CCB Certified Compliance and Business Specialist (CCB) — Questions and Answers
Question 1: A contractor submits a Request for Equitable Adjustment (REA) after the government changes the contract scope. What is the contractor claiming?
- An exemption from audit requirements
- A waiver of all future performance obligations
- Compensation for increased costs or time caused by a government-directed change (Correct answer)
- The right to terminate the contract immediately
Correct answer: Compensation for increased costs or time caused by a government-directed change
An REA is a contractor's formal request to adjust price, schedule, or both to account for increased costs or time resulting from a government-directed change.
Question 2: What is the purpose of audit documentation?
- To store employee records.
- To replace management reports.
- To promote secrecy.
- To provide proof of audit work and conclusions (Correct answer)
Correct answer: To provide proof of audit work and conclusions
Audit documentation serves as the official record of the audit work performed, the evidence gathered, and the conclusions reached by the auditor. It provides a basis for the auditor's report, demonstrating that the audit was conducted in accordance with professional standards and supporting the auditor's findings and recommendations. This documentation is crucial for accountability, quality review, and future reference.
Question 3: An auditor identifies that a single employee handles purchasing, receiving, and payment approval. This is best described as a:
- Segregation of duties weakness (Correct answer)
- Monitoring control failure
- Authorization control deficiency
- IT access control gap
Correct answer: Segregation of duties weakness
Segregation of duties requires that incompatible functions — such as authorizing, recording, and custody — be assigned to different individuals to reduce fraud risk.
Question 4: A bank deploys an AI model to make credit decisions. Under the Equal Credit Opportunity Act (ECOA), what must the bank be able to provide to a denied applicant?
- The model's source code
- The full dataset used to train the model
- Specific reasons for the adverse action (Correct answer)
- A manual review option only
Correct answer: Specific reasons for the adverse action
ECOA requires creditors to provide specific reasons for adverse action, which means AI credit models must be explainable enough to generate meaningful reason codes.
Question 5: Who is responsible for enforcing policies?
- External vendors.
- Customers.
- IT department only.
- Managers and supervisors (Correct answer)
Correct answer: Managers and supervisors
While top management establishes policies, managers and supervisors are primarily responsible for their day-to-day enforcement. They communicate policies to their teams, provide guidance, monitor compliance, and address non-adherence. Their direct oversight ensures that policies are consistently applied and integrated into operational practices, making them crucial links in the compliance chain.
Question 6: The concept of 'greenwashing' in the context of business ethics refers to:
- Hiring external consultants to conduct environmental audits
- Making misleading claims about the environmental benefits of products or practices to appear more sustainable (Correct answer)
- Using green-colored branding on environmentally compliant products
- Obtaining green building certifications for corporate headquarters
Correct answer: Making misleading claims about the environmental benefits of products or practices to appear more sustainable
Greenwashing involves companies overstating or fabricating environmental credentials to exploit consumer and investor interest in sustainability without genuine action.
Question 7: Which standard-setting body issues the International Standards for the Professional Practice of Internal Auditing?
- IIA (Institute of Internal Auditors) (Correct answer)
- ISACA
- PCAOB
- AICPA
Correct answer: IIA (Institute of Internal Auditors)
The Institute of Internal Auditors (IIA) publishes the International Standards for the Professional Practice of Internal Auditing, the globally recognized framework for internal audit.
Question 8: Which approach does SupTech (Supervisory Technology) represent from a regulator's perspective?
- Technology used by regulators to supervise financial institutions more efficiently (Correct answer)
- Software for managing compliance training programs
- A cybersecurity framework for regulatory data
- Technology that firms use to comply with regulations
Correct answer: Technology used by regulators to supervise financial institutions more efficiently
SupTech refers to technology adopted by regulators and supervisory authorities to enhance their ability to monitor, analyze, and enforce compliance across regulated entities.
Question 9: What is the primary compliance obligation of employers under the Consolidated Omnibus Budget Reconciliation Act (COBRA)?
- Offering continuation of group health coverage to eligible former employees and dependents (Correct answer)
- Providing severance pay upon termination
- Contributing to employee retirement accounts
- Providing paid family leave
Correct answer: Offering continuation of group health coverage to eligible former employees and dependents
COBRA requires employers with 20 or more employees to offer continuation of group health insurance coverage to employees and their families who lose coverage due to qualifying events such as termination or reduced hours.
Question 10: During implementation, employees report that a new travel expense policy is unclear. The compliance team should FIRST:
- Issue an FAQ or supplemental guidance document to clarify intent (Correct answer)
- Transfer the policy to the legal department for rewriting
- Discipline employees who ask questions
- Immediately rescind the policy and start over
Correct answer: Issue an FAQ or supplemental guidance document to clarify intent
Supplemental guidance or FAQs are a quick, practical way to resolve ambiguity without the formal process of revising the entire policy.
Question 11: Which stakeholder group is MOST critical to engage during the policy development phase to ensure operational feasibility?
- Board of directors only
- Customers and vendors
- Front-line managers and subject matter experts (Correct answer)
- External auditors
Correct answer: Front-line managers and subject matter experts
Front-line managers and SMEs understand day-to-day operations and can identify practical barriers before a policy is finalized.
Question 12: A 'control gap' is BEST described as:
- A difference between budgeted and actual expenses
- A situation where no control exists or existing controls are insufficient to mitigate a risk (Correct answer)
- A finding noted in a prior audit that was corrected
- An unreconciled balance in the general ledger
Correct answer: A situation where no control exists or existing controls are insufficient to mitigate a risk
A control gap exists when the level of risk is not adequately addressed by existing controls, leaving the organization exposed to potential losses or misstatements.
Question 13: In the context of CCB certification, what is the most important consideration when implementing compliance technology & regtech?
- Completing implementation as quickly as possible regardless of quality
- Delegating all responsibilities to junior staff
- Ensuring alignment with established standards, stakeholder needs, and best practices (Correct answer)
- Minimizing documentation to save time
Correct answer: Ensuring alignment with established standards, stakeholder needs, and best practices
When implementing compliance technology & regtech, CCB professionals must ensure alignment with industry standards and stakeholder needs. Hasty implementation without proper planning often leads to compliance issues and suboptimal outcomes.
Question 14: Who is responsible for establishing internal controls?
- Marketing department.
- External auditors.
- Management (Correct answer)
- Shareholders.
Correct answer: Management
Management is primarily responsible for establishing, implementing, and maintaining an effective system of internal controls within an organization. They are accountable for designing controls that address identified risks, ensuring that employees understand and adhere to them, and regularly monitoring their effectiveness. While the board oversees, management is hands-on in their creation and daily operation.
Question 15: Under HIPAA, which rule specifically governs the security of electronic protected health information (ePHI)?
- The Security Rule (Correct answer)
- The Omnibus Rule
- The Breach Notification Rule
- The Privacy Rule
Correct answer: The Security Rule
The HIPAA Security Rule establishes national standards to protect individuals' electronic protected health information through administrative, physical, and technical safeguards.
Question 16: Which element is NOT typically required for a False Claims Act whistleblower suit to proceed?
- The complaint must be filed under seal initially
- The relator must first exhaust internal reporting channels (Correct answer)
- The fraudulent claim must involve federal government funds
- The relator must have original source information
Correct answer: The relator must first exhaust internal reporting channels
The FCA does not require relators to exhaust internal reporting channels before filing; however, prior public disclosure may bar claims unless the relator is an original source.
Question 17: How can policy effectiveness be measured?
- By counting team lunches.
- By analyzing results and compliance (Correct answer)
- By monitoring social media likes.
- By checking email volume.
Correct answer: By analyzing results and compliance
To measure policy effectiveness, an organization must assess whether the policy is achieving its intended outcomes and if employees are adhering to its requirements. This involves collecting data, analyzing key performance indicators, monitoring compliance rates, and evaluating the impact of the policy on relevant processes or behaviors. Such analysis helps determine if the policy is working as intended or if revisions are needed.
Question 18: A compliance officer learns that a division head has been falsifying expense reports but is also the company's top revenue generator. The ethical response is:
- Apply the same disciplinary process used for any other employee (Correct answer)
- Transfer the executive to a role with fewer expense privileges
- Overlook the violation given the executive's value to the company
- Conduct a confidential review only if the amounts exceed $10,000
Correct answer: Apply the same disciplinary process used for any other employee
Ethical governance requires consistent application of policies regardless of an individual's status or contribution to company revenue.
Question 19: Which of the following best describes the primary purpose of a third-party risk management (TPRM) program in a compliance context?
- To negotiate lower contract prices with vendors
- To eliminate the use of all external vendors wherever possible
- To transfer all liability for compliance failures to third-party vendors
- To identify, assess, and mitigate risks posed by external parties that have access to company data, systems, or operations (Correct answer)
Correct answer: To identify, assess, and mitigate risks posed by external parties that have access to company data, systems, or operations
A TPRM program is designed to systematically identify, assess, and mitigate the compliance, operational, and reputational risks that arise when third parties have access to an organization's data, systems, or business operations.
Question 20: Key risk indicators (KRIs) are BEST described as:
- Forward-looking metrics that signal increasing risk exposure (Correct answer)
- Metrics used to detect past control failures
- Audit findings from the previous year
- Regulatory thresholds for acceptable loss
Correct answer: Forward-looking metrics that signal increasing risk exposure
KRIs are predictive metrics that alert management to rising risk levels before they result in control failures or losses.
Question 21: A board audit committee asks for a 'heat map' in the compliance report. What does this typically display?
- Geographic distribution of employees
- Regulatory filing deadlines
- Training completion rates by department
- Risks plotted by likelihood and impact (Correct answer)
Correct answer: Risks plotted by likelihood and impact
A risk heat map visually represents risks on a matrix of likelihood versus impact to help the board prioritize oversight.
Question 22: Under the Uyghur Forced Labor Prevention Act (UFLPA), imports from the Xinjiang region of China are subject to which presumption?
- Presumed compliant with labor standards unless challenged by a competitor
- Presumed to be made with forced labor and prohibited unless the importer rebuts the presumption with clear and convincing evidence (Correct answer)
- Automatically subject to a 25% tariff but permitted to enter the US
- Subject to mandatory third-party audits before clearance
Correct answer: Presumed to be made with forced labor and prohibited unless the importer rebuts the presumption with clear and convincing evidence
The UFLPA creates a rebuttable presumption that goods produced in Xinjiang or by certain entities involve forced labor, shifting the burden to importers to prove otherwise.
Question 23: Which metric is MOST useful for measuring policy implementation effectiveness?
- The number of pages in the policy document
- The speed at which the policy was approved by leadership
- Employee policy acknowledgment rates combined with audit finding trends (Correct answer)
- The cost of printing and distributing the policy
Correct answer: Employee policy acknowledgment rates combined with audit finding trends
Acknowledgment rates confirm awareness, while audit finding trends reveal whether the policy is actually changing behavior and reducing violations.
Question 24: In an IT environment, which control ensures that only authorized users can access sensitive financial data?
- Backup and recovery procedures
- User access management controls (Correct answer)
- Network perimeter firewall
- Data encryption at rest
Correct answer: User access management controls
User access management controls, including role-based access and periodic access reviews, ensure that only authorized individuals can view or modify sensitive data.
Question 25: A compliance officer reviews a vendor's SOC 2 Type II report. What does this report specifically attest to?
- The vendor's financial solvency
- The vendor's compliance with AML regulations
- The accuracy of the vendor's marketing claims
- The operating effectiveness of the vendor's controls over a defined period, typically 6-12 months (Correct answer)
Correct answer: The operating effectiveness of the vendor's controls over a defined period, typically 6-12 months
A SOC 2 Type II report provides independent attestation that a vendor's security, availability, and confidentiality controls operated effectively over a sustained review period.
Question 26: Which FinCEN form must banks file within 30 calendar days of detecting a suspicious transaction?
- Foreign Bank Account Report (FBAR)
- Form 8300
- Suspicious Activity Report (SAR) (Correct answer)
- Currency Transaction Report (CTR)
Correct answer: Suspicious Activity Report (SAR)
Banks must file a Suspicious Activity Report (SAR) with FinCEN within 30 calendar days of detecting suspicious activity.
Question 27: What is a policy review?
- Delaying all updates indefinitely.
- Updating policies for clarity and accuracy (Correct answer)
- Ignoring employee feedback.
- Deleting policies without review.
Correct answer: Updating policies for clarity and accuracy
A policy review is a systematic process of examining existing policies to ensure they remain relevant, accurate, clear, and effective. This involves assessing whether the policy still meets its objectives, complies with current laws and regulations, and addresses evolving organizational needs. Regular reviews are essential for maintaining the integrity and utility of the policy framework.
Question 28: Under the EU AI Act, compliance AI systems classified as 'high-risk' are required to have which of the following?
- Annual third-party algorithm audits only
- Open-source code availability
- Human oversight mechanisms and detailed documentation (Correct answer)
- Real-time government access to system outputs
Correct answer: Human oversight mechanisms and detailed documentation
The EU AI Act mandates that high-risk AI systems include human oversight mechanisms, maintain detailed technical documentation, and undergo conformity assessments.
Question 29: A compliance program that relies solely on automated transaction monitoring without human review is MOST deficient in which area?
- Recordkeeping
- Independent testing
- Customer identification
- Contextual analysis and judgment (Correct answer)
Correct answer: Contextual analysis and judgment
Automated systems lack the contextual judgment needed to evaluate complex customer relationships and emerging typologies, requiring human analyst review.
Question 30: What is the primary risk of having too many overlapping or redundant policies in an organization?
- Increased audit costs for external reviewers
- Policies become too long to fit in a single document management system
- Confusion, inconsistent enforcement, and compliance fatigue among employees (Correct answer)
- Regulators will penalize the organization for over-compliance
Correct answer: Confusion, inconsistent enforcement, and compliance fatigue among employees
Redundant policies create contradictions, make it harder for employees to know which rule applies, and reduce overall compliance culture effectiveness.
Question 31: Which approach involves auditors tracing a transaction from initiation through completion to understand the control environment?
- Analytical review
- Substantive testing
- Observation
- Walkthrough (Correct answer)
Correct answer: Walkthrough
A walkthrough traces one or more transactions from start to finish to help auditors understand how controls operate in practice.
Question 32: A 'policy attestation' process requires employees to:
- Submit anonymous feedback about a policy's practicality
- Vote on whether a policy should be approved or rejected
- Formally acknowledge that they have read, understood, and will comply with a policy (Correct answer)
- Rewrite the policy in their own words and submit it to HR
Correct answer: Formally acknowledge that they have read, understood, and will comply with a policy
Policy attestation creates a documented record of employee acknowledgment, which is essential evidence of a compliance program's communication efforts.
Question 33: A RegTech system flags a customer as high-risk based on an algorithmic score. The compliance officer disagrees. What governance principle requires documentation of this override?
- Dual control procedures
- Know Your Customer rule
- Segregation of duties
- Human-in-the-loop accountability and audit trail requirements (Correct answer)
Correct answer: Human-in-the-loop accountability and audit trail requirements
When humans override automated compliance decisions, accountability frameworks require documenting the rationale to maintain a complete and auditable record of compliance judgments.
Question 34: What is the main goal of internal auditing?
- To approve marketing materials.
- To manage payroll.
- To monitor social media.
- To assess risks and improve processes (Correct answer)
Correct answer: To assess risks and improve processes
The main goal of internal auditing is to provide independent, objective assurance and consulting services designed to add value and improve an organization's operations. Internal auditors achieve this by evaluating the effectiveness of risk management, control, and governance processes. Their work helps identify weaknesses, recommend improvements, and ensure compliance, ultimately enhancing the organization's ability to achieve its objectives.
Question 35: Why is communication vital during policy implementation?
- To confuse stakeholders.
- To ensure understanding and compliance (Correct answer)
- To limit questions.
- To delay enforcement.
Correct answer: To ensure understanding and compliance
Effective communication during policy implementation is crucial because it ensures that all stakeholders are aware of the new or updated policy, understand its purpose, and know what is expected of them. Clear and consistent communication helps to clarify any ambiguities, address concerns, and foster buy-in, which is essential for achieving widespread compliance and successful policy adoption.
Question 36: How should CCB professionals handle confidential information related to contract compliance & management?
- Delete all records after project completion
- Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations (Correct answer)
- Share freely with all colleagues for transparency
- Store information without any security measures
Correct answer: Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations
Confidential information must be handled according to established protocols, regulatory requirements, and professional ethics standards, including proper access control and disclosure procedures.
Question 37: A compliance officer must ensure third-party RegTech vendors meet the firm's data security standards. What document BEST formalizes these requirements?
- A non-disclosure agreement (NDA)
- A letter of intent from the vendor
- An internal compliance policy update
- A vendor due diligence questionnaire and contractual data processing agreement (Correct answer)
Correct answer: A vendor due diligence questionnaire and contractual data processing agreement
A vendor due diligence questionnaire assesses security capabilities while a data processing agreement legally obligates the vendor to meet required security standards.
Question 38: A company's board has approved a new data retention policy but the IT department reports it is technically impossible to implement as written. The compliance officer should:
- Implement the policy and document the inability to comply as a known gap
- Withdraw the policy and abandon data retention compliance entirely
- Ignore the IT feedback and proceed with implementation
- Facilitate a revision process involving IT, legal, and compliance to make the policy operationally viable (Correct answer)
Correct answer: Facilitate a revision process involving IT, legal, and compliance to make the policy operationally viable
Policies must be operationally feasible; a cross-functional revision process ensures the policy achieves its compliance objective within technical constraints.
Question 39: A compliance manager is building a policy for insider trading prevention. Which control is MOST critical to include in the implementation plan?
- A policy limiting the number of stock exchanges employees may use
- Mandatory blackout periods, pre-clearance procedures, and annual training for covered persons (Correct answer)
- A requirement that all employees take a photography course
- A ban on employees owning any personal investment accounts
Correct answer: Mandatory blackout periods, pre-clearance procedures, and annual training for covered persons
Blackout periods, pre-clearance, and training are the core controls required by securities laws and SEC guidance to prevent and detect insider trading.
Question 40: Which RegTech capability is MOST useful for automating the mapping of internal controls to multiple regulatory frameworks simultaneously?
- Regulatory change management software with cross-framework tagging (Correct answer)
- Robotic process automation
- Cloud-based document storage
- Blockchain ledger systems
Correct answer: Regulatory change management software with cross-framework tagging
Regulatory change management software with cross-framework tagging allows a single control to be mapped to multiple regulations, reducing duplication and effort.
Question 41: A board member discovers that a major supplier is violating environmental regulations but the violations reduce costs significantly. What is the most ethically sound course of action?
- Continue using the supplier since it benefits shareholders
- Disclose the situation only to senior management and take no further action
- Report the violations to regulators and end the supplier relationship (Correct answer)
- Negotiate with the supplier to internalize the violations
Correct answer: Report the violations to regulators and end the supplier relationship
Ethical corporate governance requires reporting legal violations and ceasing relationships with non-compliant suppliers, regardless of cost benefits.
Question 42: Which report do publicly traded companies use to disclose material events between quarterly SEC filings?
- Form 10-Q amendment
- Form 8-K (Correct answer)
- Schedule TO
- Form NT 10-Q
Correct answer: Form 8-K
Form 8-K is the current report that public companies must file with the SEC to disclose material corporate events between quarterly or annual filings.
Question 43: A RegTech vendor claims their AML screening tool uses machine learning to reduce false positives by 60%. What should a compliance officer do BEFORE deploying it?
- Submit the tool to the regulator for pre-approval
- Accept the vendor's claim and proceed to deployment
- Require the vendor to share their training data only
- Validate the claim using the firm's own data in a controlled pilot (Correct answer)
Correct answer: Validate the claim using the firm's own data in a controlled pilot
Vendor claims must be independently validated using the firm's own data and transaction patterns before relying on the tool for compliance purposes.
Question 44: Which compliance challenge does 'federated learning' help address in financial services?
- Automating suspicious activity reports
- Managing multi-jurisdictional regulatory filings
- Standardizing KYC documentation formats
- Training AI models on sensitive data across institutions without sharing raw data (Correct answer)
Correct answer: Training AI models on sensitive data across institutions without sharing raw data
Federated learning allows AI models to be trained across multiple institutions using distributed data without centralizing or sharing the underlying sensitive data.
Question 45: Under the COSO framework, which component addresses the organizational values and ethical tone set by leadership?
- Control activities
- Risk assessment
- Control environment (Correct answer)
- Information and communication
Correct answer: Control environment
The control environment is the foundation of COSO and includes the ethical values, management philosophy, and tone set by leadership.
Question 46: A company discovers its third-party supplier uses child labor, which is legal in the supplier's country but violates the company's supplier code of conduct. The ethical response is to:
- Continue the relationship since the practice is legal locally
- Engage the supplier with a remediation plan and defined timeline, with termination if compliance fails (Correct answer)
- Terminate the contract immediately without providing any notice
- Disclose the issue only in internal risk assessments
Correct answer: Engage the supplier with a remediation plan and defined timeline, with termination if compliance fails
Ethical supply chain management requires companies to enforce their standards through structured remediation while holding suppliers accountable, balancing impact on workers with upholding principles.
Question 47: When an auditor tests a sample of transactions and finds no exceptions, this provides:
- Grounds to eliminate future testing
- Reasonable assurance based on the sample tested (Correct answer)
- Absolute assurance that no errors exist
- Proof that all controls are operating effectively
Correct answer: Reasonable assurance based on the sample tested
Sampling provides reasonable, not absolute, assurance because only a subset of transactions is tested, leaving inherent sampling risk.
Question 48: Which of the following best describes a key competency required for financial crime prevention in CCB practice?
- Memorization of all relevant regulations without understanding context
- Strong analytical skills combined with effective communication and ethical judgment (Correct answer)
- Reliance on a single methodology for all situations
- The ability to work independently without any oversight
Correct answer: Strong analytical skills combined with effective communication and ethical judgment
CCB professionals working in financial crime prevention need analytical skills to assess situations, communication skills to convey findings, and ethical judgment to make sound decisions.
Question 49: Which of the following BEST describes a policy hierarchy in a compliance program?
- A tiered structure of policies, standards, procedures, and guidelines (Correct answer)
- The order in which policies are enforced during an audit
- A ranking of which departments must comply first
- The chronological order in which policies were created
Correct answer: A tiered structure of policies, standards, procedures, and guidelines
A policy hierarchy organizes governance documents from high-level policies down to specific procedures and guidelines, ensuring consistency.
Question 50: Which governance body typically has ultimate oversight responsibility for a whistleblower/hotline program at a public company?
- The Chief Compliance Officer
- The General Counsel's office
- The Audit Committee of the Board of Directors (Correct answer)
- The Chief Human Resources Officer
Correct answer: The Audit Committee of the Board of Directors
SOX and best practices place the Audit Committee in the oversight role for hotline programs, including receipt and handling of complaints about accounting and internal controls.
Question 51: A company requires two senior managers to approve wire transfers over $500,000. This is an example of:
- Dual control (Correct answer)
- Physical safeguard
- Reconciliation control
- Segregation of duties
Correct answer: Dual control
Dual control (also called dual authorization) requires two authorized individuals to approve a single transaction, reducing the risk of unauthorized transfers.
Question 52: The 'right of erasure' (also known as the 'right to be forgotten') under GDPR allows individuals to:
- Correct inaccurate personal data held by a company
- Access a complete copy of all personal data held by an organization
- Opt out of all marketing communications permanently
- Request that their personal data be deleted under certain circumstances (Correct answer)
Correct answer: Request that their personal data be deleted under certain circumstances
GDPR Article 17 grants individuals the right to request deletion of their personal data when it is no longer necessary, consent is withdrawn, or processing is unlawful.
Question 53: Which of the following best describes a key competency required for compliance technology & regtech in CCB practice?
- Strong analytical skills combined with effective communication and ethical judgment (Correct answer)
- The ability to work independently without any oversight
- Memorization of all relevant regulations without understanding context
- Reliance on a single methodology for all situations
Correct answer: Strong analytical skills combined with effective communication and ethical judgment
CCB professionals working in compliance technology & regtech need analytical skills to assess situations, communication skills to convey findings, and ethical judgment to make sound decisions.
Question 54: Which metric is most useful for measuring the effectiveness of a segregation of duties (SoD) control over time?
- Number of employees trained on the policy
- Number of policies updated annually
- Percentage of transactions processed by a single individual without review (Correct answer)
- Total volume of transactions processed per month
Correct answer: Percentage of transactions processed by a single individual without review
Tracking the percentage of transactions processed without a second reviewer directly measures whether the SoD control is being consistently applied.
Question 55: Which law requires employers with 50 or more employees to provide up to 12 weeks of unpaid, job-protected leave for qualifying family and medical reasons?
- Family and Medical Leave Act (FMLA) (Correct answer)
- Pregnancy Discrimination Act
- Americans with Disabilities Act (ADA)
- Uniformed Services Employment and Reemployment Rights Act (USERRA)
Correct answer: Family and Medical Leave Act (FMLA)
The FMLA entitles eligible employees of covered employers to take up to 12 weeks of unpaid, job-protected leave per year for specified family and medical reasons.
Question 56: A multinational company needs a policy that complies with both US HIPAA and EU GDPR requirements. The BEST approach is to:
- Apply only the home-country regulation globally
- Develop a harmonized policy that meets the stricter of the two frameworks (Correct answer)
- Delay policy creation until both regulations are fully unified
- Create separate, fully independent policies for each jurisdiction
Correct answer: Develop a harmonized policy that meets the stricter of the two frameworks
Developing a harmonized policy that meets the stricter framework ensures compliance across all jurisdictions while reducing policy fragmentation.
Question 57: How should CCB professionals handle confidential information related to regulatory reporting requirements?
- Delete all records after project completion
- Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations (Correct answer)
- Store information without any security measures
- Share freely with all colleagues for transparency
Correct answer: Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations
Confidential information must be handled according to established protocols, regulatory requirements, and professional ethics standards, including proper access control and disclosure procedures.
Question 58: What does a policy 'owner' typically bear responsibility for in an organization?
- Maintaining, updating, and ensuring adherence to the policy over time (Correct answer)
- Writing the policy's legal disclaimers
- Distributing printed copies to all employees
- Approving every individual exception request
Correct answer: Maintaining, updating, and ensuring adherence to the policy over time
The policy owner is accountable for keeping the policy current, relevant, and aligned with regulatory requirements throughout its lifecycle.
Question 59: A company's hotline vendor stores call recordings in a foreign country. Which compliance concern is most immediately raised?
- Conflict with internal audit charter
- Breach of employment arbitration agreements
- Violation of antitrust regulations
- Cross-border data privacy and sovereignty requirements (Correct answer)
Correct answer: Cross-border data privacy and sovereignty requirements
Storing whistleblower data abroad triggers compliance obligations under laws such as GDPR, local labor codes, and data-sovereignty rules that may restrict data transfer.
Question 60: Which approach to vendor risk tiering is considered best practice?
- Applying the most rigorous controls only to domestic vendors
- Treating all vendors equally with the same level of scrutiny
- Tiering vendors solely by contract dollar value
- Categorizing vendors by risk level (e.g., critical, high, medium, low) based on data access, criticality, and regulatory exposure (Correct answer)
Correct answer: Categorizing vendors by risk level (e.g., critical, high, medium, low) based on data access, criticality, and regulatory exposure
Risk-based tiering categorizes vendors according to their potential impact on the organization (considering data sensitivity, operational criticality, and regulatory exposure), allowing compliance resources to be focused where risk is greatest.
Question 61: Which U.S. federal law prohibits bribery of foreign government officials by U.S. companies and individuals?
- The Foreign Corrupt Practices Act (FCPA) (Correct answer)
- The Robinson-Patman Act
- The Sherman Antitrust Act
- The Dodd-Frank Act
Correct answer: The Foreign Corrupt Practices Act (FCPA)
The Foreign Corrupt Practices Act (FCPA) of 1977 prohibits U.S. persons and companies from bribing foreign officials to obtain or retain business.
Question 62: What does 'data lineage' mean in a compliance data management context?
- The family tree of a database schema
- The age of data stored in a compliance system
- Tracking the origin, movement, and transformation of data throughout its lifecycle (Correct answer)
- The historical ownership chain of a dataset
Correct answer: Tracking the origin, movement, and transformation of data throughout its lifecycle
Data lineage documents where data comes from, how it moves, and how it changes, which is critical for audit trails and regulatory reporting accuracy.
Question 63: When conducting cross-border due diligence on a target company in an emerging market, which red flag most directly indicates potential FCPA exposure?
- The target has more than 50% revenue from government contracts
- The target's CFO is a foreign national
- The target operates in a country with a Transparency International CPI score below 50
- The target uses undisclosed third-party agents to win government contracts and cannot document their fees (Correct answer)
Correct answer: The target uses undisclosed third-party agents to win government contracts and cannot document their fees
Undisclosed third-party agents receiving unaccounted fees to secure government contracts is a classic FCPA red flag indicating potential bribery through intermediaries.
Question 64: Under Sarbanes-Oxley Section 404, management is required to:
- Conduct annual external fraud investigations
- Assess and report on the effectiveness of internal controls over financial reporting (Correct answer)
- Submit quarterly compliance certifications to the IIA
- Rotate external auditors every three years
Correct answer: Assess and report on the effectiveness of internal controls over financial reporting
SOX Section 404 requires management to assess and report on the design and operating effectiveness of internal controls over financial reporting, with external auditor attestation.
Question 65: Which regulatory framework specifically addresses third-party risk management requirements for financial institutions?
- OCC Bulletin 2013-29 (Third-Party Relationships) (Correct answer)
- OSHA 1910.119
- ISO 14001
- GAAP ASC 606
Correct answer: OCC Bulletin 2013-29 (Third-Party Relationships)
OCC Bulletin 2013-29 provides comprehensive guidance for national banks and federal savings associations on managing risks associated with third-party relationships, covering due diligence, contract provisions, oversight, and termination.
Question 66: A company operating in multiple states must navigate conflicting state privacy laws. This challenge is BEST managed by:
- Lobbying for federal preemption of all state privacy laws
- Establishing separate compliance programs for each state without coordination
- Applying the most restrictive applicable standards enterprise-wide as a baseline (Correct answer)
- Applying the least restrictive state's standards across all operations
Correct answer: Applying the most restrictive applicable standards enterprise-wide as a baseline
Adopting the most restrictive applicable standard as an enterprise baseline ensures compliance across all jurisdictions and simplifies the compliance program.
Question 67: What role do internal controls play in compliance?
- They ensure financial growth only.
- They maintain transparency and accountability (Correct answer)
- They slow down operations.
- They increase paperwork.
Correct answer: They maintain transparency and accountability
Internal controls are policies and procedures implemented by a company to safeguard assets, ensure the accuracy of financial records, and promote operational efficiency. In compliance, they are crucial for establishing clear processes, assigning responsibilities, and monitoring activities to prevent fraud, errors, and non-compliance, thereby fostering transparency and accountability. They are not just about financial growth or increasing paperwork.
Question 68: Which governance principle requires that board members receive compliance reports in advance of meetings?
- Tone at the top
- Segregation of duties
- Dual control
- Timely and accurate information (Correct answer)
Correct answer: Timely and accurate information
The governance principle of timely and accurate information ensures directors can make informed decisions by reviewing materials before meetings.
Question 69: What role does continuous improvement play in whistleblower & hotline management for CCB certified professionals?
- It applies only to new professionals in their first year
- It drives ongoing enhancement of practices, processes, and outcomes through systematic evaluation (Correct answer)
- It is optional and only necessary during certification renewal
- It focuses exclusively on cost reduction
Correct answer: It drives ongoing enhancement of practices, processes, and outcomes through systematic evaluation
Continuous improvement is fundamental to professional practice in whistleblower & hotline management, involving regular evaluation, feedback integration, and process enhancement to maintain high standards.
Question 70: Which of the following best describes the 'residual risk' concept in third-party vendor risk management?
- The risk that a vendor will submit residual invoices after contract termination
- The amount of risk that existed before the vendor relationship began
- The financial cost remaining after vendor payments are processed
- The risk that remains after all available controls, mitigations, and countermeasures have been applied to a third-party relationship (Correct answer)
Correct answer: The risk that remains after all available controls, mitigations, and countermeasures have been applied to a third-party relationship
Residual risk is the level of risk that persists after all identified controls and mitigations have been implemented; if residual risk exceeds the organization's risk appetite, additional controls or risk acceptance decisions are required.
Question 71: An organization's internal audit charter should PRIMARILY:
- Outline employee performance evaluation criteria
- Define the purpose, authority, and responsibility of the internal audit function (Correct answer)
- List all audit findings from the prior year
- Specify the external audit fee schedule
Correct answer: Define the purpose, authority, and responsibility of the internal audit function
The internal audit charter is a formal document approved by the board that defines the function's purpose, authority, scope, and reporting relationships.
Question 72: When a CCB professional encounters an unfamiliar challenge in whistleblower & hotline management, what is the recommended first course of action?
- Postpone addressing the issue indefinitely
- Proceed based on personal intuition alone
- Apply the solution used for the most recent similar problem without adaptation
- Research applicable standards, consult with subject matter experts, and document the approach (Correct answer)
Correct answer: Research applicable standards, consult with subject matter experts, and document the approach
Professional practice requires a methodical approach to unfamiliar challenges: research the applicable standards, consult experts when needed, and document the reasoning for the chosen approach.
Question 73: Which of the following is an example of a 'right-to-audit' clause in a vendor contract?
- A clause that allows the vendor to audit the organization's financials
- A clause granting the organization the right to conduct on-site inspections or review vendor records to verify compliance with contractual and regulatory requirements (Correct answer)
- A clause limiting the number of invoices the vendor can submit
- A clause requiring the vendor to hire a specific accounting firm
Correct answer: A clause granting the organization the right to conduct on-site inspections or review vendor records to verify compliance with contractual and regulatory requirements
A right-to-audit clause gives the organization (or its designated representative) contractual authority to examine the vendor's operations, records, and systems to verify that the vendor is meeting its contractual and compliance obligations.
Question 74: A compliance team is evaluating whether to build or buy a RegTech solution. Which factor most strongly favors a 'buy' decision?
- The firm wants full control over the source code
- The firm has unique compliance processes not found elsewhere
- Integration with legacy systems is straightforward
- A mature vendor solution already addresses the firm's needs with proven regulatory acceptance (Correct answer)
Correct answer: A mature vendor solution already addresses the firm's needs with proven regulatory acceptance
When a proven commercial solution meets the firm's needs and is already accepted by regulators, buying is typically faster and less risky than building a custom solution.
Question 75: In HR compliance, what is 'disparate impact' discrimination?
- Retaliation against an employee for filing a complaint
- Intentional discrimination based on a protected characteristic
- A neutral employment policy that disproportionately disadvantages a protected group (Correct answer)
- Harassment based on national origin
Correct answer: A neutral employment policy that disproportionately disadvantages a protected group
Disparate impact occurs when a facially neutral employment practice (e.g., a hiring test) disproportionately excludes members of a protected class, even without discriminatory intent.
Question 76: How does ethical leadership benefit a business?
- It promotes integrity and responsibility (Correct answer)
- It promotes short-term gain.
- It encourages dishonesty.
- It increases turnover rates.
Correct answer: It promotes integrity and responsibility
Ethical leadership sets the moral tone for an entire organization. When leaders act with integrity and take responsibility for their actions, it inspires employees to do the same, fostering a culture of honesty and accountability. This leads to better decision-making, stronger employee morale, and enhanced reputation, which are crucial for long-term business success.
Question 77: What is 'regulatory reporting automation' and what risk does it primarily mitigate?
- Automated alert generation; mitigates false negative risk
- Automated generation and submission of required regulatory reports; mitigates manual errors and late filing penalties (Correct answer)
- Automation of internal policies; mitigates training costs
- Automation of customer onboarding; mitigates KYC costs
Correct answer: Automated generation and submission of required regulatory reports; mitigates manual errors and late filing penalties
Regulatory reporting automation uses technology to extract, validate, and submit required reports to regulators, reducing human error and ensuring timely, accurate filings.
Question 78: What is policy implementation?
- Writing reports only.
- Storing old files.
- Scheduling team lunches.
- Enforcing and executing policy actions (Correct answer)
Correct answer: Enforcing and executing policy actions
Policy implementation is the critical phase where the developed policy is put into action within the organization. This involves communicating the policy to all relevant parties, providing necessary training, establishing procedures for adherence, and actively enforcing its rules and guidelines. Effective implementation ensures that the policy's objectives are realized and that it translates into tangible changes in behavior and operations.
Question 79: Which scenario BEST illustrates the concept of 'compliance by design' using RegTech?
- Adding compliance checks after a product is launched
- Embedding automated compliance controls and limits directly into a product's technology architecture from inception (Correct answer)
- Hiring more compliance officers to review products post-launch
- Creating a compliance manual before product development begins
Correct answer: Embedding automated compliance controls and limits directly into a product's technology architecture from inception
Compliance by design integrates regulatory requirements into the technical architecture of a product or process from the start, preventing violations rather than detecting them later.
Question 80: Why is stakeholder involvement important in policy development?
- To create barriers.
- To reduce collaboration.
- To delay the process.
- To improve relevance and acceptance (Correct answer)
Correct answer: To improve relevance and acceptance
Involving stakeholders in policy development ensures that the policy addresses their concerns, incorporates diverse perspectives, and is practical for those who will be affected by it. This collaborative approach increases the policy's relevance to real-world situations and fosters a sense of ownership among stakeholders, leading to greater acceptance and smoother implementation. Without stakeholder input, policies may be impractical or face resistance.
Question 81: What role does continuous improvement play in compliance technology & regtech for CCB certified professionals?
- It drives ongoing enhancement of practices, processes, and outcomes through systematic evaluation (Correct answer)
- It applies only to new professionals in their first year
- It is optional and only necessary during certification renewal
- It focuses exclusively on cost reduction
Correct answer: It drives ongoing enhancement of practices, processes, and outcomes through systematic evaluation
Continuous improvement is fundamental to professional practice in compliance technology & regtech, involving regular evaluation, feedback integration, and process enhancement to maintain high standards.
Question 82: The primary purpose of a control self-assessment (CSA) is to:
- Replace external audit procedures
- Test the accuracy of financial statements
- Allow management and staff to evaluate their own controls (Correct answer)
- Satisfy regulatory reporting requirements
Correct answer: Allow management and staff to evaluate their own controls
CSA is a process where process owners and staff collaboratively assess the effectiveness of controls in their area, supplementing (not replacing) formal audits.
Question 83: Which element of a written policy ensures readers can identify the most current version and avoid applying outdated rules?
- The policy rationale
- The signature of the original author
- The list of policy exceptions already granted
- Version number and effective date in the document header (Correct answer)
Correct answer: Version number and effective date in the document header
Version numbers and effective dates allow users to confirm they are referencing the current, approved policy rather than an outdated revision.
Question 84: Which type of audit evidence is generally considered MOST reliable?
- Oral statements from management
- Internal documents prepared by the client
- Copies of original source documents
- External documents obtained directly from third parties (Correct answer)
Correct answer: External documents obtained directly from third parties
Evidence obtained directly from independent external sources (e.g., bank confirmations, attorney letters) is more reliable than internally generated documents.
Question 85: Under SR 11-7, which US federal guidance governs the management of model risk at banks, what are the two key elements of effective model risk management?
- Vendor selection and contract management
- Cost control and technology selection
- Algorithm testing and IT security
- Robust model development and validation, plus sound model governance (Correct answer)
Correct answer: Robust model development and validation, plus sound model governance
SR 11-7 requires effective model risk management through rigorous development and validation processes combined with strong governance policies and controls.
Question 86: What is the most effective way to measure success in cross-border compliance issues within CCB professional practice?
- Compare only with industry averages without considering context
- Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives (Correct answer)
- Count only the number of activities completed
- Rely solely on supervisor opinion
Correct answer: Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives
Effective measurement combines multiple data sources — quantitative metrics, qualitative assessments, and stakeholder feedback — all aligned with clearly defined objectives for a comprehensive evaluation.
Question 87: What makes a policy clear and effective?
- Using vague terms and complex jargon.
- Simple language and specific rules (Correct answer)
- Skipping roles and responsibilities.
- Lack of examples and definitions.
Correct answer: Simple language and specific rules
A clear and effective policy uses straightforward language that is easily understood by all employees, avoiding jargon or overly complex phrasing. It also provides specific, actionable rules and guidelines, leaving little room for misinterpretation. Clarity ensures that employees know exactly what is expected of them, promoting consistent compliance and reducing errors.
Question 88: Which of the following is a limitation of internal control?
- They eliminate all risks.
- They may be overridden or bypassed (Correct answer)
- They are always foolproof.
- They cannot be bypassed.
Correct answer: They may be overridden or bypassed
While internal controls are designed to mitigate risks, they are not foolproof. A significant limitation is the possibility of management override, where senior personnel intentionally circumvent established controls, or collusion among employees to bypass controls. Human error, misunderstanding, or resource constraints can also limit their effectiveness, meaning controls can reduce but not eliminate all risks.
Question 89: In risk management, 'concentration risk' refers to:
- The risk of regulators focusing audits on a specific business line
- The risk of data being concentrated in a single unprotected database
- Excessive exposure to a single counterparty, sector, or geographic region that could cause significant loss (Correct answer)
- The risk that employees will not focus during compliance training
Correct answer: Excessive exposure to a single counterparty, sector, or geographic region that could cause significant loss
Concentration risk arises when an organization has overexposure to a single entity, industry, or geography, making it vulnerable if that area experiences a downturn.
Question 90: Which principle from the BCBS 239 guidelines is MOST directly supported by RegTech data management solutions?
- Capital adequacy requirements
- Accuracy and integrity of risk data aggregation and reporting (Correct answer)
- Liquidity coverage ratio calculations
- Stress testing methodology
Correct answer: Accuracy and integrity of risk data aggregation and reporting
BCBS 239 requires banks to have strong risk data aggregation capabilities; RegTech data management solutions directly support accuracy, completeness, and timeliness of risk data.
Question 91: Which of the following BEST describes a compensating control?
- A management review performed annually
- A control that detects errors after the fact
- An alternative control that mitigates risk when an ideal control is not feasible (Correct answer)
- A control embedded within an IT system
Correct answer: An alternative control that mitigates risk when an ideal control is not feasible
Compensating controls provide alternative risk mitigation when primary controls cannot be implemented, such as enhanced monitoring when segregation of duties is not practical in a small business.
Question 92: Which internal audit technique compares financial ratios and trends over time to identify unusual fluctuations?
- Analytical procedures (Correct answer)
- Confirmations
- Physical inspection
- Attribute sampling
Correct answer: Analytical procedures
Analytical procedures involve evaluating financial information through analysis of relationships and trends, helping auditors identify areas requiring further investigation.
Question 93: A company's board has 10 members, 9 of whom are former colleagues of the CEO. This structure primarily raises concerns about:
- Excessive diversity of viewpoints slowing decision-making
- Non-compliance with SEC disclosure requirements
- Board size exceeding regulatory limits
- Lack of board independence and potential rubber-stamping of management decisions (Correct answer)
Correct answer: Lack of board independence and potential rubber-stamping of management decisions
A board dominated by insiders or associates of the CEO lacks independence, undermining its ability to provide objective oversight of management.
Question 94: How often should internal audits be conducted?
- When problems arise only.
- Periodically based on risk and schedule (Correct answer)
- Every 10 years.
- Never.
Correct answer: Periodically based on risk and schedule
The frequency of internal audits should not be fixed but rather determined by a risk-based approach and a predefined audit schedule. High-risk areas or processes with significant changes may require more frequent audits, while lower-risk areas might be audited less often. This approach ensures that audit resources are allocated effectively to areas that pose the greatest potential threat to the organization's objectives.
Question 95: A firm implements a graph database to map relationships between clients, accounts, and transactions for AML purposes. What compliance capability does this PRIMARILY enhance?
- Customer risk scoring based on demographics
- Automated SAR filing
- Regulatory report generation
- Network analysis to detect complex money laundering typologies involving multiple entities (Correct answer)
Correct answer: Network analysis to detect complex money laundering typologies involving multiple entities
Graph databases excel at revealing hidden connections and relationships across entities, enabling detection of sophisticated layering and structuring schemes in AML investigations.
Question 96: What distinguishes a 'warranty' from a 'guarantee' in a contract compliance context?
- A warranty is a seller's promise about product quality; a guarantee often refers to a third-party assurance of performance (Correct answer)
- Warranties are only used in service contracts; guarantees only in product contracts
- There is no legal distinction between the two terms
- A warranty is always oral; a guarantee must be in writing
Correct answer: A warranty is a seller's promise about product quality; a guarantee often refers to a third-party assurance of performance
A warranty is the seller's direct promise about goods or services meeting certain standards, while a guarantee typically involves a third party (like a surety) assuring performance.
Question 97: What is a policy?
- An informal idea.
- A customer complaint.
- A formal guide to decisions and behavior (Correct answer)
- An accounting error log.
Correct answer: A formal guide to decisions and behavior
A policy is a written statement that outlines the principles, rules, and guidelines that govern an organization's actions, decisions, and employee conduct. It provides a framework for consistent operations, ensures compliance with legal and ethical standards, and helps achieve organizational objectives. Policies are formal documents that provide clear direction and expectations.
Question 98: In policy development, a 'stakeholder comment period' is PRIMARILY used to:
- Satisfy a regulatory requirement for public notice
- Gather feedback from affected parties to identify gaps or unintended consequences before finalization (Correct answer)
- Allow employees to vote on whether the policy is necessary
- Delay policy approval until all objections are resolved
Correct answer: Gather feedback from affected parties to identify gaps or unintended consequences before finalization
Comment periods surface practical concerns, legal issues, or operational impacts that drafters may have missed, improving policy quality before approval.
Question 99: What is the most effective way to measure success in compliance technology & regtech within CCB professional practice?
- Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives (Correct answer)
- Count only the number of activities completed
- Rely solely on supervisor opinion
- Compare only with industry averages without considering context
Correct answer: Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives
Effective measurement combines multiple data sources — quantitative metrics, qualitative assessments, and stakeholder feedback — all aligned with clearly defined objectives for a comprehensive evaluation.
Question 100: Which type of internal audit focuses on whether organizational resources are used efficiently and economically?
- Performance audit (Correct answer)
- Financial audit
- Compliance audit
- IT audit
Correct answer: Performance audit
Performance audits (also called operational or efficiency audits) assess whether resources are being used economically and efficiently to achieve organizational objectives.
Question 101: An organization's compliance team conducts a post-implementation review 90 days after a new policy goes live. The PRIMARY goal of this review is to:
- Prepare the policy for submission to external regulators
- Assess whether the policy is achieving its intended compliance outcomes and identify needed adjustments (Correct answer)
- Identify employees who have not yet signed the attestation
- Calculate the cost savings from eliminating previous informal practices
Correct answer: Assess whether the policy is achieving its intended compliance outcomes and identify needed adjustments
A post-implementation review evaluates real-world policy effectiveness and surfaces gaps or unintended consequences that require corrective action.
Question 102: What is the significance of the 'inherent risk' assessment in third-party risk management before controls are applied?
- It establishes the baseline level of risk a vendor relationship poses before any controls or mitigations are considered (Correct answer)
- It quantifies the financial cost of the vendor relationship
- It assesses the risk that a vendor will raise their prices
- It measures the risk that remains after all mitigating controls are in place
Correct answer: It establishes the baseline level of risk a vendor relationship poses before any controls or mitigations are considered
Inherent risk represents the raw or baseline risk of a vendor relationship without accounting for controls, providing the starting point for determining how much mitigation is needed and what residual risk will remain.
Question 103: Why are control activities necessary?
- To enforce policy and reduce risk (Correct answer)
- To increase complexity.
- To encourage non-compliance.
- To remove supervision.
Correct answer: To enforce policy and reduce risk
Control activities are specific actions taken by management to help ensure that management directives are carried out and that risks to the achievement of organizational objectives are mitigated. These activities include approvals, authorizations, reconciliations, and segregation of duties. They are essential for enforcing policies, preventing errors, detecting fraud, and safeguarding assets, thereby reducing overall operational and financial risks.
Question 104: When performing a 'test of design' for an operational control, a compliance officer is evaluating whether:
- The control was actually executed during the testing period
- The control meets the minimum number of automated checks required by regulation
- The control, if operating as intended, would effectively mitigate the identified risk (Correct answer)
- The control has been tested in prior periods without exception
Correct answer: The control, if operating as intended, would effectively mitigate the identified risk
A test of design assesses whether the control is conceptually capable of addressing the risk, separate from whether it is actually being performed.
Question 105: A material weakness in internal control over financial reporting is best defined as:
- A finding that requires immediate management correction
- A minor error that does not affect financial statements
- An audit exception noted in the working papers
- A deficiency that could result in a material misstatement not being prevented or detected (Correct answer)
Correct answer: A deficiency that could result in a material misstatement not being prevented or detected
A material weakness is a significant deficiency (or combination of deficiencies) that creates a reasonable possibility of a material misstatement going undetected.
Question 106: When audit findings are rated by severity, a 'significant deficiency' falls:
- Between a control deficiency and a material weakness (Correct answer)
- Above a material weakness
- Below a control deficiency
- At the same level as a material weakness
Correct answer: Between a control deficiency and a material weakness
A significant deficiency is more severe than a control deficiency but less severe than a material weakness on the audit findings severity scale.
Question 107: When deploying a cloud-based RegTech solution, which legal concept determines which country's data protection laws apply to customer data stored in that cloud?
- Cross-border licensing agreements
- Data residency and data sovereignty requirements (Correct answer)
- Regulatory arbitrage
- Cloud service level agreements
Correct answer: Data residency and data sovereignty requirements
Data residency and sovereignty rules determine the geographic location where data must be stored and which nation's laws govern its protection and access.
Question 108: The purpose of an exit conference at the end of an internal audit is to:
- Discuss findings and recommendations with management before the report is issued (Correct answer)
- Present the final audit report to regulators
- Archive audit documentation for future reference
- Obtain management sign-off on audit working papers
Correct answer: Discuss findings and recommendations with management before the report is issued
The exit conference allows auditors to review draft findings with management, verify factual accuracy, and obtain preliminary management responses before the final report.
Question 109: How should CCB professionals handle confidential information related to financial crime prevention?
- Share freely with all colleagues for transparency
- Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations (Correct answer)
- Store information without any security measures
- Delete all records after project completion
Correct answer: Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations
Confidential information must be handled according to established protocols, regulatory requirements, and professional ethics standards, including proper access control and disclosure procedures.
Question 110: Under CARES Act and subsequent legislation, employers claiming Employee Retention Credits must reconcile those credits on which payroll tax form?
- Form 945
- Form 940
- Form W-3
- Form 941 (Correct answer)
Correct answer: Form 941
Employers report and reconcile Employee Retention Credits on Form 941, the Employer's Quarterly Federal Tax Return.
Question 111: Which international standard provides a framework for anti-bribery management systems that organizations can implement to demonstrate cross-border compliance efforts?
- ISO 9001 (Quality Management)
- ISO 37001 (Anti-Bribery Management Systems) (Correct answer)
- ISO 27001 (Information Security Management)
- ISO 31000 (Risk Management)
Correct answer: ISO 37001 (Anti-Bribery Management Systems)
ISO 37001 is the international standard specifically designed for anti-bribery management systems and is recognized by enforcement authorities worldwide.
Question 112: Under the Foreign Account Tax Compliance Act (FATCA), what obligation does a foreign financial institution (FFI) have regarding US account holders?
- FFIs must report US account holder information to the IRS or withhold 30% on certain US-source payments (Correct answer)
- FFIs must refuse service to all US citizens
- FFIs must obtain IRS pre-approval before opening any account
- FFIs must convert US accounts to non-interest-bearing accounts
Correct answer: FFIs must report US account holder information to the IRS or withhold 30% on certain US-source payments
FATCA requires FFIs to identify and report US account holders' financial information to the IRS or face a 30% withholding tax on certain US-source income.
Question 113: Which of the following is a characteristic of a strong ethical organizational culture?
- Employees are discouraged from reporting concerns to avoid legal exposure
- Ethics training is conducted once at onboarding with no follow-up
- Ethical behavior is formally incentivized and violations are consistently punished (Correct answer)
- The compliance department operates independently with no board oversight
Correct answer: Ethical behavior is formally incentivized and violations are consistently punished
A strong ethical culture reinforces desired behavior through positive incentives and consistent consequences for violations.
Question 114: Which internal audit activity involves reviewing controls before a new system goes live?
- Substantive testing
- Post-implementation review
- Pre-implementation review (Correct answer)
- Walkthrough procedure
Correct answer: Pre-implementation review
Pre-implementation reviews assess the adequacy of controls in a new system before it becomes operational, reducing the risk of control gaps after launch.
Question 115: Which board committee has primary responsibility for overseeing the integrity of financial reporting and the relationship with external auditors?
- Audit committee (Correct answer)
- Risk management committee
- Nominating and governance committee
- Compensation committee
Correct answer: Audit committee
The audit committee oversees financial reporting integrity, internal controls, and the engagement and independence of external auditors.
CCB Certified Compliance and Business Specialist (CCB)
The CCB Certified Compliance and Business Specialist credential, administered by the Compliance Certification Board (SCCE), validates expertise in core business compliance disciplines including data privacy, internal auditing, policy governance, and regulatory technology. It is designed for compliance professionals responsible for building and managing compliance programs across corporate and regulated environments.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds