTION # 33
How can a chief risk officer encourage the governing body and executive management team to create a stronger risk culture?
- A. Discourage personal accountability to avoid a blame culture.
- B. Having a vision of achievable but not excessive ambition.
- C. Balance rewarding success in profitability goals with punishment when there is a failure to achieve goals.
- D. Establish a set of objectives that the board and executive team must adhere to.
Answer: B
Explanation:
A Chief Risk Officer (CRO) plays a crucial role in shaping and strengthening the risk culture within an organization. PRMIA defines risk culture as the shared values, beliefs, knowledge, and understanding about risk that drive behaviors within an institution.
Setting a Clear Vision
The CRO should communicate a vision of risk management that aligns with organizational goals while ensuring that risk-taking remains within acceptable limits.
The vision should be achievable and realistic, rather than overly ambitious, which could incentivize reckless risk-taking.
Embedding Risk Awareness into Decision-Making
A strong risk culture ensures that risk considerations are embedded into business decision-making rather than treated as a separate compliance exercise.
This is supported by PRMIA's Enterprise Risk Management (ERM) Framework, which stresses integrating risk management into strategy and operations.
Avoiding a Blame Culture
A risk-aware organization promotes accountability without fear, enabling employees to report risks without retribution.
Option B (Discourage personal accountability to avoid a blame culture) is incorrect because personal accountability is essential for a healthy risk culture.
Avoiding a Strict, Prescriptive Approach
A set of rigid objectives that must be followed by the executive team (Option C) does not foster a dynamic, evolving risk culture.
Instead, risk culture should be flexible and adaptive to emerging risks.
Balancing Incentives and Consequences
While balancing rewards with penalties (Option D) is part of governance, a strong risk culture is not built solely through fear of punishment.
PRMIA emphasizes positive reinforcement, such as linking risk management behaviors to performance evaluations and incentives.
PRMIA Reference for Verification
PRMIA Risk Governance Framework - Discusses the role of leadership in shaping risk culture.
PRMIA Standards on Enterprise Risk Management (ERM) - Covers best practices for embedding risk culture within organizations.
NEW QUESTION # 34
Governance can be defined as which of the following?
- A. Governance is a structure specifying the ways in which reporting is made to the primary regulator.
- B. Governance is a structure specifying the policies, principles, and procedures for making decisions about corporate direction.
- C. Governance is a structure specifying the daily operation of a firm.
- D. Governance is being replaced by management in all firms that are regulated.
Answer: B
Explanation:
Definition of Governance
Governance refers to the framework of policies, principles, and processes used to guide corporate decision-making and strategic direction.
It ensures accountability, transparency, and risk oversight within an organization.
Key Elements of Governance
Risk oversight - Ensuring risks are properly identified and managed.
Accountability structures - Defining roles and responsibilities.
Decision-making frameworks - Establishing policies for long-term corporate success.
Why Other Answers Are Incorrect
Option
Explanation:
A . Governance is a structure specifying the daily operation of a firm.
Incorrect - Governance focuses on high-level corporate oversight, not day-to-day operations.
B . Governance is a structure specifying the ways in which reporting is made to the primary regulator.
Incorrect - Governance is broader than just regulatory reporting.
C . Governance is being replaced by management in all firms that are regulated.
Incorrect - Governance and management are separate but complementary; governance provides oversight, while management executes strategy.
PRMIA Reference for Verification
PRMIA 10 Principles of Good Governance
NEW QUESTION # 35
Risk Capacity for a bank is defined as the:
- A. Ability to withstand an extreme event and make a profit.
- B. Ability to suffer an extreme event with an orderly wind up with only shareholders losing money.
- C. Amount of risk the regulator sets for the bank.
- D. Amount of risk the bank wishes to take.
Answer: B
Explanation:
Step 1: Definition of Risk Capacity
Risk Capacity refers to the maximum level of risk a bank can absorb while still maintaining orderly operations or, in extreme cases, conducting an orderly resolution.
PRMIA and Basel III define risk capacity as a bank's ability to absorb losses in a crisis without systemic consequences.
Step 2: Why Option D Is Correct
The ultimate test of a bank's risk capacity is whether it can survive an extreme shock without harming depositors or financial markets.
Regulators ensure that a bank can be wound up in an orderly manner so that only shareholders lose money, while depositors and creditors remain protected under resolution planning frameworks.
Step 3: Why the Other Options Are Incorrect
Option A ("Amount of risk the bank wishes to take")
Incorrect because this describes Risk Appetite, not Risk Capacity.
Option B ("Amount of risk the regulator sets for the bank")
Incorrect because regulators set capital requirements, but the bank's actual risk capacity is based on its own capital structure and business model.
Option C ("Ability to withstand an extreme event and make a profit")
Incorrect because risk capacity is about survival, not profit-making during extreme events.
PRMIA Risk Reference Used:
Basel III Risk Capacity Standards - Defines the ability to absorb losses during crises.
PRMIA Risk Governance Framework - Describes how banks should manage risk capacity through capital buffers.
Final Conclusion:
Banks must be able to withstand an extreme event and conduct an orderly wind-up if necessary, ensuring that only shareholders bear the loss, making Option D the correct answer.
NEW QUESTION # 36
What are the objectives of conducting an internal loss investigation?
- A. This is determined on a case by case basis by the HR team.
- B. Increase understanding of root causes, focus attention on remediation, and improve the quality of scenario analysis and risk assessments.
- C. Increase understanding of root causes, focus attention on remediation, and ascertain responsibility for the loss event.
- D. Increase understanding of root causes, focus attention on who caused the issue, and improve the quality of scenario analysis and risk assessments.
Answer: B
Explanation:
tep 1: Purpose of Internal Loss Investigations
Internal loss investigations analyze past loss events to identify root causes, improve controls, and enhance risk assessments.
Step 2: Why Option A Is Correct
Root Cause Analysis: Identifying why the loss occurred.
Focus on Remediation: Implementing corrective measures to prevent recurrence.
Scenario Analysis Improvement: Using lessons learned to enhance risk scenario modeling.
Step 3: Why the Other Options Are Incorrect
Option B ("Focus on who caused the issue") → Incorrect because loss investigations are about systemic issues, not assigning blame.
Option C ("Ascertain responsibility for the loss event") → Incorrect because the focus is on process improvements, not individual accountability.
Option D ("Determined by HR on a case-by-case basis") → Incorrect because HR does not dictate risk investigations-risk and compliance functions do.
PRMIA Risk Reference Used:
PRMIA Operational Risk Framework - Emphasizes loss investigations for systemic risk management.
Basel III Risk Governance Standards - Defines loss event analysis as a key risk management tool.
NEW QUESTION # 37
Which of the following best describes the role of the compliance department?
- A. The compliance department is responsible for providing oversight over the auditor's implementation of compliance risk management controls.
- B. The compliance department is responsible for implementing the first line's compliance risk management controls.
- C. The compliance department is responsible for providing oversight over the board's implementation of compliance risk management controls.
- D. The compliance department is responsible for providing oversight over the first line's implementation of compliance risk management controls.
Answer: D
Explanation:
Three Lines of Defense Model
The compliance department functions as the second line of defense, ensuring oversight over the first line's compliance controls.
It does not directly implement controls but monitors and advises on compliance risk management.
Responsibilities of the Compliance Department
Ensures regulatory compliance with laws, policies, and industry standards.
Monitors and enforces risk management controls within business operations.
Provides advisory and training on compliance risks.
Why Answer D is Correct
The first line of defense (business operations) is responsible for executing compliance controls.
The compliance department (second line) provides oversight and governance to ensure compliance adherence.
Why Other Answers Are Incorrect
Option
Explanation:
A . The compliance department is responsible for implementing the first line's compliance risk management controls.
Incorrect - The first line (business units) implement compliance controls, while compliance oversees.
B . The compliance department is responsible for providing oversight over the auditor's implementation of compliance risk management controls.
Incorrect - Internal audit is part of the third line of defense, not directly overseen by compliance.
C . The compliance department is responsible for providing oversight over the board's implementation of compliance risk management controls.
Incorrect - The board provides high-level governance; compliance ensures business adherence to regulations.
PRMIA Reference for Verification
PRMIA Governance & Compliance Oversight Framework
Basel Committee's Guidelines on Compliance Risk Management
NEW QUESTION # 38
In operational resilience, what is impact tolerance?
- A. Impact tolerance is a firm's risk appetite statement.
- B. Impact tolerance is a firm's tolerance for disruption to a particular business process.
- C. Impact tolerance is a firm's risk capacity statement.
- D. Impact tolerance is a firm's tolerance for disruption to a particular business service.
Answer: D
NEW QUESTION # 39
In Operational Resilience, which of the following is not an important measure of whether a Business Service can be considered Critical?
- A. Whether a disruption to the provision of the service could exceed risk appetite.
- B. Whether a disruption to the provision of the service could threaten a firm's viability.
- C. Whether a disruption to the provision of the service could cause material customer detriment.
- D. Whether a disruption to the provision of the service could harm market integrity.
Answer: A
Explanation:
Step 1: Definition of a Critical Business Service in Operational Resilience A Critical Business Service is one whose failure could result in severe harm to customers, financial markets, or the firm's viability.
Regulators (e.g., Bank of England, Basel Committee, PRMIA) define three primary factors for identifying critical services:
Customer impact
Market integrity impact
Firm viability impact
Step 2: Why Option C Is Incorrect
Risk appetite is an internal business decision, not an external measure of criticality.
A service can be critical even if its disruption stays within risk appetite.
Criticality is based on external impacts, not just internal risk limits.
Step 3: Why the Other Options Are Correct
Option A ("Material customer detriment") → Correct as customer harm defines critical services.
Option B ("Harm to market integrity") → Correct as market stability is a regulatory priority.
Option D ("Threaten firm viability") → Correct as critical services often determine business survival.
PRMIA Risk Reference Used:
PRMIA Operational Resilience Framework - Defines criteria for critical business services.
Basel Committee Operational Risk Guidelines - Highlights customer, market, and firm viability as resilience factors.
Final Conclusion:
Risk appetite is an internal benchmark, not a measure of critical service designation, making Option C the correct answer.
NEW QUESTION # 40
For the National Australia Bank - FX Options case study, which was the major cause of the loss event?
- A. Currency traders were allowed access to the risk system by the CEO.
- B. Currency traders were able to complete a Management Buy Out (MBO).
- C. Currency traders smoothed profits and concealed losses.
- D. Currency traders concealed losses using back office knowledge.
Answer: C
Explanation:
Overview of the National Australia Bank (NAB) FX Options Case Study
Traders at National Australia Bank (NAB) engaged in unauthorized foreign exchange (FX) options trading.
They smoothed profits and concealed losses using fictitious transactions and manipulated reporting.
This led to a major financial scandal and loss of investor confidence.
Key Findings of the Investigation
Traders artificially smoothed profits to avoid drawing attention to large fluctuations.
Losses were concealed from internal risk controls by manipulating trade records.
The bank's risk management and governance controls failed to detect and prevent these activities.
Why Other Answers Are Incorrect
Option
Explanation:
A . Currency traders were allowed access to the risk system by the CEO.
Incorrect - No evidence suggests CEO involvement in granting system access.
B . Currency traders concealed losses using back-office knowledge.
Incorrect - While they concealed losses, they also smoothed profits to manipulate earnings trends.
D . Currency traders were able to complete a Management Buy Out (MBO).
Incorrect - This event was not related to a Management Buyout (MBO); it was a trading scandal.
PRMIA Reference for Verification
PRMIA Fraud and Risk Management Case Studies
Basel Principles on Market Risk and Internal Control Failures
NEW QUESTION # 41
Ideally, which of the following should be completed as part of the risk assessments of service providers?
- A. An assessment of a third party should include its compliance and risk infrastructure, financials, business strategy and operating history.
- B. An assessment of a third party should not include its compliance and risk infrastructure, financials, business strategy and operating history.
- C. A review of the pay levels of the staff supporting the service.
- D. Onsite visits are not advantageous for understanding the third party's risks and control environment.
Answer: A
Explanation:
Third-Party Risk Management (TPRM)
PRMIA highlights the importance of conducting thorough due diligence on third-party vendors and service providers.
This includes evaluating compliance programs, risk management frameworks, financial stability, strategic objectives, and operational history.
Key Areas of Third-Party Risk Assessment
Compliance and Risk Infrastructure → Ensures that the provider meets regulatory and security requirements.
Financial Health → Determines whether the provider has the financial stability to support long-term service delivery.
Business Strategy → Helps assess alignment with the organization's risk appetite and goals.
Operating History → Evaluates experience and reliability in delivering services.
Why Other Answers Are Incorrect
Option
Explanation:
B . An assessment of a third party should not include its compliance and risk infrastructure, financials, business strategy, and operating history.
Incorrect - Ignoring these critical factors increases the risk of working with an unreliable vendor.
C . Onsite visits are not advantageous for understanding the third party's risks and control environment.
Incorrect - Onsite visits are highly valuable as they provide first-hand insights into operational controls. PRMIA encourages risk managers to conduct site visits.
D . A review of the pay levels of the staff supporting the service.
Incorrect - Employee salaries are not a primary risk factor in vendor assessments. The focus should be on the vendor's security, compliance, and operational risks.
PRMIA Reference for Verification
PRMIA Third-Party Risk Management (TPRM) Guidelines - Details best practices for vendor risk assessments.
Basel Principles on Outsourcing and Third-Party Risk - Provides regulatory guidance on evaluating third-party service providers.
NEW QUESTION # 42
The acronym ESG can stand for:
- A. Enhanced Social Governance.
- B. Environmental. Strategy, and corporate Governance.
- C. Extra Social Governance.
- D. Environmental. Social and corporate Governance.
Answer: D
Explanation:
Step 1: Definition of ESG
ESG (Environmental, Social, and Corporate Governance) refers to the three core factors used to evaluate a company's sustainability and ethical impact.
ESG is now a key part of risk management, influencing investment decisions, regulatory compliance, and corporate strategy.
Step 2: Breakdown of ESG Components
Environmental (E): Climate change, carbon emissions, resource management.
Social (S): Diversity & inclusion, labor rights, community engagement.
Governance (G): Board structure, executive pay, corporate ethics.
Step 3: Why the Other Options Are Incorrect
Option A ("Environmental, Strategy, and Corporate Governance")
Incorrect because Strategy is not part of ESG.
Option C ("Enhanced Social Governance")
Incorrect because ESG covers more than just social governance.
Option D ("Extra Social Governance")
Incorrect as it does not align with the recognized ESG definition.
PRMIA Risk Reference Used:
PRMIA ESG Risk Management Guidelines - Defines ESG factors as Environmental, Social, and Governance.
PRI (Principles for Responsible Investment) - Aligns ESG with financial risk management.
NEW QUESTION # 43
Which of the follow does the risk function typically have responsibility for?
- A. Documenting its activities, typically by developing a Risk Management Manual and set of Risk Policies.
- B. Putting in place the servers, firewalls and software to ensure cyber security.
- C. Documenting its activities, typically by operating and then recording the daily operation of controls.
- D. Creating a trial balance, balance sheet statement and cash flow statement.
Answer: A
Explanation:
Role of the Risk Function
The risk function is responsible for documenting, monitoring, and overseeing risk policies and frameworks.
It ensures the organization maintains structured risk governance, reporting, and compliance.
Key Responsibilities
Developing Risk Management Manuals to define risk appetite, risk frameworks, and risk governance structures.
Creating Risk Policies that align with regulatory standards and internal controls.
Why Answer B is Correct
The risk function primarily develops, implements, and maintains risk management frameworks, which include formal manuals and policies.
Why Other Answers Are Incorrect
Option
Explanation:
A . Documenting its activities, typically by operating and then recording the daily operation of controls.
Incorrect - The first line of defense (business units) handles daily operational controls, not the risk function.
C . Putting in place the servers, firewalls, and software to ensure cybersecurity.
Incorrect - Cybersecurity is an IT responsibility, while the risk function oversees cyber risk frameworks.
D . Creating a trial balance, balance sheet statement, and cash flow statement.
Incorrect - These are financial accounting responsibilities, not risk management duties.
PRMIA Reference for Verification
PRMIA Governance Framework for Risk Management
Basel Risk Management Principles
NEW QUESTION # 44
Stafford Beers Viable System Model (VSM) has several implementation elements. Which of the following is not one of these?
- A. Governance
- B. Output
- C. Process
- D. Input
Answer: D
Explanation:
Stafford Beer's Viable System Model (VSM)
VSM is a cybernetic model designed to analyze and improve organizational structures.
It consists of five core subsystems that define governance and operations.
Why Answer B is Correct
The VSM does not explicitly include "Input" as a key component.
The key elements of VSM include Governance, Process, and Output, but it does not define "Input" as a standalone concept.
Why Other Answers Are Incorrect
Option
Explanation:
A . Governance
Correct - Governance is part of VSM and deals with decision-making and oversight.
C . Process
Correct - Process represents the operational functions within VSM.
D . Output
Correct - Output refers to the results of the system's operations.
PRMIA Reference for Verification
PRMIA Governance and Cybernetic Systems Guidelines
Stafford Beer's Viable System Model Framework
NEW QUESTION # 45
......
Authentic Best resources for 8020 Online Practice Exam: https://examcollection.prep4sureguide.com/8020-prep4sure-exam-guide.html