Mixed Deck — All CCB Topics Flashcards
100 cards from real CCB practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All CCB Topics flashcards as text
Under the Uyghur Forced Labor Prevention Act (UFLPA), imports from the Xinjiang region of China are subject to which presumption?
Answer: Presumed to be made with forced labor and prohibited unless the importer rebuts the presumption with clear and convincing evidence
The UFLPA creates a rebuttable presumption that goods produced in Xinjiang or by certain entities involve forced labor, shifting the burden to importers to prove otherwise.
In the context of CCB certification, what is the most important consideration when implementing regulatory reporting requirements?
Answer: Ensuring alignment with established standards, stakeholder needs, and best practices
When implementing regulatory reporting requirements, CCB professionals must ensure alignment with industry standards and stakeholder needs. Hasty implementation without proper planning often leads to compliance issues and suboptimal outcomes.
How should CCB professionals handle confidential information related to financial crime prevention?
Answer: Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations
Confidential information must be handled according to established protocols, regulatory requirements, and professional ethics standards, including proper access control and disclosure procedures.
Which technology is BEST suited for creating an immutable audit trail for compliance purposes?
Answer: Distributed ledger / blockchain technology
Blockchain's immutable, append-only distributed ledger creates tamper-evident records that are ideal for compliance audit trails.
A company's board has 10 members, 9 of whom are former colleagues of the CEO. This structure primarily raises concerns about:
Answer: Lack of board independence and potential rubber-stamping of management decisions
A board dominated by insiders or associates of the CEO lacks independence, undermining its ability to provide objective oversight of management.
Which ethical risk is most associated with 'organizational conflict of interest' (OCI) in government contracting?
Answer: A contractor using access to non-public information to gain an unfair competitive advantage
OCI occurs when a contractor's work for the government gives it unfair access to non-public information or the ability to bias future competitions in its favor.
What is the purpose of a 'right to audit' clause in a contract?
Answer: To give the buyer the right to examine the contractor's books and records related to the contract
A right to audit clause allows the contracting party to inspect the contractor's relevant financial records to verify billing accuracy and compliance.
Who is responsible for establishing internal controls?
Answer: Management
Management is primarily responsible for establishing, implementing, and maintaining an effective system of internal controls within an organization. They are accountable for designing controls that address identified risks, ensuring that employees understand and adhere to them, and regularly monitoring their effectiveness. While the board oversees, management is hands-on in their creation and daily operation.
What is the purpose of a control self-assessment (CSA)?
Answer: To enable business units to evaluate the effectiveness of their own controls
A CSA is a process by which management and staff identify and evaluate risks and controls within their own business units.
Which U.S. federal law prohibits bribery of foreign government officials by U.S. companies and individuals?
Answer: The Foreign Corrupt Practices Act (FCPA)
The Foreign Corrupt Practices Act (FCPA) of 1977 prohibits U.S. persons and companies from bribing foreign officials to obtain or retain business.
A compliance officer is designing a test plan for a new automated transaction monitoring system. Which testing type should be performed first?
Answer: Unit testing of individual rule components
Unit testing of individual components should occur first to ensure each rule or algorithm works correctly before integrated or user acceptance testing begins.
An auditor identifies that a single employee handles purchasing, receiving, and payment approval. This is best described as a:
Answer: Segregation of duties weakness
Segregation of duties requires that incompatible functions — such as authorizing, recording, and custody — be assigned to different individuals to reduce fraud risk.
A vendor risk assessment questionnaire (VRAQ) is BEST used to:
Answer: Gather standardized information about a vendor's security, compliance, and operational practices to support risk evaluation
A VRAQ systematically collects information about a vendor's policies, controls, certifications, and practices across risk domains, enabling the compliance team to evaluate risk before and during the vendor relationship.
Which governance mechanism most directly aligns executive compensation with long-term shareholder value?
Answer: Equity-based compensation with multi-year vesting schedules
Equity compensation with vesting schedules incentivizes executives to focus on sustainable long-term performance rather than short-term gains.
A 'policy attestation' process requires employees to:
Answer: Formally acknowledge that they have read, understood, and will comply with a policy
Policy attestation creates a documented record of employee acknowledgment, which is essential evidence of a compliance program's communication efforts.
A 'mandatory' policy differs from a 'recommended' guideline primarily in that:
Answer: Mandatory policies require compliance; guidelines suggest best practices
Mandatory policies are binding requirements enforced with sanctions, while guidelines represent optional best practices without punitive consequences.
An organization wants to ensure a supplier meets cybersecurity standards throughout the contract period, not just at signing. Which mechanism is most effective?
Answer: Annual third-party security assessments as a contract requirement
Requiring periodic third-party security assessments as a contractual obligation ensures ongoing cybersecurity compliance throughout the contract lifecycle.
Under the EU General Data Protection Regulation (GDPR), which mechanism allows a US company to legally transfer personal data from the EU without relying on Standard Contractual Clauses?
Answer: EU-US Data Privacy Framework
The EU-US Data Privacy Framework, adopted in 2023, is the current adequacy decision allowing certified US companies to receive EU personal data lawfully.
In the context of CCB certification, what is the most important consideration when implementing contract compliance & management?
Answer: Ensuring alignment with established standards, stakeholder needs, and best practices
When implementing contract compliance & management, CCB professionals must ensure alignment with industry standards and stakeholder needs. Hasty implementation without proper planning often leads to compliance issues and suboptimal outcomes.
What does 'indemnification' in a contract primarily require?
Answer: One party to compensate the other for losses arising from specified events
An indemnification clause requires one party to hold the other harmless and cover losses, damages, or liabilities from specified circumstances.