← All CCEP Flashcard Decks

Risk Assessment & Monitoring Flashcards

7 cards from real CCEP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Assessment & Monitoring flashcards as text
  1. Which scenario represents a failure of the 'monitoring' component of an effective compliance program?

    Answer: Control deficiencies identified in testing are never remediated or tracked

    Monitoring must include remediation tracking; failing to close identified control gaps renders the monitoring process ineffective.

  2. A compliance officer wants to assess the effectiveness of employee training as a risk control. Which method is MOST appropriate?

    Answer: Measure post-training knowledge retention and track related incident rates

    Measuring knowledge retention and linking training to incident trends provides evidence of whether training is actually reducing compliance risk.

  3. What risk is most directly associated with a compliance program that relies solely on self-reporting for incident detection?

    Answer: Under-detection of violations due to fear of retaliation or lack of awareness

    Self-reporting programs can miss violations when employees fear retaliation or do not recognize misconduct, making independent monitoring equally essential.

  4. When a compliance risk assessment reveals that a risk has been 'transferred,' what does this mean?

    Answer: The financial or operational consequence of the risk has been shifted to a third party, such as through insurance

    Risk transfer involves shifting the financial or operational burden of a risk to another party, most commonly through insurance or contractual arrangements.

  5. In the COSO ERM framework, which component most directly supports ongoing compliance risk monitoring?

    Answer: Monitoring activities

    The 'Monitoring Activities' component of COSO ERM encompasses ongoing evaluations and separate assessments that ensure controls remain effective over time.

  6. A compliance officer notices that a high-risk process has no assigned risk owner. What is the MOST significant consequence of this gap?

    Answer: Accountability for monitoring and remediating the risk is unclear, increasing the chance it goes unaddressed

    Without a designated owner, no one is accountable for monitoring or mitigating the risk, making it likely to persist unaddressed.

  7. Which practice BEST demonstrates that a compliance program's risk assessment is 'dynamic' rather than static?

    Answer: Risk assessments are refreshed whenever significant internal changes, external events, or regulatory updates occur

    A dynamic risk assessment is updated in response to triggering events — business changes, regulatory shifts, or external incidents — ensuring it reflects current reality.