Regulatory Frameworks Flashcards
7 cards from real CCEP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Regulatory Frameworks flashcards as text
When a compliance officer identifies a potential conflict between two applicable regulatory frameworks governing the same business activity, which approach is MOST consistent with best practices?
Answer: Apply the stricter standard and document the analysis supporting the decision
Best practice is to apply the more stringent requirement and document the analysis, demonstrating good faith compliance efforts and protecting the organization from liability.
The Financial Action Task Force (FATF) is best described as which type of body?
Answer: An intergovernmental policy-making body that sets international AML/CFT standards
FATF is an intergovernmental organization that develops and promotes policies to combat money laundering and terrorist financing, issuing Recommendations that member countries implement into national law.
Under the Americans with Disabilities Act (ADA), which standard applies to determine whether an employer must provide a reasonable accommodation?
Answer: The accommodation must not cause undue hardship considering the employer's specific circumstances
Employers must provide reasonable accommodations unless doing so would impose an undue hardship, which is evaluated based on factors such as cost, the employer's resources, and the nature of operations.
Which element is considered the MOST critical factor in establishing that an organization has an 'effective' compliance program under the DOJ's Evaluation of Corporate Compliance Programs guidance?
Answer: Whether the program is well-designed, adequately resourced, and actually works in practice
The DOJ evaluates whether a compliance program is 'well-designed, adequately resourced and empowered, and whether it works in practice,' focusing on real-world effectiveness over paper compliance.
Under the EU's NIS2 Directive (Network and Information Security), which category of organizations faces the MOST stringent cybersecurity obligations?
Answer: Essential entities in critical sectors such as energy, transport, and banking
NIS2 creates a two-tier system where 'essential entities' in critical sectors face stricter supervision and penalties than 'important entities,' reflecting their higher risk impact.
A compliance officer is conducting a gap analysis against a new regulatory requirement. Which of the following BEST describes the purpose of a gap analysis in this context?
Answer: Comparing current practices against the new requirement to identify areas needing remediation
A gap analysis systematically compares an organization's current state against required standards to identify deficiencies that must be addressed through a remediation plan.
Under the California Consumer Privacy Act (CCPA) as amended by CPRA, which right allows consumers to correct inaccurate personal information held by a business?
Answer: Right to rectification
The CPRA amendment to the CCPA added the right to correction (rectification), allowing consumers to request that businesses correct inaccurate personal information the business holds about them.