
Ultimate access to all questions.
An operational risk manager at a large retail bank is asked to review the framework for the bank's risk mitigation controls. As part of this review, the manager classifies the risk controls as preventive, detective, corrective, or directive. Which of the following should the manager classify as a directive control?
A
An employee training program that explains the policies and procedures for reviewing new account applications
B
A notification to a credit card customer about a potentially fraudulent transaction on that customer's account
C
An implementation of an antivirus software update across all of the bank's IT systems
D
A dual-factor authentication protocol that is used to control access to critical business systems