CBO Regulatory Compliance & Risk Management 2 — Questions and Answers
Question 1: A business discovers a data breach affecting 600 customers in California. Under CCPA, what is the required notification timeline?
- Immediately upon discovery
- Within 30 days
- Within 72 hours
- In the most expedient time possible without unreasonable delay (Correct answer)
Correct answer: In the most expedient time possible without unreasonable delay
California's CCPA requires notification in the most expedient time possible without unreasonable delay, though no specific day count is mandated.
Question 2: Which risk management strategy involves purchasing insurance to cover potential losses?
- Risk avoidance
- Risk reduction
- Risk transfer (Correct answer)
- Risk acceptance
Correct answer: Risk transfer
Risk transfer shifts the financial burden of a loss to a third party, such as an insurer, in exchange for a premium.
Question 3: A manufacturing company must maintain OSHA Form 300 logs. How long must these records be retained?
- 1 year
- 3 years
- 5 years (Correct answer)
- 10 years
Correct answer: 5 years
OSHA requires employers to retain Form 300 injury and illness logs for five years following the end of the calendar year that records cover.
Question 4: Under the Americans with Disabilities Act (ADA), which business type is generally required to provide reasonable accommodations to employees?
- Businesses with 5 or more employees
- Businesses with 10 or more employees
- Businesses with 15 or more employees (Correct answer)
- All businesses regardless of size
Correct answer: Businesses with 15 or more employees
Title I of the ADA applies to employers with 15 or more employees, requiring reasonable accommodations for qualified individuals with disabilities.
Question 5: What is the primary purpose of an internal audit function within a compliance program?
- To prepare tax filings for regulators
- To independently assess whether controls are operating effectively (Correct answer)
- To negotiate penalties with regulatory agencies
- To create marketing materials about compliance
Correct answer: To independently assess whether controls are operating effectively
Internal audit independently evaluates whether a company's risk controls and compliance processes are functioning as intended.
Question 6: A company operates in multiple states with different minimum wage laws. Which minimum wage rate must it pay employees?
- Always the federal minimum wage
- The lower of federal or state minimum wage
- The higher of federal or state minimum wage (Correct answer)
- The average of all applicable rates
Correct answer: The higher of federal or state minimum wage
Employers must pay the higher of the applicable federal, state, or local minimum wage to ensure compliance with all governing laws.
Question 7: Which document formally defines the scope, objectives, and responsibilities of a company's compliance program?
- Employee handbook
- Compliance charter or program document (Correct answer)
- Articles of incorporation
- Operating agreement
Correct answer: Compliance charter or program document
A compliance charter or program document establishes the structure, authority, and responsibilities of the compliance function within an organization.
A business discovers a data breach affecting 600 customers in California.
Under CCPA, what is the required notification timeline?