CCB Regulatory Compliance & Risk Management 2 — Questions and Answers
Question 1: Under the Bank Secrecy Act (BSA), what is the threshold amount that triggers a Currency Transaction Report (CTR)?
- $5,000
- $10,000 (Correct answer)
- $25,000
- $50,000
Correct answer: $10,000
The BSA requires financial institutions to file a CTR for any cash transaction exceeding $10,000 in a single business day.
Question 2: Which risk management framework published by COSO is most widely used for enterprise risk management?
- ISO 31000
- COSO ERM 2017 (Correct answer)
- NIST RMF
- Basel III
Correct answer: COSO ERM 2017
The COSO Enterprise Risk Management – Integrating with Strategy and Performance (2017) framework is the most widely referenced ERM standard globally.
Question 3: A company discovers that a vendor is processing personal data in a non-compliant manner under GDPR. What is the organization's PRIMARY obligation?
- Immediately terminate the vendor contract
- Notify regulators within 24 hours
- Ensure a Data Processing Agreement is in place and remediate non-compliance (Correct answer)
- Suspend all data transfers until an audit is complete
Correct answer: Ensure a Data Processing Agreement is in place and remediate non-compliance
Under GDPR Article 28, controllers must have a Data Processing Agreement with vendors and ensure compliance; termination is a last resort after remediation attempts.
Question 4: What does 'residual risk' refer to in risk management?
- The total risk before any controls are applied
- The risk remaining after controls and mitigation measures are implemented (Correct answer)
- Risks that cannot be identified in advance
- The financial cost of a risk event
Correct answer: The risk remaining after controls and mitigation measures are implemented
Residual risk is the level of risk that remains after an organization has applied its risk controls and mitigation strategies.
Question 5: Which of the following best describes the purpose of a compliance gap analysis?
- To calculate the financial penalties for non-compliance
- To identify differences between current practices and required regulatory standards (Correct answer)
- To train employees on new regulations
- To document completed compliance audits
Correct answer: To identify differences between current practices and required regulatory standards
A gap analysis compares an organization's current compliance posture to regulatory requirements to identify areas needing remediation.
Question 6: Under the Sarbanes-Oxley Act (SOX), which section specifically requires management to assess and report on internal controls over financial reporting?
- Section 302
- Section 404 (Correct answer)
- Section 802
- Section 906
Correct answer: Section 404
SOX Section 404 mandates that management assess and report on the effectiveness of internal controls over financial reporting, with external auditor attestation.
Question 7: An organization uses a 'risk appetite statement' primarily to:
- Determine the budget for compliance activities
- Communicate the level of risk the organization is willing to accept in pursuit of its objectives (Correct answer)
- Identify all existing risks in the organization
- Assign accountability for risk mitigation to specific departments
Correct answer: Communicate the level of risk the organization is willing to accept in pursuit of its objectives
A risk appetite statement defines and communicates the amount and type of risk an organization is willing to accept to achieve its strategic goals.
Under the Bank Secrecy Act (BSA), what is the threshold amount that triggers a Currency Transaction Report (CTR)?