CCB Policy Development & Implementation 4 — Questions and Answers
Question 1: A policy review triggered by a regulatory change should be classified as a:
- Scheduled periodic review
- Ad-hoc or triggered review (Correct answer)
- Voluntary internal audit
- Sunset review
Correct answer: Ad-hoc or triggered review
An ad-hoc or triggered review is initiated by a specific event—such as a regulatory change—outside the normal review schedule.
Question 2: What is the primary risk of having too many overlapping or redundant policies in an organization?
- Increased audit costs for external reviewers
- Confusion, inconsistent enforcement, and compliance fatigue among employees (Correct answer)
- Regulators will penalize the organization for over-compliance
- Policies become too long to fit in a single document management system
Correct answer: Confusion, inconsistent enforcement, and compliance fatigue among employees
Redundant policies create contradictions, make it harder for employees to know which rule applies, and reduce overall compliance culture effectiveness.
Question 3: When a policy is retired or sunset, which action is MOST important from a compliance standpoint?
- Shredding all physical copies immediately
- Archiving the policy and maintaining records of its effective dates for audit trails (Correct answer)
- Notifying only the policy owner and no other stakeholders
- Replacing it with an informal verbal agreement
Correct answer: Archiving the policy and maintaining records of its effective dates for audit trails
Archiving retired policies with effective dates preserves the historical record needed to demonstrate compliance during the period the policy was active.
Question 4: A compliance officer wants to assess whether employees can apply a new code of conduct policy correctly. The BEST assessment method is:
- Reviewing how many employees signed the acknowledgment form
- Scenario-based testing or case study exercises during training (Correct answer)
- Counting the number of HR complaints filed after rollout
- Checking whether the policy was posted on the intranet
Correct answer: Scenario-based testing or case study exercises during training
Scenario-based testing measures applied understanding, not just passive awareness, revealing whether employees can make correct decisions under the policy.
Question 5: Under the 'reasonable person' standard used in compliance, a policy should be written so that:
- Only legal counsel can interpret it correctly
- An average employee in the relevant role can understand and apply it (Correct answer)
- It requires a compliance officer to explain it before every use
- It uses technical regulatory language verbatim from the source regulation
Correct answer: An average employee in the relevant role can understand and apply it
The reasonable person standard requires that policy language be clear enough for the intended audience to understand and follow without specialized expertise.
Question 6: Which of the following represents a key input when developing a new anti-bribery policy?
- Employee satisfaction survey results
- Requirements of the Foreign Corrupt Practices Act (FCPA) and UK Bribery Act (Correct answer)
- Marketing department's brand style guide
- The organization's social media policy
Correct answer: Requirements of the Foreign Corrupt Practices Act (FCPA) and UK Bribery Act
Anti-bribery policies must be grounded in applicable laws like the FCPA and UK Bribery Act to ensure legal compliance and enforceability.
Question 7: A 'policy attestation' process requires employees to:
- Rewrite the policy in their own words and submit it to HR
- Formally acknowledge that they have read, understood, and will comply with a policy (Correct answer)
- Vote on whether a policy should be approved or rejected
- Submit anonymous feedback about a policy's practicality
Correct answer: Formally acknowledge that they have read, understood, and will comply with a policy
Policy attestation creates a documented record of employee acknowledgment, which is essential evidence of a compliance program's communication efforts.
A policy review triggered by a regulatory change should be classified as a: