Policy Development & Implementation Flashcards
7 cards from real CCB practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Policy Development & Implementation flashcards as text
A policy review triggered by a regulatory change should be classified as a:
Answer: Ad-hoc or triggered review
An ad-hoc or triggered review is initiated by a specific event—such as a regulatory change—outside the normal review schedule.
What is the primary risk of having too many overlapping or redundant policies in an organization?
Answer: Confusion, inconsistent enforcement, and compliance fatigue among employees
Redundant policies create contradictions, make it harder for employees to know which rule applies, and reduce overall compliance culture effectiveness.
When a policy is retired or sunset, which action is MOST important from a compliance standpoint?
Answer: Archiving the policy and maintaining records of its effective dates for audit trails
Archiving retired policies with effective dates preserves the historical record needed to demonstrate compliance during the period the policy was active.
A compliance officer wants to assess whether employees can apply a new code of conduct policy correctly. The BEST assessment method is:
Answer: Scenario-based testing or case study exercises during training
Scenario-based testing measures applied understanding, not just passive awareness, revealing whether employees can make correct decisions under the policy.
Under the 'reasonable person' standard used in compliance, a policy should be written so that:
Answer: An average employee in the relevant role can understand and apply it
The reasonable person standard requires that policy language be clear enough for the intended audience to understand and follow without specialized expertise.
Which of the following represents a key input when developing a new anti-bribery policy?
Answer: Requirements of the Foreign Corrupt Practices Act (FCPA) and UK Bribery Act
Anti-bribery policies must be grounded in applicable laws like the FCPA and UK Bribery Act to ensure legal compliance and enforceability.
A 'policy attestation' process requires employees to:
Answer: Formally acknowledge that they have read, understood, and will comply with a policy
Policy attestation creates a documented record of employee acknowledgment, which is essential evidence of a compliance program's communication efforts.