Mergers & Acquisitions Compliance Flashcards
7 cards from real CCCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Mergers & Acquisitions Compliance flashcards as text
Which agency administers the Committee on Foreign Investment in the United States (CFIUS) review process?
Answer: U.S. Department of the Treasury
The U.S. Department of the Treasury chairs CFIUS, though the committee includes members from multiple agencies including DOD, DOJ, and DHS.
What is a 'virtual data room' (VDR) used for in M&A due diligence from a compliance perspective?
Answer: A secure, auditable platform for sharing confidential target company documents with authorized reviewers
VDRs provide a controlled, tracked environment for sharing sensitive documents, creating an audit trail of who accessed what information during due diligence.
Under the FCPA, which of the following actions by a newly acquired foreign subsidiary could expose the US acquirer to liability?
Answer: Paying a government official a bribe to win a local contract before the acquisition closed
Under successor liability, a US acquirer can face FCPA enforcement for pre-acquisition conduct of the target, especially if adequate pre-close due diligence was not conducted.
What does a 'second request' from the DOJ or FTC during HSR review signify?
Answer: A demand for additional documents and information, extending the waiting period
A Second Request is a formal demand for extensive additional information, which extends the antitrust review period until the parties substantially comply.
Which compliance risk is most commonly overlooked in private equity acquisitions of portfolio companies?
Answer: Compliance program gaps in lower-revenue subsidiaries acquired as part of a platform strategy
In platform-and-bolt-on strategies, smaller acquired subsidiaries often lack mature compliance programs, creating aggregate regulatory risk that is frequently underestimated.
What is the role of the compliance officer during the letter of intent (LOI) phase of an M&A transaction?
Answer: Identify key compliance risk areas and influence due diligence scope and focus
At the LOI stage, the compliance officer should flag high-risk areas—such as sanctions exposure, regulatory investigations, or data privacy gaps—to shape the due diligence workplan.
Which data privacy law creates the most significant compliance obligation when a US company acquires a European target that processes EU personal data?
Answer: General Data Protection Regulation (GDPR)
GDPR imposes strict obligations on any entity processing EU personal data, and the acquirer inherits these obligations upon taking control of the EU target.