CCB Policy Development & Implementation 5 — Questions and Answers
Question 1: Which element of a written policy ensures readers can identify the most current version and avoid applying outdated rules?
- The policy rationale
- Version number and effective date in the document header (Correct answer)
- The list of policy exceptions already granted
- The signature of the original author
Correct answer: Version number and effective date in the document header
Version numbers and effective dates allow users to confirm they are referencing the current, approved policy rather than an outdated revision.
Question 2: A company's board has approved a new data retention policy but the IT department reports it is technically impossible to implement as written. The compliance officer should:
- Ignore the IT feedback and proceed with implementation
- Facilitate a revision process involving IT, legal, and compliance to make the policy operationally viable (Correct answer)
- Implement the policy and document the inability to comply as a known gap
- Withdraw the policy and abandon data retention compliance entirely
Correct answer: Facilitate a revision process involving IT, legal, and compliance to make the policy operationally viable
Policies must be operationally feasible; a cross-functional revision process ensures the policy achieves its compliance objective within technical constraints.
Question 3: When communicating a significant policy change that affects all employees, which approach is MOST effective for ensuring comprehension?
- Sending a single all-staff email with the full policy text attached
- Using multi-channel communication including training, Q&A sessions, and concise summaries (Correct answer)
- Posting the updated policy on the intranet without announcement
- Notifying only department heads and letting them cascade information informally
Correct answer: Using multi-channel communication including training, Q&A sessions, and concise summaries
Multi-channel communication increases reach and comprehension by reinforcing the message through multiple formats and opportunities for questions.
Question 4: In policy development, a 'stakeholder comment period' is PRIMARILY used to:
- Delay policy approval until all objections are resolved
- Gather feedback from affected parties to identify gaps or unintended consequences before finalization (Correct answer)
- Allow employees to vote on whether the policy is necessary
- Satisfy a regulatory requirement for public notice
Correct answer: Gather feedback from affected parties to identify gaps or unintended consequences before finalization
Comment periods surface practical concerns, legal issues, or operational impacts that drafters may have missed, improving policy quality before approval.
Question 5: A compliance manager is building a policy for insider trading prevention. Which control is MOST critical to include in the implementation plan?
- A requirement that all employees take a photography course
- Mandatory blackout periods, pre-clearance procedures, and annual training for covered persons (Correct answer)
- A policy limiting the number of stock exchanges employees may use
- A ban on employees owning any personal investment accounts
Correct answer: Mandatory blackout periods, pre-clearance procedures, and annual training for covered persons
Blackout periods, pre-clearance, and training are the core controls required by securities laws and SEC guidance to prevent and detect insider trading.
Question 6: What distinguishes a 'policy' from a 'procedure' in a compliance governance framework?
- Policies are optional; procedures are mandatory
- A policy states what must be done and why; a procedure describes step-by-step how to do it (Correct answer)
- Procedures are approved by the board; policies are approved by managers
- Policies apply to external parties; procedures apply only internally
Correct answer: A policy states what must be done and why; a procedure describes step-by-step how to do it
Policies establish the 'what' and 'why' at a high level, while procedures operationalize the policy by detailing the specific steps required.
Question 7: An organization's compliance team conducts a post-implementation review 90 days after a new policy goes live. The PRIMARY goal of this review is to:
- Identify employees who have not yet signed the attestation
- Assess whether the policy is achieving its intended compliance outcomes and identify needed adjustments (Correct answer)
- Calculate the cost savings from eliminating previous informal practices
- Prepare the policy for submission to external regulators
Correct answer: Assess whether the policy is achieving its intended compliance outcomes and identify needed adjustments
A post-implementation review evaluates real-world policy effectiveness and surfaces gaps or unintended consequences that require corrective action.
Which element of a written policy ensures readers can identify the most current version and avoid applying outdated rules?