BCI Regulatory Compliance & Legal Framework 3 — Questions and Answers
Question 1: A financial services firm operating in both New York and California must comply with both NYDFS 23 NYCRR 500 and CCPA. Which approach BEST addresses dual compliance?
- Comply only with NYDFS as it is more stringent
- Implement the stricter requirement of each regulation across all operations (Correct answer)
- Create entirely separate programs for each state
- Apply CCPA company-wide since it covers more data types
Correct answer: Implement the stricter requirement of each regulation across all operations
Organizations subject to multiple regulations should implement the most stringent applicable requirement per control area to achieve compliance with all frameworks simultaneously.
Question 2: What is the primary purpose of a regulatory horizon scanning process within a BC program?
- To identify upcoming regulatory changes that may affect BC obligations before they take effect (Correct answer)
- To monitor competitor compliance postures
- To track enforcement actions against peer organizations
- To schedule regulatory examinations
Correct answer: To identify upcoming regulatory changes that may affect BC obligations before they take effect
Horizon scanning proactively identifies forthcoming regulations so the BC program can adapt before compliance deadlines arrive.
Question 3: Under the Dodd-Frank Act, which entity has authority to require systemically important financial institutions (SIFIs) to maintain recovery and resolution plans?
- FDIC and Federal Reserve jointly (Correct answer)
- OCC alone
- CFPB
- SEC
Correct answer: FDIC and Federal Reserve jointly
The FDIC and Federal Reserve jointly administer the 'living will' requirements for SIFIs under Title I of Dodd-Frank.
Question 4: Which clause in a vendor contract limits the vendor's liability for BC failures to a defined monetary cap?
- Force majeure clause
- Limitation of liability clause (Correct answer)
- Indemnification clause
- Liquidated damages clause
Correct answer: Limitation of liability clause
A limitation of liability clause caps the maximum financial exposure a vendor bears for failures, including BC-related service outages.
Question 5: The CPS 232 standard, which mandates operational risk and business continuity requirements, applies primarily to regulated entities in which country?
- United Kingdom
- Canada
- Australia (Correct answer)
- Singapore
Correct answer: Australia
CPS 232 is an Australian Prudential Regulation Authority (APRA) standard requiring authorized deposit-taking institutions and insurers to maintain robust BC capabilities.
Question 6: An organization's BCP must be reviewed after a regulatory change. Who is ultimately accountable for ensuring the review occurs?
- The BC Manager
- The IT Director
- Senior management or the Board (Correct answer)
- The external auditor
Correct answer: Senior management or the Board
Governance frameworks universally assign ultimate accountability for BC program adequacy to senior management or the Board, not operational staff.
Question 7: Which U.S. Executive Order framework established the basis for critical infrastructure protection and sector-specific BC requirements across 16 sectors?
- EO 13636 / PPD-21 (Correct answer)
- EO 12333
- EO 13691
- EO 14028
Correct answer: EO 13636 / PPD-21
EO 13636 and PPD-21 (Presidential Policy Directive 21) together established the framework for critical infrastructure cybersecurity and resilience across 16 designated sectors.
A financial services firm operating in both New York and California must comply with both NYDFS 23 NYCRR 500 and CCPA.
Which approach BEST addresses dual compliance?