CBA Regulatory Compliance Audits Questions and Answers 1 — Questions and Answers
Question 1: An auditor reviewing a bank's compliance with the Bank Secrecy Act (BSA) discovers a pattern of cash deposits into a single account across multiple branches on the same day, with each deposit being slightly under the $10,000 reporting threshold. This activity is a significant indicator of:
- Kiting
- Structuring (Correct answer)
- Redlining
- Wash trading
Correct answer: Structuring
Structuring involves intentionally breaking up a large cash transaction into smaller, individual transactions to fall below the Currency Transaction Report (CTR) reporting threshold of $10,000, for the purpose of evading BSA reporting requirements. A bank must file a SAR when it suspects structuring.
Question 2: Which of the following is the primary objective of a compliance audit focused on the Community Reinvestment Act (CRA)?
- To ensure the bank has adequate controls to prevent money laundering and terrorist financing.
- To verify that the bank is not engaging in predatory lending practices in any of its operating areas.
- To assess whether the bank is effectively meeting the credit needs of its entire community, including low- and moderate-income neighborhoods. (Correct answer)
- To confirm the accuracy and timeliness of the bank's quarterly financial reports to shareholders.
Correct answer: To assess whether the bank is effectively meeting the credit needs of its entire community, including low- and moderate-income neighborhoods.
The Community Reinvestment Act (CRA) was enacted to encourage federally insured banks to meet the credit needs of their entire communities, with a particular focus on low- and moderate-income (LMI) neighborhoods. A CRA audit evaluates the bank's performance in lending, investments, and services within these communities.
Question 3: During a review of a bank's Identity Theft Prevention Program, an auditor is primarily concerned with compliance with the rules promulgated under which act?
- Gramm-Leach-Bliley Act (GLBA)
- Bank Secrecy Act (BSA)
- Fair and Accurate Credit Transactions Act (FACTA) (Correct answer)
- Truth in Lending Act (TILA)
Correct answer: Fair and Accurate Credit Transactions Act (FACTA)
The Fair and Accurate Credit Transactions Act (FACTA) amended the Fair Credit Reporting Act (FCRA) and required the implementation of the "Red Flags Rules." These rules mandate that financial institutions and creditors develop and implement a written Identity Theft Prevention Program to detect, prevent, and mitigate identity theft.
Question 4: A bank's marketing department launches a campaign for a new savings account, advertising it as "Completely Free." An auditor's review finds that while there are no monthly maintenance fees, a fee is charged if the account balance drops below $100. This practice would most likely be a violation of which regulation?
- Regulation Z (Truth in Lending)
- Regulation DD (Truth in Savings) (Correct answer)
- Regulation CC (Expedited Funds Availability)
- Regulation E (Electronic Fund Transfers)
Correct answer: Regulation DD (Truth in Savings)
Regulation DD, which implements the Truth in Savings Act (TISA), prohibits advertisements that are misleading or inaccurate. It specifically prohibits describing an account as "free" or "no cost" if any maintenance or activity fee, such as a fee for failing to maintain a minimum balance, can be imposed.
Question 5: When performing a regulatory compliance audit of the Gramm-Leach-Bliley Act (GLBA), which of the following is the auditor's MOST critical area of focus?
- Ensuring the timely and accurate filing of Currency Transaction Reports.
- Verifying that all loan disclosures provide a clear Annual Percentage Rate (APR).
- Evaluating the adequacy of the bank's program to protect the confidentiality and security of customers' nonpublic personal information. (Correct answer)
- Assessing the bank's efforts to provide credit services to all segments of its community.
Correct answer: Evaluating the adequacy of the bank's program to protect the confidentiality and security of customers' nonpublic personal information.
The Gramm-Leach-Bliley Act (GLBA) has two main components: the Privacy Rule and the Safeguards Rule. The Safeguards Rule is a critical focus for auditors, as it requires financial institutions to develop, implement, and maintain a comprehensive written information security program to protect nonpublic customer information.
Question 6: In the initial planning phase of a compliance audit, what is the auditor's MOST important first step?
- Requesting and reviewing all prior audit reports and regulatory examination findings.
- Developing the detailed audit program and testing procedures.
- Conducting preliminary interviews with department heads and key personnel.
- Performing a comprehensive risk assessment to identify the laws and regulations applicable to the bank's operations and products. (Correct answer)
Correct answer: Performing a comprehensive risk assessment to identify the laws and regulations applicable to the bank's operations and products.
The foundational step in planning a compliance audit is to understand the bank's compliance risk profile. This involves performing a risk assessment to identify all applicable laws, regulations, and internal policies related to the bank's products, services, and operations to determine the audit's scope and priorities. Reviewing prior reports and interviewing staff are subsequent steps that build upon this initial risk assessment.
An auditor reviewing a bank's compliance with the Bank Secrecy Act (BSA) discovers a pattern of cash deposits into a single account across multiple branches on the same day, with each deposit being slightly under the $10,000 reporting threshold.
This activity is a significant indicator of: