CBO Regulatory Compliance & Risk Management 3 — Questions and Answers
Question 1: What does the term 'inherent risk' mean in the context of enterprise risk management?
- Risk remaining after controls are applied
- Risk that exists before any mitigating controls are in place (Correct answer)
- Risk transferred to a third party
- Risk accepted by the board of directors
Correct answer: Risk that exists before any mitigating controls are in place
Inherent risk is the level of risk present in a business activity before any controls or mitigation measures are implemented.
Question 2: Under the Fair Labor Standards Act (FLSA), what is the standard overtime threshold for non-exempt employees?
- More than 35 hours per week
- More than 40 hours per week (Correct answer)
- More than 45 hours per week
- More than 50 hours per week
Correct answer: More than 40 hours per week
The FLSA requires overtime pay at 1.5 times the regular rate for non-exempt employees who work more than 40 hours in a workweek.
Question 3: A business wants to reduce its regulatory compliance risk by simplifying its product line. This is an example of which risk response?
- Risk transfer
- Risk acceptance
- Risk avoidance (Correct answer)
- Risk mitigation
Correct answer: Risk avoidance
Risk avoidance eliminates exposure by exiting or not entering an activity that carries the risk, such as discontinuing a heavily regulated product.
Question 4: Which federal agency enforces workplace safety and health standards in the United States?
- EPA
- EEOC
- OSHA (Correct answer)
- FTC
Correct answer: OSHA
The Occupational Safety and Health Administration (OSHA) enforces federal workplace safety and health regulations.
Question 5: A risk heat map is most useful for which of the following purposes?
- Calculating exact financial losses from a risk event
- Visually prioritizing risks by likelihood and impact (Correct answer)
- Filing regulatory reports with government agencies
- Determining insurance premium amounts
Correct answer: Visually prioritizing risks by likelihood and impact
A risk heat map plots risks on a matrix of probability versus impact, helping management visually prioritize which risks deserve the most attention.
Question 6: What is the main goal of a whistleblower protection policy within a compliance program?
- To discourage employees from contacting regulators directly
- To encourage reporting of violations without fear of retaliation (Correct answer)
- To limit management liability for employee misconduct
- To document disciplinary actions taken against employees
Correct answer: To encourage reporting of violations without fear of retaliation
Whistleblower protection policies create a safe channel for employees to report suspected violations without risking job loss or other retaliation.
Question 7: Under the Sarbanes-Oxley Act (SOX), who is ultimately responsible for the accuracy of a public company's financial statements?
- The external auditor
- The audit committee chair
- The CEO and CFO (Correct answer)
- The board of directors as a whole
Correct answer: The CEO and CFO
SOX Section 302 requires the CEO and CFO to personally certify the accuracy and completeness of the company's financial reports.
What does the term 'inherent risk' mean in the context of enterprise risk management?