CCEP Audit and Reporting 5 — Questions and Answers
Question 1: Under the Dodd-Frank Act, which behavior by an employer constitutes prohibited retaliation against a whistleblower?
- Conducting a performance review after the report is filed
- Terminating, demoting, or harassing an employee for reporting potential securities violations (Correct answer)
- Reassigning the employee to a different but equivalent role unrelated to the reported issue
- Requiring the employee to cooperate with the internal investigation
Correct answer: Terminating, demoting, or harassing an employee for reporting potential securities violations
Dodd-Frank prohibits adverse employment actions—including termination, demotion, and harassment—taken against employees because they reported potential securities law violations.
Question 2: Which metric would BEST measure the effectiveness of a compliance hotline over time?
- The dollar amount of fines paid to regulators
- Trends in report volume, substantiation rates, and time-to-close investigations (Correct answer)
- The number of employees who signed the code of conduct
- Total hours spent on compliance training annually
Correct answer: Trends in report volume, substantiation rates, and time-to-close investigations
Tracking report volume trends, how many reports are substantiated, and how quickly investigations are resolved provides insight into hotline health and organizational ethics culture.
Question 3: A compliance team is preparing to audit a third-party vendor. Which document most directly grants the right to conduct such an audit?
- The company's internal code of conduct
- A contractual audit rights clause in the vendor agreement (Correct answer)
- A board resolution approving the audit program
- The vendor's self-certification of compliance
Correct answer: A contractual audit rights clause in the vendor agreement
An audit rights clause in the vendor contract is the legal mechanism that entitles the company to inspect the vendor's records and operations for compliance.
Question 4: Which principle guides the frequency with which a compliance program should be audited?
- Audits must always occur on a fixed annual schedule regardless of risk changes
- Audit frequency should be commensurate with the organization's risk profile and any material changes in the environment (Correct answer)
- Audits should be conducted only when a regulator requests them
- Once a program passes an audit, it should not be re-audited for at least five years
Correct answer: Audit frequency should be commensurate with the organization's risk profile and any material changes in the environment
Risk-based audit scheduling ties audit frequency to the current risk landscape, ensuring higher-risk areas receive more frequent scrutiny as conditions change.
Question 5: What is the purpose of audit 'workpapers' in a compliance audit?
- To serve as a public disclosure document for regulators
- To document the evidence gathered, procedures performed, and conclusions reached during the audit (Correct answer)
- To provide a summary of employee compliance training completion
- To replace the formal audit report submitted to management
Correct answer: To document the evidence gathered, procedures performed, and conclusions reached during the audit
Workpapers are the auditor's internal record of evidence, procedures, and conclusions, providing a trail that supports the audit report and demonstrates due professional care.
Question 6: In a compliance investigation triggered by an audit finding, what is the role of attorney-client privilege?
- It prevents auditors from ever disclosing findings to the board
- It can protect communications between legal counsel and the organization during an investigation from compelled disclosure (Correct answer)
- It requires all investigation findings to be published publicly
- It applies only to communications with external regulators, not internal counsel
Correct answer: It can protect communications between legal counsel and the organization during an investigation from compelled disclosure
Attorney-client privilege may protect confidential communications with counsel during an investigation, helping the organization conduct a candid internal inquiry without compelled disclosure.
Question 7: Which practice helps ensure audit recommendations do not simply 'sit on the shelf' after a compliance audit?
- Limiting the number of recommendations to avoid overwhelming management
- Establishing a formal corrective action tracking system with assigned owners and deadline monitoring (Correct answer)
- Allowing each department to decide independently whether to implement recommendations
- Publishing all recommendations externally to create public accountability
Correct answer: Establishing a formal corrective action tracking system with assigned owners and deadline monitoring
A corrective action tracking system assigns ownership, sets deadlines, and monitors completion, ensuring audit recommendations are actually implemented rather than ignored.
Under the Dodd-Frank Act, which behavior by an employer constitutes prohibited retaliation against a whistleblower?