CCB Regulatory Compliance & Risk Management 4 — Questions and Answers
Question 1: A compliance officer discovers that an employee self-reported a potential policy violation before it caused any harm. What is the BEST initial response?
- Immediately escalate to law enforcement
- Investigate the report, protect the whistleblower, and remediate the issue (Correct answer)
- Terminate the employee for admitting wrongdoing
- Ignore the report if no harm occurred
Correct answer: Investigate the report, protect the whistleblower, and remediate the issue
Best practice is to investigate thoroughly, protect the reporting employee from retaliation, and use the finding to remediate the root cause.
Question 2: Under the Dodd-Frank Act, which agency has authority to bring enforcement actions against covered financial institutions for unfair, deceptive, or abusive acts or practices (UDAAP)?
- The SEC
- The CFPB (Correct answer)
- The OCC
- The FDIC
Correct answer: The CFPB
The Consumer Financial Protection Bureau (CFPB), created by Dodd-Frank, has primary authority to enforce UDAAP standards against financial institutions.
Question 3: What is 'inherent risk' in the context of risk assessments?
- Risk that exists after mitigation controls are applied
- Risk that exists naturally in a process or activity before any controls are implemented (Correct answer)
- Risk introduced by third-party vendors
- Risk related to information technology systems only
Correct answer: Risk that exists naturally in a process or activity before any controls are implemented
Inherent risk is the level of risk in the absence of any controls or mitigating factors, representing the raw exposure to a particular threat.
Question 4: Which international standard provides guidance on anti-bribery management systems for organizations?
- ISO 9001
- ISO 37001 (Correct answer)
- ISO 27001
- ISO 14001
Correct answer: ISO 37001
ISO 37001 specifies requirements for establishing, implementing, and maintaining an anti-bribery management system to help organizations prevent and detect bribery.
Question 5: A Key Risk Indicator (KRI) is BEST described as:
- A measure of the financial loss from a past risk event
- A forward-looking metric that signals the potential increase in risk exposure (Correct answer)
- A regulatory requirement for annual risk reporting
- A list of all identified risks in the organization's risk register
Correct answer: A forward-looking metric that signals the potential increase in risk exposure
KRIs are predictive metrics that provide early warning signals of increasing risk, enabling proactive management before risks materialize into losses.
Question 6: Under HIPAA, which rule specifically governs the security of electronic protected health information (ePHI)?
- The Privacy Rule
- The Security Rule (Correct answer)
- The Breach Notification Rule
- The Omnibus Rule
Correct answer: The Security Rule
The HIPAA Security Rule establishes national standards to protect individuals' electronic protected health information through administrative, physical, and technical safeguards.
Question 7: A company operating in multiple states must navigate conflicting state privacy laws. This challenge is BEST managed by:
- Applying the least restrictive state's standards across all operations
- Applying the most restrictive applicable standards enterprise-wide as a baseline (Correct answer)
- Lobbying for federal preemption of all state privacy laws
- Establishing separate compliance programs for each state without coordination
Correct answer: Applying the most restrictive applicable standards enterprise-wide as a baseline
Adopting the most restrictive applicable standard as an enterprise baseline ensures compliance across all jurisdictions and simplifies the compliance program.
A compliance officer discovers that an employee self-reported a potential policy violation before it caused any harm.
What is the BEST initial response?