CCB Regulatory Compliance & Risk Management 5 — Questions and Answers
Question 1: Which of the following is an example of a 'detective' control in an internal control framework?
- Requiring dual authorization for payments over $50,000
- Conducting monthly bank reconciliations to identify discrepancies (Correct answer)
- Encrypting sensitive data before transmission
- Training employees on anti-fraud policies
Correct answer: Conducting monthly bank reconciliations to identify discrepancies
Detective controls, like bank reconciliations, are designed to identify errors or fraud after they have occurred, rather than preventing them.
Question 2: When performing third-party risk due diligence, which factor is MOST critical to evaluate for a vendor handling sensitive customer data?
- The vendor's geographic location
- The vendor's information security practices and data breach history (Correct answer)
- The vendor's marketing budget
- The vendor's number of employees
Correct answer: The vendor's information security practices and data breach history
For vendors handling sensitive data, evaluating their information security posture and incident history is critical to assessing the risk they pose to your organization.
Question 3: A compliance program's effectiveness is BEST measured by:
- The number of policies and procedures in place
- The absence of any regulatory fines or enforcement actions
- A combination of output metrics, culture assessments, and compliance incident trends (Correct answer)
- The size of the compliance department budget
Correct answer: A combination of output metrics, culture assessments, and compliance incident trends
Effective compliance measurement uses multiple indicators including qualitative culture measures and quantitative incident trends, not just lagging indicators like fines.
Question 4: The 'right of erasure' (also known as the 'right to be forgotten') under GDPR allows individuals to:
- Opt out of all marketing communications permanently
- Request that their personal data be deleted under certain circumstances (Correct answer)
- Access a complete copy of all personal data held by an organization
- Correct inaccurate personal data held by a company
Correct answer: Request that their personal data be deleted under certain circumstances
GDPR Article 17 grants individuals the right to request deletion of their personal data when it is no longer necessary, consent is withdrawn, or processing is unlawful.
Question 5: Under the Equal Credit Opportunity Act (ECOA), a lender must notify an applicant of adverse action within how many days of receiving a completed credit application?
- 15 days
- 30 days (Correct answer)
- 45 days
- 60 days
Correct answer: 30 days
ECOA requires lenders to notify applicants of adverse action within 30 days of receiving a completed credit application.
Question 6: In risk management, 'concentration risk' refers to:
- The risk that employees will not focus during compliance training
- Excessive exposure to a single counterparty, sector, or geographic region that could cause significant loss (Correct answer)
- The risk of regulators focusing audits on a specific business line
- The risk of data being concentrated in a single unprotected database
Correct answer: Excessive exposure to a single counterparty, sector, or geographic region that could cause significant loss
Concentration risk arises when an organization has overexposure to a single entity, industry, or geography, making it vulnerable if that area experiences a downturn.
Question 7: A compliance officer is asked to assess the regulatory risk of launching a new product. Which step should be performed FIRST?
- Draft the marketing materials for the new product
- Identify all applicable laws, regulations, and regulatory guidance relevant to the product (Correct answer)
- File a pre-launch notification with all relevant regulators
- Conduct customer focus groups to test product messaging
Correct answer: Identify all applicable laws, regulations, and regulatory guidance relevant to the product
The first step in regulatory risk assessment is to map all applicable regulatory requirements so that the full compliance obligation landscape is understood before any other steps.
Which of the following is an example of a 'detective' control in an internal control framework?