Regulatory Compliance & Risk Management Flashcards
7 cards from real CCB practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Regulatory Compliance & Risk Management flashcards as text
Which of the following is an example of a 'detective' control in an internal control framework?
Answer: Conducting monthly bank reconciliations to identify discrepancies
Detective controls, like bank reconciliations, are designed to identify errors or fraud after they have occurred, rather than preventing them.
When performing third-party risk due diligence, which factor is MOST critical to evaluate for a vendor handling sensitive customer data?
Answer: The vendor's information security practices and data breach history
For vendors handling sensitive data, evaluating their information security posture and incident history is critical to assessing the risk they pose to your organization.
A compliance program's effectiveness is BEST measured by:
Answer: A combination of output metrics, culture assessments, and compliance incident trends
Effective compliance measurement uses multiple indicators including qualitative culture measures and quantitative incident trends, not just lagging indicators like fines.
The 'right of erasure' (also known as the 'right to be forgotten') under GDPR allows individuals to:
Answer: Request that their personal data be deleted under certain circumstances
GDPR Article 17 grants individuals the right to request deletion of their personal data when it is no longer necessary, consent is withdrawn, or processing is unlawful.
Under the Equal Credit Opportunity Act (ECOA), a lender must notify an applicant of adverse action within how many days of receiving a completed credit application?
Answer: 30 days
ECOA requires lenders to notify applicants of adverse action within 30 days of receiving a completed credit application.
In risk management, 'concentration risk' refers to:
Answer: Excessive exposure to a single counterparty, sector, or geographic region that could cause significant loss
Concentration risk arises when an organization has overexposure to a single entity, industry, or geography, making it vulnerable if that area experiences a downturn.
A compliance officer is asked to assess the regulatory risk of launching a new product. Which step should be performed FIRST?
Answer: Identify all applicable laws, regulations, and regulatory guidance relevant to the product
The first step in regulatory risk assessment is to map all applicable regulatory requirements so that the full compliance obligation landscape is understood before any other steps.