Regulatory Compliance & Risk Management Flashcards
7 cards from real CCB practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Regulatory Compliance & Risk Management flashcards as text
A compliance officer discovers that an employee self-reported a potential policy violation before it caused any harm. What is the BEST initial response?
Answer: Investigate the report, protect the whistleblower, and remediate the issue
Best practice is to investigate thoroughly, protect the reporting employee from retaliation, and use the finding to remediate the root cause.
Under the Dodd-Frank Act, which agency has authority to bring enforcement actions against covered financial institutions for unfair, deceptive, or abusive acts or practices (UDAAP)?
Answer: The CFPB
The Consumer Financial Protection Bureau (CFPB), created by Dodd-Frank, has primary authority to enforce UDAAP standards against financial institutions.
What is 'inherent risk' in the context of risk assessments?
Answer: Risk that exists naturally in a process or activity before any controls are implemented
Inherent risk is the level of risk in the absence of any controls or mitigating factors, representing the raw exposure to a particular threat.
Which international standard provides guidance on anti-bribery management systems for organizations?
Answer: ISO 37001
ISO 37001 specifies requirements for establishing, implementing, and maintaining an anti-bribery management system to help organizations prevent and detect bribery.
A Key Risk Indicator (KRI) is BEST described as:
Answer: A forward-looking metric that signals the potential increase in risk exposure
KRIs are predictive metrics that provide early warning signals of increasing risk, enabling proactive management before risks materialize into losses.
Under HIPAA, which rule specifically governs the security of electronic protected health information (ePHI)?
Answer: The Security Rule
The HIPAA Security Rule establishes national standards to protect individuals' electronic protected health information through administrative, physical, and technical safeguards.
A company operating in multiple states must navigate conflicting state privacy laws. This challenge is BEST managed by:
Answer: Applying the most restrictive applicable standards enterprise-wide as a baseline
Adopting the most restrictive applicable standard as an enterprise baseline ensures compliance across all jurisdictions and simplifies the compliance program.