CBO Regulatory Compliance & Risk Management 4 — Questions and Answers
Question 1: Which regulatory framework specifically governs the privacy of protected health information (PHI) in the United States?
- GDPR
- SOX
- HIPAA (Correct answer)
- FCRA
Correct answer: HIPAA
The Health Insurance Portability and Accountability Act (HIPAA) establishes national standards for protecting the privacy and security of protected health information.
Question 2: A business identifies that a critical supplier has no business continuity plan. This represents which type of risk?
- Credit risk
- Third-party or supply chain risk (Correct answer)
- Market risk
- Regulatory risk
Correct answer: Third-party or supply chain risk
Supply chain or third-party risk arises when an external vendor's failure or disruption can negatively impact the company's own operations.
Question 3: Which document outlines the procedures employees must follow to report suspected compliance violations?
- Employee Non-Disclosure Agreement
- Code of Conduct or Ethics Hotline Policy (Correct answer)
- Organizational chart
- Strategic plan
Correct answer: Code of Conduct or Ethics Hotline Policy
A code of conduct or ethics hotline policy details how employees should report suspected violations, including anonymous reporting options.
Question 4: Under the Equal Employment Opportunity (EEO) laws, which of the following is NOT a protected class at the federal level?
- National origin
- Religion
- Political affiliation (Correct answer)
- Sex
Correct answer: Political affiliation
Federal EEO laws protect race, color, religion, sex, national origin, age, disability, and genetic information, but political affiliation is not a federally protected class.
Question 5: What is the purpose of a compliance risk assessment?
- To determine the company's tax liability
- To identify, evaluate, and prioritize regulatory and legal risks facing the business (Correct answer)
- To assess the financial performance of the compliance department
- To compare compliance costs with competitors
Correct answer: To identify, evaluate, and prioritize regulatory and legal risks facing the business
A compliance risk assessment systematically identifies and evaluates the legal and regulatory risks an organization faces so resources can be allocated appropriately.
Question 6: A company's board of directors sets the organization's 'risk appetite.' What does this term mean?
- The maximum loss the company can sustain before bankruptcy
- The amount and type of risk the organization is willing to accept in pursuit of its objectives (Correct answer)
- The total value of the company's insurance coverage
- The number of regulatory violations permitted per year
Correct answer: The amount and type of risk the organization is willing to accept in pursuit of its objectives
Risk appetite is the level and type of risk an organization is prepared to accept, tolerate, or be exposed to in pursuit of its strategic goals.
Question 7: Which of the following best describes a 'key risk indicator' (KRI)?
- A financial ratio used in loan applications
- A metric that provides an early warning signal that risk is increasing (Correct answer)
- A summary of past losses from risk events
- A regulatory penalty issued by a government agency
Correct answer: A metric that provides an early warning signal that risk is increasing
KRIs are forward-looking metrics that signal when risk levels are rising, enabling proactive management before a risk event occurs.
Which regulatory framework specifically governs the privacy of protected health information (PHI) in the United States?