← All CCB Flashcard Decks

Regulatory Compliance & Risk Management Flashcards

7 cards from real CCB practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Regulatory Compliance & Risk Management flashcards as text
  1. Under the Bank Secrecy Act (BSA), what is the threshold amount that triggers a Currency Transaction Report (CTR)?

    Answer: $10,000

    The BSA requires financial institutions to file a CTR for any cash transaction exceeding $10,000 in a single business day.

  2. Which risk management framework published by COSO is most widely used for enterprise risk management?

    Answer: COSO ERM 2017

    The COSO Enterprise Risk Management – Integrating with Strategy and Performance (2017) framework is the most widely referenced ERM standard globally.

  3. A company discovers that a vendor is processing personal data in a non-compliant manner under GDPR. What is the organization's PRIMARY obligation?

    Answer: Ensure a Data Processing Agreement is in place and remediate non-compliance

    Under GDPR Article 28, controllers must have a Data Processing Agreement with vendors and ensure compliance; termination is a last resort after remediation attempts.

  4. What does 'residual risk' refer to in risk management?

    Answer: The risk remaining after controls and mitigation measures are implemented

    Residual risk is the level of risk that remains after an organization has applied its risk controls and mitigation strategies.

  5. Which of the following best describes the purpose of a compliance gap analysis?

    Answer: To identify differences between current practices and required regulatory standards

    A gap analysis compares an organization's current compliance posture to regulatory requirements to identify areas needing remediation.

  6. Under the Sarbanes-Oxley Act (SOX), which section specifically requires management to assess and report on internal controls over financial reporting?

    Answer: Section 404

    SOX Section 404 mandates that management assess and report on the effectiveness of internal controls over financial reporting, with external auditor attestation.

  7. An organization uses a 'risk appetite statement' primarily to:

    Answer: Communicate the level of risk the organization is willing to accept in pursuit of its objectives

    A risk appetite statement defines and communicates the amount and type of risk an organization is willing to accept to achieve its strategic goals.