CBA Internal Controls & Compliance 2 — Questions and Answers
Question 1: Which control activity best addresses the risk of unauthorized access to a bank's core banking system?
- Dual-control procedures
- Role-based access controls with periodic user access reviews (Correct answer)
- Mandatory vacation policies
- Transaction velocity limits
Correct answer: Role-based access controls with periodic user access reviews
Role-based access controls limit system access to job-relevant functions, and periodic reviews ensure access remains appropriate as roles change.
Question 2: Under COSO's Internal Control—Integrated Framework, which component involves an organization's values, ethics, and operating style?
- Risk Assessment
- Control Environment (Correct answer)
- Monitoring Activities
- Information & Communication
Correct answer: Control Environment
The Control Environment is the foundation of internal control and encompasses the organization's tone, values, ethical standards, and management philosophy.
Question 3: A bank's BSA/AML compliance program must include all of the following EXCEPT:
- A designated compliance officer
- Board-approved written policies and procedures
- Annual external audits of all loan files (Correct answer)
- Ongoing employee training
Correct answer: Annual external audits of all loan files
The four pillars of a BSA/AML program are: internal controls, a designated compliance officer, training, and independent testing—not annual external loan file audits specifically.
Question 4: What is the primary purpose of a bank's Suspicious Activity Report (SAR) filing requirement?
- To notify customers of potential fraud against their accounts
- To inform law enforcement of potential money laundering or criminal activity (Correct answer)
- To document internal control deficiencies
- To report credit losses to the FDIC
Correct answer: To inform law enforcement of potential money laundering or criminal activity
SARs are filed with FinCEN to alert law enforcement of transactions that may involve money laundering, fraud, or other criminal activity.
Question 5: During a compliance review, an auditor finds that a branch has been waiving overdraft fees for preferred customers without documented approval. This is BEST classified as:
- A credit risk issue
- A fair lending and consumer compliance concern (Correct answer)
- An operational efficiency problem
- A capital adequacy matter
Correct answer: A fair lending and consumer compliance concern
Inconsistent fee waivers for select customers without documented criteria can indicate discriminatory practices, violating fair lending laws such as the Equal Credit Opportunity Act.
Question 6: Which control is MOST effective in preventing a teller from both initiating and approving their own cash transactions?
- Fidelity bonding
- Separation of duties (Correct answer)
- Dual control over the vault
- Surprise cash counts
Correct answer: Separation of duties
Separation of duties ensures no single individual can initiate, approve, and record a transaction, reducing the risk of fraud or error.
Question 7: A bank auditor is assessing the effectiveness of the institution's interest rate risk controls. Which document is MOST relevant to this review?
- The bank's BSA/AML policy
- The Asset/Liability Management (ALM) policy (Correct answer)
- The customer complaint log
- The employee code of conduct
Correct answer: The Asset/Liability Management (ALM) policy
The ALM policy governs how the bank manages interest rate risk, including limits, measurement methods, and reporting requirements.
Which control activity best addresses the risk of unauthorized access to a bank's core banking system?