Certified Compliance & Ethics Professional (CCEP) — Corporate Compliance Professional — Questions and Answers
Question 1: What is control testing?
- Building new procedures.
- Testing employees' patience.
- Conducting product launches.
- Evaluating control effectiveness (Correct answer)
Correct answer: Evaluating control effectiveness
Control testing is a critical component of internal control systems, involving the systematic evaluation of whether established controls are operating as intended and effectively mitigating identified risks. This process helps determine if controls are designed appropriately and functioning efficiently to prevent or detect errors and fraud. Regular control testing ensures the ongoing reliability and integrity of an organization's processes.
Question 2: How does the concept of 'beneficial ownership' factor into third-party due diligence under U.S. compliance standards?
- It involves identifying the actual human beings who ultimately own or control a third party to detect hidden conflicts or sanctions exposure (Correct answer)
- It restricts third-party contracts to publicly traded companies only
- It applies exclusively to financial institution vendors under FinCEN rules
- It requires companies to disclose their own ownership structure to vendors
Correct answer: It involves identifying the actual human beings who ultimately own or control a third party to detect hidden conflicts or sanctions exposure
Understanding who ultimately owns or controls a vendor helps detect sanctioned individuals, politically exposed persons, or undisclosed conflicts of interest that screening on entity names alone would miss.
Question 3: An executive proposes that compliance updates be embedded in the CFO's financial presentation to save board meeting time. The compliance officer should:
- Advocate for a separate compliance agenda item to ensure independent oversight visibility (Correct answer)
- Reduce all compliance reporting to a single footnote in financial statements
- Eliminate board-level compliance reporting entirely
- Agree fully, since financial and compliance matters are equivalent
Correct answer: Advocate for a separate compliance agenda item to ensure independent oversight visibility
Embedding compliance in financial presentations undermines independent compliance oversight and can obscure material risks from directors.
Question 4: What is the PRIMARY purpose of a Key Risk Indicator (KRI)?
- To provide early warning signals of increasing risk exposure (Correct answer)
- To measure the effectiveness of past controls
- To assign ownership of a specific risk
- To document the root cause of a risk event
Correct answer: To provide early warning signals of increasing risk exposure
KRIs are forward-looking metrics that signal when risk levels are trending toward or beyond acceptable thresholds before an event occurs.
Question 5: Under the FTC Act Section 5, what type of data security practice can constitute an unfair or deceptive act?
- Implementing multi-factor authentication
- Encrypting data in transit using TLS 1.2 or higher
- Failing to implement reasonable data security measures after promising consumers their data is secure (Correct answer)
- Conducting annual penetration tests
Correct answer: Failing to implement reasonable data security measures after promising consumers their data is secure
The FTC has authority to take action against companies that fail to implement reasonable data security, particularly when their practices contradict privacy policy promises made to consumers.
Question 6: A compliance officer is reviewing vendor contracts for data processing agreements. Under GDPR Article 28, which element is NOT required in a data processing agreement?
- Subject matter and duration of processing
- Instructions for returning or deleting data after processing ends
- The processor's right to subcontract without controller notice (Correct answer)
- Security measures the processor must implement
Correct answer: The processor's right to subcontract without controller notice
GDPR Article 28 requires processors to obtain prior written authorization from the controller before engaging sub-processors, not a unilateral right to subcontract.
Question 7: Under the Dodd-Frank whistleblower program, an employee who first reports internally before going to the SEC is treated as if they reported to the SEC on which date?
- The date the SEC receives the complaint
- The date of the internal report, provided they report to the SEC within 120 days (Correct answer)
- The date the employee retains legal counsel
- The date the employer completes its internal investigation
Correct answer: The date of the internal report, provided they report to the SEC within 120 days
SEC rules allow whistleblowers who first report internally to receive credit as of their internal report date if they subsequently report to the SEC within 120 days.
Question 8: A 'clawback' policy in executive compensation is designed to:
- Cap total annual compensation at a fixed multiple of median worker pay
- Require board approval before bonuses are paid
- Recover compensation paid based on subsequently restated financial results (Correct answer)
- Prevent executives from selling shares during blackout periods
Correct answer: Recover compensation paid based on subsequently restated financial results
Clawback policies allow companies to recoup incentive pay when financial results that triggered the pay are later found to be inaccurate.
Question 9: Which of the following is the MOST significant indicator that a compliance program is 'paper only' (not effective in practice)?
- The compliance training has not been updated in 18 months
- Compliance policies are not translated into every language spoken by employees
- Employees are unaware of the policies, and management does not enforce them consistently (Correct answer)
- Policies are stored in a digital repository rather than printed binders
Correct answer: Employees are unaware of the policies, and management does not enforce them consistently
A 'paper program' exists formally but is not integrated into actual operations; the clearest sign is employees not knowing about it and management not enforcing it.
Question 10: What is 'middle management squeeze' in the context of corporate ethics programs?
- A regulatory requirement for mid-level manager certification in ethics
- The challenge of delivering ethics content to employees across multiple time zones
- Pressure on middle managers caught between upper management demands and frontline ethical concerns (Correct answer)
- Budget constraints that limit compliance training for managers
Correct answer: Pressure on middle managers caught between upper management demands and frontline ethical concerns
Middle managers often face pressure from above to meet targets while also fielding ethical concerns from below, making them a critical and vulnerable compliance layer.
Question 11: Which control activity is MOST effective at detecting unauthorized access to sensitive systems after the fact?
- Role-based access controls
- Multi-factor authentication
- Access control lists
- System access log reviews (Correct answer)
Correct answer: System access log reviews
Reviewing system access logs is a detective control that identifies unauthorized or suspicious access activities after they have occurred.
Question 12: How should a compliance program handle an employee's report made in good faith that turns out to be unsubstantiated?
- Require the employee to retract the report in writing
- Discipline the employee for wasting investigative resources
- Document the closure and thank the employee for raising the concern (Correct answer)
- Treat the reporter as a whistleblower and take no adverse action
Correct answer: Document the closure and thank the employee for raising the concern
Good-faith reporters should be thanked and protected from retaliation even when investigations find no wrongdoing, reinforcing the speak-up culture.
Question 13: When a company undergoes a major reorganization, what is the compliance officer's immediate responsibility regarding the Code of Conduct?
- Transfer all Code of Conduct oversight to Human Resources permanently
- Assess whether the reorganization creates new risk areas requiring updates to policies, training, and reporting lines (Correct answer)
- Suspend the Code of Conduct until the reorganization is complete
- Reissue the existing Code of Conduct without changes to save time
Correct answer: Assess whether the reorganization creates new risk areas requiring updates to policies, training, and reporting lines
Reorganizations often create new reporting structures, risk exposures, and accountability gaps that require prompt compliance program reassessment.
Question 14: What does 'obstruction of justice' in a corporate investigation context most commonly involve?
- Refusing to voluntarily disclose potential violations before they are discovered
- Asserting attorney-client privilege over internal investigation findings
- Destroying documents, coaching witnesses, or impeding government access to evidence (Correct answer)
- Failing to appoint an independent compliance monitor as required by a consent decree
Correct answer: Destroying documents, coaching witnesses, or impeding government access to evidence
Obstruction of justice typically involves actions like document destruction, witness tampering, or any effort to impede the government's ability to gather evidence in an investigation.
Question 15: When a U.S. company's foreign subsidiary makes a payment to a government official to expedite a routine customs clearance, this most likely violates which law?
- The Export Administration Regulations
- The International Emergency Economic Powers Act
- The Bank Secrecy Act
- The Foreign Corrupt Practices Act (Correct answer)
Correct answer: The Foreign Corrupt Practices Act
The FCPA prohibits U.S. companies and their foreign subsidiaries from making payments to foreign government officials to obtain or retain business, including facilitation payments above de minimis thresholds.
Question 16: During a board meeting, a director asks the CCO a question about a specific employee investigation. The CCO should:
- Provide all investigation documents to the full board immediately
- Answer fully in open session to demonstrate transparency
- Decline to answer and leave the meeting
- Defer to counsel and offer to discuss in executive session to protect confidentiality (Correct answer)
Correct answer: Defer to counsel and offer to discuss in executive session to protect confidentiality
Active investigations require confidentiality protections; executive session with counsel preserves privilege and prevents prejudice.
Question 17: In an SEC enforcement action, what is a 'Wells Notice' and what does it signal?
- An offer by the SEC to settle enforcement proceedings without a formal admission of wrongdoing
- A formal notification that the SEC has decided to file charges against a respondent
- A court order directing a company to preserve all documents related to an investigation
- A preliminary notice informing a party that SEC staff intends to recommend enforcement action, allowing a response (Correct answer)
Correct answer: A preliminary notice informing a party that SEC staff intends to recommend enforcement action, allowing a response
A Wells Notice informs the recipient that SEC staff plans to recommend enforcement action and invites a Wells Submission—the recipient's opportunity to argue against bringing charges.
Question 18: Under the concept of 'compliance program effectiveness,' what does 'operationalization' mean?
- Embedding compliance requirements into day-to-day business processes and decision-making (Correct answer)
- Hiring a dedicated compliance operations manager
- Establishing a compliance operations center in a low-risk jurisdiction
- Publishing compliance policies on the company website
Correct answer: Embedding compliance requirements into day-to-day business processes and decision-making
Operationalization means integrating compliance controls and expectations directly into business workflows so that compliance occurs naturally as part of normal operations.
Question 19: When a CCCP professional encounters an unfamiliar challenge in board & executive communication, what is the recommended first course of action?
- Apply the solution used for the most recent similar problem without adaptation
- Proceed based on personal intuition alone
- Research applicable standards, consult with subject matter experts, and document the approach (Correct answer)
- Postpone addressing the issue indefinitely
Correct answer: Research applicable standards, consult with subject matter experts, and document the approach
Professional practice requires a methodical approach to unfamiliar challenges: research the applicable standards, consult experts when needed, and document the reasoning for the chosen approach.
Question 20: The 'tone at the top' concept in corporate governance primarily refers to:
- The pitch and frequency of internal communications
- Board approval of the annual ethics report
- The compliance department's authority to discipline employees
- Senior leadership's visible commitment to ethical conduct and compliance (Correct answer)
Correct answer: Senior leadership's visible commitment to ethical conduct and compliance
Tone at the top reflects the ethical culture set by senior leaders through their words, actions, and decision-making priorities.
Question 21: How often should a compliance officer present a comprehensive program update to the full board, at minimum?
- Annually, with interim audit committee updates as needed (Correct answer)
- Monthly, with full metrics every time
- Only when regulators request it
- Every five years at strategic planning sessions
Correct answer: Annually, with interim audit committee updates as needed
Best practice calls for at least annual full-board compliance updates, supplemented by more frequent audit committee engagement.
Question 22: Which of the following BEST describes the 'duty to inquire' concept relevant to board compliance oversight?
- Directors must ask probing questions when red flags suggest compliance weaknesses (Correct answer)
- Regulators must be asked to explain each new rule
- The CCO must inquire about all board members' personal finances
- The board must audit every transaction personally
Correct answer: Directors must ask probing questions when red flags suggest compliance weaknesses
The duty to inquire requires directors to probe deeper when warning signs emerge, rather than accepting management's assurances passively.
Question 23: What is a hotline in the context of compliance?
- A confidential reporting channel (Correct answer)
- An internal marketing number.
- A tool for IT support only.
- A customer service call line.
Correct answer: A confidential reporting channel
In the context of compliance, a hotline is a confidential and often anonymous channel that employees can use to report suspected violations of laws, regulations, or company policies. It serves as a critical tool for detecting misconduct early, fostering a culture of integrity, and ensuring that concerns are addressed promptly and appropriately without fear of retaliation.
Question 24: Which risk appetite framework component defines the maximum level of risk an organization is willing to accept before action is required?
- Risk appetite statement
- Risk capacity
- Risk tolerance
- Risk threshold (Correct answer)
Correct answer: Risk threshold
Risk threshold is the specific level at which a risk triggers mandatory escalation or corrective action.
Question 25: The Federal Sentencing Guidelines for Organizations (FSGO) allow courts to reduce a company's culpability score for an effective compliance program. Which factor would INCREASE the culpability score under the FSGO?
- High-level personnel were involved in or condoned the offense (Correct answer)
- The company had a formal code of conduct and ethics hotline
- The company self-reported the offense to appropriate authorities
- The company cooperated fully with the government investigation
Correct answer: High-level personnel were involved in or condoned the offense
Under the FSGO, the culpability score is multiplied upward when high-level personnel participated in, condoned, or were willfully ignorant of the offense, reflecting the organization's greater culpability.
Question 26: What is the primary compliance risk associated with having a Code of Conduct that employees must 'acknowledge' but not meaningfully understand?
- Mandatory external audit requirements under SEC rules
- Higher legal costs for document preparation
- Increased regulatory filing requirements
- A false sense of compliance without actual behavioral change or risk mitigation (Correct answer)
Correct answer: A false sense of compliance without actual behavioral change or risk mitigation
Checkbox acknowledgment without genuine understanding creates a paper compliance program that fails to reduce actual misconduct risk.
Question 27: Why should internal controls be reviewed regularly?
- To delay reporting cycles.
- To transfer all responsibilities externally.
- To eliminate them permanently.
- To ensure effectiveness over time (Correct answer)
Correct answer: To ensure effectiveness over time
Internal controls are not static; their effectiveness can diminish due to changes in business processes, technology, personnel, or external regulations. Regular review and testing are essential to identify any weaknesses, inefficiencies, or outdated controls and to make necessary adjustments. This continuous monitoring ensures that controls remain robust and continue to provide adequate protection against risks.
Question 28: Which U.S. government agencies have primary enforcement authority over the FCPA?
- FBI and CIA
- DOJ and SEC (Correct answer)
- OFAC and FinCEN
- FTC and CFPB
Correct answer: DOJ and SEC
The Department of Justice (DOJ) enforces the FCPA's criminal anti-bribery provisions, while the Securities and Exchange Commission (SEC) enforces the civil anti-bribery and accounting provisions against issuers.
Question 29: Which of the following improves corporate governance?
- Using external financial services.
- Reducing board size to 1.
- Appointing independent board members (Correct answer)
- Hiring relatives to the board.
Correct answer: Appointing independent board members
Appointing independent board members significantly improves corporate governance by bringing objective perspectives and reducing potential conflicts of interest. Independent directors are not part of the company's management and do not have material relationships with the company, allowing them to provide unbiased oversight and challenge management decisions effectively. This enhances accountability and protects shareholder interests.
Question 30: Under the HIPAA Breach Notification Rule, covered entities must notify HHS of breaches affecting fewer than 500 individuals:
- Within 60 days of discovery
- Within 10 business days of discovery
- Within 60 days of the calendar year end in which the breach occurred (Correct answer)
- Within 30 days of the calendar year end in which the breach occurred
Correct answer: Within 60 days of the calendar year end in which the breach occurred
For breaches affecting fewer than 500 individuals, covered entities must notify HHS no later than 60 days after the end of the calendar year in which the breach was discovered.
Question 31: A company experiences a ransomware attack that encrypts employee PII. Under HIPAA, when must breach notification to HHS be submitted if fewer than 500 individuals are affected?
- Within 60 days after the end of the calendar year (Correct answer)
- Within 90 days of discovery
- Within 30 days of discovery
- Within 60 days of discovery
Correct answer: Within 60 days after the end of the calendar year
HIPAA requires covered entities to notify HHS of breaches affecting fewer than 500 individuals within 60 days after the end of the calendar year in which the breach occurred.
Question 32: What is the primary purpose of a 'deferred prosecution agreement' (DPA) in a corporate investigation?
- To transfer prosecution responsibility to state authorities
- To allow a company to avoid conviction by meeting certain conditions over a set period (Correct answer)
- To permanently close an investigation without any corporate admissions
- To grant full immunity to all corporate officers named in the indictment
Correct answer: To allow a company to avoid conviction by meeting certain conditions over a set period
A DPA allows prosecutors to defer criminal charges against a company in exchange for the company meeting specific conditions such as paying fines, implementing compliance programs, and cooperating with ongoing investigations.
Question 33: Which of the following best describes 'tone at the top' in the context of ethics and compliance?
- The volume of compliance communications sent to employees
- The ratio of ethics training hours to total work hours
- The number of compliance policies issued each quarter
- Senior leadership's visible commitment to ethical behavior and compliance values (Correct answer)
Correct answer: Senior leadership's visible commitment to ethical behavior and compliance values
'Tone at the top' refers to the demonstrated commitment of senior leadership to ethical conduct, which shapes the entire organization's compliance culture.
Question 34: A hospital's compliance officer discovers that a nurse accessed the medical records of a celebrity patient out of curiosity. Under HIPAA, this is best characterized as:
- A permitted disclosure under the treatment exception
- A breach requiring no further action if the data was not shared
- A minor infraction exempt from HIPAA penalties
- An impermissible use of PHI that may constitute a reportable breach (Correct answer)
Correct answer: An impermissible use of PHI that may constitute a reportable breach
Accessing PHI without a permissible purpose—even without external disclosure—is an impermissible use that must be evaluated under the Breach Notification Rule.
Question 35: A compliance officer discovers that controls designed to prevent money laundering are operating but are insufficient to reduce risk to an acceptable level. The BEST next step is to:
- Implement additional or enhanced compensating controls (Correct answer)
- Accept the residual risk and document the decision
- Report the deficiency to external auditors immediately
- Terminate the business activity generating the risk
Correct answer: Implement additional or enhanced compensating controls
When existing controls are insufficient, the appropriate response is to strengthen or add compensating controls to close the gap before considering acceptance or escalation.
Question 36: In the context of CCCP certification, what is the most important consideration when implementing government investigation response?
- Ensuring alignment with established standards, stakeholder needs, and best practices (Correct answer)
- Completing implementation as quickly as possible regardless of quality
- Delegating all responsibilities to junior staff
- Minimizing documentation to save time
Correct answer: Ensuring alignment with established standards, stakeholder needs, and best practices
When implementing government investigation response, CCCP professionals must ensure alignment with industry standards and stakeholder needs. Hasty implementation without proper planning often leads to compliance issues and suboptimal outcomes.
Question 37: How should CCCP professionals handle confidential information related to board & executive communication?
- Share freely with all colleagues for transparency
- Delete all records after project completion
- Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations (Correct answer)
- Store information without any security measures
Correct answer: Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations
Confidential information must be handled according to established protocols, regulatory requirements, and professional ethics standards, including proper access control and disclosure procedures.
Question 38: A US bank discovers it processed wire transfers for a customer later designated as a Specially Designated National (SDN) by OFAC. The transactions occurred before the designation. What is the bank's primary obligation?
- Reverse all prior transactions retroactively and notify the affected customer
- Immediately freeze all accounts and report to OFAC within 10 business days (Correct answer)
- Terminate the customer relationship without any reporting obligation
- File a Suspicious Activity Report (SAR) with FinCEN and block future transactions
Correct answer: Immediately freeze all accounts and report to OFAC within 10 business days
Upon discovering that a customer has been designated as an SDN, US financial institutions must block the account, reject future transactions, and report to OFAC within 10 business days.
Question 39: The Stark Law (Physician Self-Referral Law) prohibits a physician from referring Medicare patients for designated health services to an entity in which the physician has a financial relationship, unless:
- A recognized exception applies (Correct answer)
- The referral is for emergency services only
- The referring physician is a hospital employee
- The referring physician discloses the relationship to the patient
Correct answer: A recognized exception applies
The Stark Law is a strict liability statute, so the only way to make a prohibited referral permissible is to fit within a statutory or regulatory exception.
Question 40: Under the FCA's statute of limitations, when does a qui tam action brought by a relator (without government intervention) expire?
- 6 years from the violation or 3 years after the government knew or should have known, not to exceed 10 years (Correct answer)
- 5 years from the date the relator discovered the fraud
- 10 years from the date of the last false claim
- 3 years from the violation date only
Correct answer: 6 years from the violation or 3 years after the government knew or should have known, not to exceed 10 years
The FCA's statute of limitations is 6 years from the violation or 3 years from when the responsible official knew or should have known, whichever is later, capped at 10 years.
Question 41: Under the Anti-Kickback Statute (AKS), which element distinguishes a safe harbor arrangement from a prohibited kickback?
- Safe harbor arrangements must be disclosed to Medicare beneficiaries
- Safe harbor arrangements meet specific criteria that insulate them from prosecution (Correct answer)
- Safe harbor arrangements are only available to non-profit healthcare entities
- Safe harbor arrangements require prior HHS approval
Correct answer: Safe harbor arrangements meet specific criteria that insulate them from prosecution
AKS safe harbors define specific criteria under which remuneration arrangements will not be treated as kickbacks warranting prosecution.
Question 42: Under EU General Data Protection Regulation (GDPR), what is the maximum administrative fine for the most serious violations?
- €10 million or 2% of global annual turnover, whichever is higher
- €50 million flat fine regardless of company size
- €20 million or 4% of global annual turnover, whichever is higher (Correct answer)
- €5 million or 1% of global annual turnover, whichever is higher
Correct answer: €20 million or 4% of global annual turnover, whichever is higher
GDPR's most serious violations (Tier 2) can result in fines up to €20 million or 4% of the company's total global annual turnover from the preceding year, whichever is higher.
Question 43: Which of the following is a recognized 'red flag' indicating a weak ethics culture within an organization?
- Frequent ethics training completion rates above 95%
- High volume of hotline reports relative to employee count
- Low near-miss reporting combined with high actual incident rates (Correct answer)
- Compliance officer reporting directly to the board audit committee
Correct answer: Low near-miss reporting combined with high actual incident rates
Low near-miss reporting with high actual incidents suggests employees are not surfacing concerns early, a key indicator of a weak speak-up culture.
Question 44: Under the Computer Fraud and Abuse Act (CFAA), which action could expose a compliance officer to criminal liability?
- Accessing a computer system without authorization to investigate suspected fraud (Correct answer)
- Conducting authorized penetration testing with written permission
- Monitoring network traffic using company-owned equipment with disclosed policies
- Reviewing employee emails pursuant to a documented retention policy
Correct answer: Accessing a computer system without authorization to investigate suspected fraud
The CFAA prohibits unauthorized access to protected computer systems, and even internal investigators can face liability if they access systems beyond the scope of their authorization.
Question 45: What is the primary role of a compliance monitor appointed as part of a DPA or NPA settlement?
- To independently assess and report on the company's compliance program and remediation efforts (Correct answer)
- To approve all major business transactions during the monitoring period
- To conduct ongoing criminal investigations into company employees on the government's behalf
- To manage day-to-day business operations on behalf of the government during the agreement period
Correct answer: To independently assess and report on the company's compliance program and remediation efforts
A compliance monitor independently evaluates whether the company is meeting its obligations under the agreement, reporting findings to the government without managing company operations.
Question 46: A compliance officer notices that a key control has not been tested in 18 months due to staff turnover. This situation BEST represents which type of risk?
- Reputational risk
- Operational risk — people and process failure (Correct answer)
- Systemic risk
- Strategic risk
Correct answer: Operational risk — people and process failure
The failure to execute a control due to staff turnover is an operational risk arising from inadequate people and process management within the compliance function itself.
Question 47: Which regulatory body must approve certain financial institution mergers in the United States beyond standard antitrust review?
- Securities and Exchange Commission (SEC)
- Department of Labor (DOL)
- Office of the Comptroller of the Currency (OCC), Federal Reserve, or FDIC depending on charter (Correct answer)
- Consumer Financial Protection Bureau (CFPB)
Correct answer: Office of the Comptroller of the Currency (OCC), Federal Reserve, or FDIC depending on charter
Bank mergers require approval from the relevant federal banking regulator (OCC, Fed, or FDIC) based on the institutions' charter types, in addition to DOJ antitrust review.
Question 48: Which body is responsible for administering the CCCP certification in the United States?
- The Society of Corporate Compliance and Ethics (SCCE) (Correct answer)
- The Securities and Exchange Commission (SEC)
- The U.S. Department of Justice (DOJ)
- The American Bar Association (ABA)
Correct answer: The Society of Corporate Compliance and Ethics (SCCE)
The Society of Corporate Compliance and Ethics (SCCE) administers the CCCP certification for corporate compliance professionals.
Question 49: What is the compliance officer's role in an ethics hotline program?
- To ensure the hotline is accessible, confidential, and that reports are properly triaged and investigated (Correct answer)
- To share all hotline reports directly with regulators quarterly
- To personally investigate every hotline report without delegation
- To discourage use of the hotline to reduce workload
Correct answer: To ensure the hotline is accessible, confidential, and that reports are properly triaged and investigated
The compliance officer ensures the hotline is operational, confidential, non-retaliatory, and that all reports receive appropriate follow-up and investigation.
Question 50: A company settles an FCA case without admitting liability. What is the typical compliance obligation imposed in the settlement agreement?
- A Corporate Integrity Agreement (CIA) with the HHS Office of Inspector General (Correct answer)
- An immediate debarment period
- A mandatory criminal guilty plea
- Appointment of a government-selected CEO
Correct answer: A Corporate Integrity Agreement (CIA) with the HHS Office of Inspector General
Healthcare FCA settlements frequently require a CIA with HHS-OIG, imposing monitoring, compliance program requirements, and reporting obligations for typically 5 years.
Question 51: A whistleblower complaint alleges misconduct by the CEO. The CCO should report this FIRST to:
- The CEO directly to allow a response
- The independent directors or audit committee, bypassing the CEO (Correct answer)
- The SEC before conducting an internal investigation
- All employees via an internal announcement
Correct answer: The independent directors or audit committee, bypassing the CEO
When the alleged wrongdoer is the CEO, the CCO must bypass that individual and report directly to independent board members.
Question 52: A pharmaceutical company pays a kickback to physicians who prescribe its drug covered by Medicaid. Under the FCA, why does this typically constitute a false claim?
- The drug is presumed ineffective when kickbacks are paid
- It converts the claim into a criminal matter only
- Pharmaceutical companies are per se FCA violators
- Claims tainted by Anti-Kickback Statute violations are deemed false under the FCA (Correct answer)
Correct answer: Claims tainted by Anti-Kickback Statute violations are deemed false under the FCA
The ACA explicitly made AKS violations a per se false claim under the FCA, so any Medicaid or Medicare claim tainted by an illegal kickback is actionable.
Question 53: What does FCPA stand for?
- Foreign Corporate Procurement Act
- Federal Compliance and Penalties Act
- Foreign Corrupt Practices Act (Correct answer)
- Financial Crime Prevention Act
Correct answer: Foreign Corrupt Practices Act
The Foreign Corrupt Practices Act (FCPA) is a U.S. law enacted in 1977 that prohibits bribery of foreign government officials by U.S. persons and companies.
Question 54: What does it mean for a company to 'toll' the statute of limitations during a government investigation negotiation?
- The government obtains a court order freezing the company's assets during the investigation period
- The company waives its right to assert a statute of limitations defense in exchange for cooperation credit
- The company pays a fee to extend the time period in which regulators may bring charges
- The company agrees to temporarily suspend the running of the statute of limitations while negotiations with the government are ongoing (Correct answer)
Correct answer: The company agrees to temporarily suspend the running of the statute of limitations while negotiations with the government are ongoing
Tolling agreements allow both parties to pause the limitations clock during negotiations, giving the government time to complete its investigation without rushing to file charges prematurely.
Question 55: When a company receives a grand jury subpoena for documents, what is the immediate first step compliance should take?
- Begin collecting and reviewing all responsive documents
- Instruct employees to delete non-essential files to reduce scope
- Issue a litigation hold to preserve all potentially relevant records (Correct answer)
- Notify the SEC within 24 hours of receipt
Correct answer: Issue a litigation hold to preserve all potentially relevant records
A litigation hold must be issued immediately upon receipt of a subpoena to prevent spoliation of evidence, which can result in sanctions.
Question 56: Which of the following best describes a key competency required for board & executive communication in CCCP practice?
- Memorization of all relevant regulations without understanding context
- The ability to work independently without any oversight
- Strong analytical skills combined with effective communication and ethical judgment (Correct answer)
- Reliance on a single methodology for all situations
Correct answer: Strong analytical skills combined with effective communication and ethical judgment
CCCP professionals working in board & executive communication need analytical skills to assess situations, communication skills to convey findings, and ethical judgment to make sound decisions.
Question 57: Which of the following represents an effective control for managing gifts and hospitality provided by vendors to company employees?
- Prohibiting all vendor contact with employees outside of formal contract meetings
- Allowing each business unit to set its own gifts and hospitality standards independently
- Implementing a pre-approval and disclosure process with defined thresholds for gifts and hospitality (Correct answer)
- Requiring vendors to pay a compliance fee in lieu of gift restrictions
Correct answer: Implementing a pre-approval and disclosure process with defined thresholds for gifts and hospitality
A pre-approval and disclosure process with defined thresholds creates accountability, transparency, and a paper trail that deters improper influence.
Question 58: Which of the following is a best practice for managing compliance risk within a company's supply chain?
- Relying solely on industry association certifications for supplier compliance
- Requiring all suppliers to be domiciled in the United States
- Extending compliance expectations, due diligence, and audit rights through multiple supply chain tiers based on risk (Correct answer)
- Limiting compliance requirements to Tier 1 direct suppliers only
Correct answer: Extending compliance expectations, due diligence, and audit rights through multiple supply chain tiers based on risk
Material compliance risks — such as forced labor, bribery, or sanctions violations — can originate in lower supply chain tiers, requiring risk-based oversight beyond Tier 1.
Question 59: What is the significance of the 'public disclosure bar' in the FCA following the 2010 amendments?
- It requires courts to dismiss suits unless the government opposes dismissal
- It permanently bars all relators from suits involving media reports
- It only applies to suits filed after 2010
- It converts from a jurisdictional bar to a defense the government can waive (Correct answer)
Correct answer: It converts from a jurisdictional bar to a defense the government can waive
The 2010 ACA amendments changed the public disclosure bar from a jurisdictional defect to an affirmative defense that the government can waive to allow a suit to proceed.
Question 60: What is the primary purpose of a corporate Code of Conduct in a CCCP-certified compliance program?
- To establish legally binding contracts with employees
- To replace the need for a formal compliance training program
- To serve as the sole disciplinary policy for misconduct
- To articulate the organization's values, principles, and behavioral expectations (Correct answer)
Correct answer: To articulate the organization's values, principles, and behavioral expectations
A Code of Conduct articulates the organization's core values and sets clear behavioral expectations for all employees and stakeholders.
Question 61: Under the Federal Sentencing Guidelines, which factor related to board oversight can MOST significantly reduce an organization's culpability score?
- Publishing an annual CSR report
- Having a large legal department
- Demonstrated high-level personnel responsibility for and oversight of an effective compliance program (Correct answer)
- Maintaining a compliance hotline that is never used
Correct answer: Demonstrated high-level personnel responsibility for and oversight of an effective compliance program
The Guidelines reward organizations where high-level personnel exercise genuine oversight of compliance, reducing culpability and potential fines.
Question 62: A new board director with no compliance background asks the CCO to explain why a regulatory fine was classified as 'low risk' in the annual report. The CCO's BEST response is:
- Provide only the fine dollar amount and move on
- Dismiss the question as outside the director's expertise
- Explain the risk classification criteria, the fine's magnitude relative to thresholds, and remediation status (Correct answer)
- Redirect the director to read the SEC filing without further explanation
Correct answer: Explain the risk classification criteria, the fine's magnitude relative to thresholds, and remediation status
New directors deserve clear explanations of risk classification methodology to perform their oversight function effectively.
Question 63: Under HIPAA's Minimum Necessary Standard, what must a covered entity do when requesting PHI from another covered entity?
- Limit the request to the minimum PHI reasonably needed for the purpose (Correct answer)
- Submit a formal written authorization signed by the patient
- Obtain approval from the HHS Office for Civil Rights
- Request all available PHI to ensure completeness
Correct answer: Limit the request to the minimum PHI reasonably needed for the purpose
The Minimum Necessary Standard requires covered entities to limit PHI requests to only what is reasonably necessary to accomplish the intended purpose.
Question 64: What is 'successor liability' in the context of anti-corruption compliance during mergers and acquisitions?
- The legal obligation to maintain the target company's existing compliance program post-acquisition
- The acquiring company's potential liability for the target company's pre-acquisition FCPA violations (Correct answer)
- The responsibility of the target company's former executives to indemnify the acquirer for undisclosed violations
- The personal liability board members assume when they vote to approve an acquisition
Correct answer: The acquiring company's potential liability for the target company's pre-acquisition FCPA violations
Successor liability means that when a company acquires another, it may inherit legal liability for the target's prior FCPA violations, making pre-acquisition anti-corruption due diligence essential.
Question 65: How should CCCP professionals handle confidential information related to false claims act & whistleblower laws?
- Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations (Correct answer)
- Store information without any security measures
- Delete all records after project completion
- Share freely with all colleagues for transparency
Correct answer: Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations
Confidential information must be handled according to established protocols, regulatory requirements, and professional ethics standards, including proper access control and disclosure procedures.
Question 66: What is the primary limitation of using only quantitative metrics (e.g., training completion rates, hotline call volumes) to assess compliance effectiveness?
- They measure activity but may not capture whether employees actually behave ethically (Correct answer)
- Quantitative metrics cannot be audited
- Regulators do not accept quantitative evidence
- Quantitative data is too expensive to collect
Correct answer: They measure activity but may not capture whether employees actually behave ethically
Quantitative metrics show activity levels but not actual ethical behavior change, culture quality, or real-world application of compliance principles.
Question 67: A director who learns of material non-public information about a competitor during a board meeting should:
- Share the information with analysts to ensure market efficiency
- Refrain from trading in any security affected by the information and maintain confidentiality (Correct answer)
- Disclose the information immediately to the company's investors
- Trade in the competitor's stock before the information becomes public to maximize board returns
Correct answer: Refrain from trading in any security affected by the information and maintain confidentiality
Directors who possess material non-public information are prohibited from trading on it or tipping others under SEC insider trading rules.
Question 68: What role does continuous improvement play in board & executive communication for CCCP certified professionals?
- It is optional and only necessary during certification renewal
- It drives ongoing enhancement of practices, processes, and outcomes through systematic evaluation (Correct answer)
- It focuses exclusively on cost reduction
- It applies only to new professionals in their first year
Correct answer: It drives ongoing enhancement of practices, processes, and outcomes through systematic evaluation
Continuous improvement is fundamental to professional practice in board & executive communication, involving regular evaluation, feedback integration, and process enhancement to maintain high standards.
Question 69: Under the UK Bribery Act 2010, which defense is available to a commercial organization charged with failing to prevent bribery?
- The organization had 'adequate procedures' in place to prevent bribery (Correct answer)
- The organization self-reported the violation within 30 days
- The organization had no prior knowledge of the bribe
- The bribe was paid by a third-party agent, not a direct employee
Correct answer: The organization had 'adequate procedures' in place to prevent bribery
The UK Bribery Act's 'adequate procedures' defense requires that an organization implement proportionate anti-bribery procedures, including third-party controls.
Question 70: How often should a corporate Code of Conduct be reviewed and updated according to best compliance practices?
- Every 10 years or upon merger
- Only upon CEO or board turnover
- Periodically, typically annually or when significant regulatory or business changes occur (Correct answer)
- Only when a regulatory violation occurs
Correct answer: Periodically, typically annually or when significant regulatory or business changes occur
Best practice requires periodic review — often annually — and updates whenever material regulatory, legal, or business changes occur.
Question 71: What is the result of failing to comply with regulations?
- Market monopoly.
- Legal penalties and reputation loss (Correct answer)
- Government awards.
- Fewer audits.
Correct answer: Legal penalties and reputation loss
Failing to comply with regulations can lead to severe consequences for an organization. These often include significant legal penalties such as fines, sanctions, and even imprisonment for individuals, alongside potential operational restrictions. Furthermore, non-compliance severely damages a company's reputation, eroding public trust and potentially leading to loss of customers and market share.
Question 72: A company discovers that two employees in the accounts payable department have been colluding to approve fraudulent invoices. Which control failure does this best illustrate?
- Breakdown in collusion-resistant controls (Correct answer)
- Failure of the tone at the top
- Inadequate segregation of duties
- Insufficient authorization controls
Correct answer: Breakdown in collusion-resistant controls
Collusion-resistant controls are specifically designed to prevent two or more employees from circumventing controls together, and their failure enables collaborative fraud.
Question 73: When presenting a sensitive government subpoena to the board, the CCO should coordinate PRIMARILY with:
- All department heads simultaneously
- Outside counsel and the audit committee chair before any broader disclosure (Correct answer)
- The marketing department to manage public messaging
- The company's largest investor before board notification
Correct answer: Outside counsel and the audit committee chair before any broader disclosure
Government subpoenas require immediate coordination with outside counsel and audit committee leadership to manage legal risk and privilege.
Question 74: When a company employee invokes their Fifth Amendment right during a government investigation, what risk does the company face?
- The government may draw adverse inferences against the company in civil proceedings (Correct answer)
- The company is automatically deemed an uncooperating party by the DOJ
- The employee must be immediately terminated to avoid obstruction liability
- The company loses all attorney-client privilege over related documents
Correct answer: The government may draw adverse inferences against the company in civil proceedings
While individuals have Fifth Amendment rights, in civil proceedings the government and courts may draw adverse inferences from employee invocations in ways that can harm the company.
Question 75: A healthcare organization's compliance program receives an anonymous hotline tip alleging billing fraud. The FIRST step the compliance officer should take is to:
- Notify the board of directors before taking any other action
- Terminate employees named in the tip pending investigation
- Immediately report the allegation to OIG
- Conduct a preliminary assessment to determine whether the allegation has merit (Correct answer)
Correct answer: Conduct a preliminary assessment to determine whether the allegation has merit
A compliance officer should first conduct a preliminary assessment to evaluate the credibility and scope of the allegation before escalating or taking remedial action.
Question 76: A compliance officer notices that policy violations are down 40% year-over-year. What additional data is needed before concluding the compliance program is effective?
- The total number of employees
- Whether the CCO attended industry conferences
- The age of the compliance program
- Whether reporting mechanisms changed or fear of retaliation increased (Correct answer)
Correct answer: Whether reporting mechanisms changed or fear of retaliation increased
A drop in reported violations can reflect improved behavior or a chilling effect on reporting—distinguishing between these is critical.
Question 77: How does the DOJ's 2023 guidance on corporate compliance programs address the evaluation of ethics culture?
- It requires companies to publicly disclose all ethics violations annually
- It mandates that all employees pass an ethics certification exam
- It instructs prosecutors to assess whether compliance programs are adequately resourced, empowered, and actually working (Correct answer)
- It focuses exclusively on financial controls rather than cultural factors
Correct answer: It instructs prosecutors to assess whether compliance programs are adequately resourced, empowered, and actually working
The DOJ's 2023 guidance emphasizes evaluating whether compliance programs are well-resourced, empowered, and producing genuine behavioral outcomes — not just paper policies.
Question 78: What is the compliance officer's role when a whistleblower reports that a key vendor is engaging in fraudulent billing?
- Delay action until the next scheduled vendor performance review
- Conduct or oversee a prompt, objective investigation, preserve evidence, assess legal exposure, and determine whether regulatory disclosure is required (Correct answer)
- Immediately terminate the vendor contract before conducting any investigation
- Refer the matter entirely to the vendor's own internal audit team
Correct answer: Conduct or oversee a prompt, objective investigation, preserve evidence, assess legal exposure, and determine whether regulatory disclosure is required
Vendor fraud requires an independent internal investigation, evidence preservation, and assessment of disclosure obligations — unilateral termination before investigation can destroy evidence and create legal risks.
Question 79: A material weakness in internal controls is BEST defined as:
- A significant deficiency that does not rise to the level of a material weakness
- A minor error in a non-critical business process
- Any control that has failed to operate for more than 30 days
- A deficiency or combination of deficiencies that could result in a material misstatement not being prevented or detected (Correct answer)
Correct answer: A deficiency or combination of deficiencies that could result in a material misstatement not being prevented or detected
A material weakness is a severe internal control deficiency where there is a reasonable possibility that a material misstatement of financial statements would not be prevented or timely detected.
Question 80: Which scenario represents a 'risk transfer' strategy in corporate compliance?
- Stopping a high-risk business line entirely
- Purchasing cyber liability insurance (Correct answer)
- Adding a supervisory approval step to a process
- Strengthening employee training programs
Correct answer: Purchasing cyber liability insurance
Purchasing insurance transfers the financial consequences of a risk event to a third party (the insurer), which is the defining characteristic of a risk transfer strategy.
Question 81: When communicating a newly identified compliance gap to the executive team before board reporting, the CCO should FIRST:
- Assess severity, document findings, and present a preliminary remediation plan to leadership (Correct answer)
- Wait for the annual risk assessment to include the gap
- Escalate to regulators before informing the executive team
- Publicly announce the gap to all employees
Correct answer: Assess severity, document findings, and present a preliminary remediation plan to leadership
Internal documentation with a remediation plan allows the executive team to respond constructively before formal board escalation.
Question 82: A compliance program conducts periodic testing of controls to verify they are operating as designed. This activity is best described as:
- Control design assessment
- Control operating effectiveness testing (Correct answer)
- Gap analysis
- Risk identification
Correct answer: Control operating effectiveness testing
Control operating effectiveness testing evaluates whether controls are actually functioning as intended in practice, not just whether they are well-designed on paper.
Question 83: When evaluating compliance program effectiveness after a significant violation, the DOJ will consider whether the company 'detected the misconduct.' Which program element primarily enables detection?
- Monitoring, auditing, and reporting mechanisms (Correct answer)
- Anti-retaliation training for managers
- Executive compensation clawback policies
- A written code of conduct
Correct answer: Monitoring, auditing, and reporting mechanisms
Monitoring, auditing, and internal reporting channels are the primary mechanisms that enable companies to detect compliance violations.
Question 84: A compliance team is using a 'bow-tie' risk analysis. What does the LEFT side of the bow-tie represent?
- Key risk indicators and monitoring metrics
- Consequences and impacts of the risk event
- Causes and threat pathways leading to the risk event (Correct answer)
- Recovery controls and corrective actions
Correct answer: Causes and threat pathways leading to the risk event
In a bow-tie analysis, the left side maps the threats and causes (with preventive controls) leading to the central risk event, while the right side maps consequences and recovery controls.
Question 85: Why is third-party due diligence considered a critical component of a CCCP-level compliance program?
- Because vendor invoices must be approved by the compliance officer
- Because organizations can be held liable for the misconduct of their third parties under laws like the FCPA (Correct answer)
- Because third-party contracts always require external legal counsel
- Because third parties are immune from U.S. law enforcement
Correct answer: Because organizations can be held liable for the misconduct of their third parties under laws like the FCPA
The FCPA and other U.S. laws impose liability on companies for third-party misconduct conducted on their behalf, making due diligence essential.
Question 86: What is the most effective way to measure success in international compliance programs within CCCP professional practice?
- Rely solely on supervisor opinion
- Compare only with industry averages without considering context
- Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives (Correct answer)
- Count only the number of activities completed
Correct answer: Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives
Effective measurement combines multiple data sources — quantitative metrics, qualitative assessments, and stakeholder feedback — all aligned with clearly defined objectives for a comprehensive evaluation.
Question 87: Which of the following best describes 'inherent risk' in a compliance context?
- Risk transferred to a third party through insurance
- Risk accepted by management after analysis
- Risk remaining after controls are applied
- Risk that exists before any mitigating controls are in place (Correct answer)
Correct answer: Risk that exists before any mitigating controls are in place
Inherent risk is the raw or gross risk level existing in a business process or activity before any controls or mitigation measures are applied.
Question 88: When preparing board materials on a new regulatory requirement, the compliance officer should PRIMARILY focus on:
- Detailed legislative history and committee debates
- Business impact, gap assessment, required resources, and implementation timeline (Correct answer)
- Competitor responses to the regulation only
- Legal definitions and statutory language verbatim
Correct answer: Business impact, gap assessment, required resources, and implementation timeline
Board members need to understand operational impact and resource requirements to fulfill their oversight and decision-making roles.
Question 89: Under the FCA, a relator who voluntarily dismisses a qui tam action without the government's consent faces what consequence?
- The government automatically takes over the action
- Dismissal is not allowed without government and court consent once the complaint is unsealed (Correct answer)
- The relator must pay the defendant's legal fees
- The relator forfeits only their attorneys' fees
Correct answer: Dismissal is not allowed without government and court consent once the complaint is unsealed
Under 31 U.S.C. § 3730(b)(1), once the complaint is filed, the action may be dismissed only with written consent of the court and the Attorney General.
Question 90: Attorney-client privilege over compliance communications to the board is BEST preserved when:
- Board minutes document all compliance details in full
- The CCO sends emails to all executives copied to outside counsel
- Legal counsel directs the investigation and communications are marked as attorney-client privileged (Correct answer)
- Compliance reports are shared with investors upon request
Correct answer: Legal counsel directs the investigation and communications are marked as attorney-client privileged
Privilege requires that legal counsel direct the work and communications be properly labeled and limited in distribution.
Question 91: A qui tam relator's complaint is filed under seal. During the seal period, what is the government required to do?
- Investigate the allegations and decide whether to intervene (Correct answer)
- Serve the defendant within 30 days
- Refer the complaint to state authorities
- Immediately notify the defendant of the pending complaint
Correct answer: Investigate the allegations and decide whether to intervene
During the seal period, typically 60 days (often extended), the DOJ investigates the allegations to decide whether to intervene and take over the prosecution.
Question 92: A compliance officer is asked to present a 'lessons learned' summary after a major compliance incident to the board. The presentation should PRIMARILY focus on:
- Root cause analysis, systemic control gaps, corrective actions taken, and preventive measures implemented (Correct answer)
- Minimizing the incident's significance to maintain board confidence
- Assigning personal blame to identified employees
- Describing only the external regulatory response and fines
Correct answer: Root cause analysis, systemic control gaps, corrective actions taken, and preventive measures implemented
Post-incident board presentations should drive systemic improvement through root cause analysis and documented corrective actions, not blame or minimization.
Question 93: In False Claims Act cases, what is the purpose of the 'government's share' versus the 'relator's share' distinction?
- The government retains 70-75% of proceeds when it intervenes; the relator receives 15-25% (Correct answer)
- The relator always receives 50% of the recovery as the original source
- The government and relator split proceeds equally in all cases
- The relator's share is fixed at 10% regardless of government intervention
Correct answer: The government retains 70-75% of proceeds when it intervenes; the relator receives 15-25%
When the government intervenes, it retains most of the recovery (roughly 75-80%) while the relator typically receives 15-25%; if the government declines, the relator may receive 25-30%.
Question 94: Under the U.S. Federal Sentencing Guidelines, which factor related to a Code of Conduct can reduce an organization's culpability score?
- Publishing the Code of Conduct on the company's public website only
- Distributing the Code of Conduct only to managerial employees
- Having a Code of Conduct written exclusively by outside counsel
- Implementing and communicating standards of conduct effectively to all personnel (Correct answer)
Correct answer: Implementing and communicating standards of conduct effectively to all personnel
The Federal Sentencing Guidelines reward organizations that implement effective compliance programs, including communicating standards to all personnel.
Question 95: What is a 'clean team' in the context of M&A due diligence?
- A restricted group of advisors who access competitively sensitive information under a firewall protocol (Correct answer)
- HR staff who handle employee communications during a deal
- The legal team responsible for closing conditions
- A group that sanitizes physical documents before review
Correct answer: A restricted group of advisors who access competitively sensitive information under a firewall protocol
A clean team is a firewalled group that reviews competitively sensitive data so that gun-jumping and antitrust concerns are minimized during pre-closing diligence.
Question 96: What role does 'values-based compliance' play alongside 'rules-based compliance' in a CCCP framework?
- Values-based compliance applies only to senior leadership
- Values-based compliance motivates ethical behavior from internal principles, complementing rule-based deterrence (Correct answer)
- Values-based compliance replaces the need for written policies
- Values-based compliance is relevant only in non-profit organizations
Correct answer: Values-based compliance motivates ethical behavior from internal principles, complementing rule-based deterrence
Values-based compliance builds intrinsic motivation for ethical behavior, while rules-based compliance provides clear boundaries — together they create a more resilient program.
Question 97: Which metric is most useful for measuring the effectiveness of an ethics and Code of Conduct program?
- Training completion rates alone
- Number of pages in the Code of Conduct
- Combination of hotline utilization rates, substantiation rates, repeat violations, and employee survey data (Correct answer)
- Number of disciplinary actions taken per quarter
Correct answer: Combination of hotline utilization rates, substantiation rates, repeat violations, and employee survey data
Effective measurement combines multiple data points — hotline usage, substantiation rates, recidivism, and survey sentiment — to assess true program health.
Question 98: What are internal controls?
- Controls for holiday scheduling.
- Software update protocols.
- Procedures for external marketing.
- Mechanisms to support compliance and accuracy (Correct answer)
Correct answer: Mechanisms to support compliance and accuracy
Internal controls are processes, policies, and procedures implemented by an organization to ensure the integrity of financial and accounting information, promote operational efficiency, and encourage adherence to laws and regulations. They act as safeguards to prevent errors, fraud, and non-compliance, thereby supporting the achievement of organizational objectives. Examples include segregation of duties and authorization procedures.
Question 99: A compliance officer wants to ensure the board understands the company's ethics hotline trend data. Which approach is MOST effective?
- Present raw call volume numbers without context or comparison
- Show year-over-year trends, category breakdowns, and benchmarks against industry peers (Correct answer)
- Summarize all cases in a single aggregate number to protect privacy
- Only report cases that resulted in terminations
Correct answer: Show year-over-year trends, category breakdowns, and benchmarks against industry peers
Trend data with industry benchmarks gives the board meaningful context to evaluate hotline effectiveness and culture health.
Question 100: What is the purpose of including compliance representations and warranties in third-party contracts?
- To transfer all liability from the company to the vendor in the event of a violation
- To allow the company to audit the vendor's personal finances
- To contractually require the third party to comply with applicable laws and the company's compliance standards (Correct answer)
- To replace the need for ongoing monitoring of the third party
Correct answer: To contractually require the third party to comply with applicable laws and the company's compliance standards
Compliance representations and warranties contractually bind the third party to legal and ethical standards and provide grounds for termination or indemnification if violated.
Question 101: A risk that cannot be further reduced through practical controls and must be consciously accepted by management is called:
- Transferred risk
- Residual risk
- Secondary risk
- Tolerated risk (Correct answer)
Correct answer: Tolerated risk
Tolerated risk refers to residual risk that management has evaluated, deemed acceptable within the risk appetite, and formally decided to accept rather than further mitigate.
Question 102: Which element is considered most essential when drafting an effective Code of Conduct under U.S. compliance standards?
- Clear, plain-language guidance applicable to real workplace scenarios (Correct answer)
- Detailed descriptions of criminal penalties for each violation
- Signatures from all board members on every page
- Extensive legal citations and statutory references
Correct answer: Clear, plain-language guidance applicable to real workplace scenarios
An effective Code of Conduct uses plain language and practical examples so employees at all levels can understand and apply the standards.
Question 103: What is the most effective way to measure success in board & executive communication within CCCP professional practice?
- Count only the number of activities completed
- Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives (Correct answer)
- Rely solely on supervisor opinion
- Compare only with industry averages without considering context
Correct answer: Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives
Effective measurement combines multiple data sources — quantitative metrics, qualitative assessments, and stakeholder feedback — all aligned with clearly defined objectives for a comprehensive evaluation.
Question 104: The FCA's 'materiality' standard after Escobar requires plaintiffs to show that the false statement:
- Had a natural tendency to influence or was capable of influencing the government's payment decision (Correct answer)
- Appeared in the face of the submitted claim form
- Actually caused the government to make the payment
- Was the sole reason for the government's payment
Correct answer: Had a natural tendency to influence or was capable of influencing the government's payment decision
Escobar adopted an objective materiality test: the misrepresentation must have a natural tendency to influence or be capable of influencing the payment decision, not necessarily be the direct cause.
Question 105: Which governance framework specifically addresses the controls organizations should implement over IT systems that support financial reporting, relevant to Sarbanes-Oxley compliance?
- TOGAF
- COBIT (Correct answer)
- ITIL
- PRINCE2
Correct answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is the most widely used framework for IT governance and control, specifically referenced for SOX IT general controls.
Question 106: What is the recommended approach when a compliance officer discovers that a senior executive violated the Code of Conduct?
- Apply the same investigation and disciplinary standards used for any other employee to demonstrate consistency (Correct answer)
- Report only to external regulators and bypass internal processes
- Immediately terminate the executive without investigation
- Defer to the executive's supervisor to handle informally
Correct answer: Apply the same investigation and disciplinary standards used for any other employee to demonstrate consistency
Consistent application of standards regardless of seniority is a hallmark of an effective ethics program and critical to maintaining credibility.
Question 107: A compliance officer discovers that a business unit is pressuring employees to meet targets in ways that may violate policy. What is the MOST appropriate first step?
- Escalate the concern to senior leadership or the board audit committee (Correct answer)
- Immediately suspend the business unit's operations
- Report the issue directly to regulators without internal escalation
- Issue a company-wide memo warning against policy violations
Correct answer: Escalate the concern to senior leadership or the board audit committee
The compliance officer should escalate to senior leadership or the board's audit committee to ensure proper investigation before taking external action.
Question 108: Which internal control principle requires that an employee who records a transaction should NOT also have custody of the related assets?
- Least privilege
- Dual authorization
- Mandatory rotation
- Segregation of duties (Correct answer)
Correct answer: Segregation of duties
Segregation of duties separates the functions of record-keeping and asset custody to reduce the risk of fraud or error going undetected.
Question 109: What best describes the 'common interest privilege' and its application in a government investigation?
- An exemption allowing companies in the same industry to share confidential compliance data
- A doctrine that allows multiple parties with a common legal interest to share privileged communications without waiving the privilege (Correct answer)
- A privilege shared between co-defendants allowing them to discuss their defense strategies with one attorney
- The government's right to access communications shared between a company and its trade association
Correct answer: A doctrine that allows multiple parties with a common legal interest to share privileged communications without waiving the privilege
The common interest privilege extends attorney-client privilege to communications shared among parties with aligned legal interests (such as co-defendants or related entities), provided they have a common legal objective.
Question 110: Which format is BEST suited for presenting a complex multi-jurisdiction compliance risk to a board with limited regulatory background?
- A dense 40-page legal memorandum with full statutory citations
- A one-page heat map with tiered risk ratings and a brief executive summary (Correct answer)
- A spreadsheet of all violations without prioritization or context
- An oral-only presentation to avoid creating discoverable documents
Correct answer: A one-page heat map with tiered risk ratings and a brief executive summary
Heat maps with executive summaries communicate risk tiers efficiently and support board members in making informed decisions without legal expertise.
Question 111: In designing ethics training for U.S. employees, which approach is most effective according to compliance best practices?
- Training that focuses exclusively on legal penalties for violations
- One-time onboarding training with no refresher requirements
- Annual all-hands lecture covering the entire Code of Conduct in one session
- Role-based, scenario-driven training delivered in regular, manageable intervals (Correct answer)
Correct answer: Role-based, scenario-driven training delivered in regular, manageable intervals
Role-based, scenario-driven training delivered regularly is more effective because it is relevant to employees' actual work situations and improves retention.
Question 112: Under the DOJ's 2023 Evaluation of Corporate Compliance Programs guidance, which factor is used to assess whether a compliance program is 'adequately resourced'?
- The ratio of lawyers to compliance officers
- The compliance budget as a percentage of revenue
- Whether the company has cyber liability insurance
- The number of compliance staff and their access to relevant data and expertise (Correct answer)
Correct answer: The number of compliance staff and their access to relevant data and expertise
The DOJ evaluates staffing levels, expertise, and access to information to determine whether compliance has the resources needed to function effectively.
Question 113: Which element is required in a GDPR-compliant privacy notice but is NOT typically required under the original U.S. HIPAA Privacy Rule's Notice of Privacy Practices?
- Individual's right to access their health information
- Lawful basis for each processing activity (Correct answer)
- Contact information for the privacy officer
- Description of how data may be used and disclosed
Correct answer: Lawful basis for each processing activity
GDPR requires organizations to specify the lawful basis (e.g., consent, legitimate interest, contract) for each processing activity, a requirement that does not have a direct equivalent in HIPAA's Notice of Privacy Practices.
Question 114: What distinguishes a 'speak-up culture' from a mere hotline program in corporate compliance?
- A speak-up culture requires all concerns to be escalated to the board
- A speak-up culture eliminates the need for a formal whistleblower policy
- A speak-up culture relies exclusively on anonymous reporting
- A speak-up culture actively encourages employees to raise concerns through any channel without fear of retaliation (Correct answer)
Correct answer: A speak-up culture actively encourages employees to raise concerns through any channel without fear of retaliation
A speak-up culture goes beyond a hotline by embedding psychological safety so employees feel comfortable raising concerns through any appropriate channel.
Question 115: A board member shares a confidential compliance report with a personal friend who is a major shareholder. This MOST likely violates:
- No rule, since shareholders have a right to all company information
- The company's travel and expense policy
- Fiduciary duties, confidentiality obligations, and potentially securities laws on selective disclosure (Correct answer)
- The company's social media policy only
Correct answer: Fiduciary duties, confidentiality obligations, and potentially securities laws on selective disclosure
Directors have fiduciary duties of confidentiality, and selective disclosure of material non-public information can trigger Reg FD and insider trading violations.
Certified Compliance & Ethics Professional (CCEP) — Corporate Compliance Professional
The CCEP credential from the Society of Corporate Compliance and Ethics (SCCE) validates expertise in designing, implementing, and managing corporate compliance and ethics programs, covering governance, risk assessment, training, investigations, and third-party compliance.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds