CCEP Regulatory Frameworks 3 — Questions and Answers
Question 1: Under the False Claims Act (FCA), what percentage of the government's recovery can a whistleblower (relator) receive when the government intervenes in a qui tam lawsuit?
- 5 to 10 percent
- 15 to 25 percent (Correct answer)
- 25 to 30 percent
- 30 to 40 percent
Correct answer: 15 to 25 percent
Under the FCA, if the government intervenes, the relator is entitled to between 15 and 25 percent of the proceeds recovered.
Question 2: The NIST Cybersecurity Framework (CSF) is organized around which five core functions?
- Plan, Do, Check, Act, Improve
- Identify, Protect, Detect, Respond, Recover (Correct answer)
- Prevent, Detect, Investigate, Contain, Remediate
- Assess, Design, Implement, Monitor, Review
Correct answer: Identify, Protect, Detect, Respond, Recover
The NIST CSF core consists of five functions: Identify, Protect, Detect, Respond, and Recover, which together form a risk management lifecycle.
Question 3: Which regulatory framework specifically governs the privacy and security of protected health information (PHI) in the United States?
- Gramm-Leach-Bliley Act (GLBA)
- Health Insurance Portability and Accountability Act (HIPAA) (Correct answer)
- Children's Online Privacy Protection Act (COPPA)
- California Consumer Privacy Act (CCPA)
Correct answer: Health Insurance Portability and Accountability Act (HIPAA)
HIPAA's Privacy Rule and Security Rule establish national standards for the protection of PHI held by covered entities and their business associates.
Question 4: In the context of anti-money laundering (AML) compliance, what does 'KYC' stand for and what is its primary purpose?
- Keep Your Customers; to improve customer retention
- Know Your Customer; to verify client identity and assess risk (Correct answer)
- Key Your Credentials; to authenticate user access
- Knowledge Yield Compliance; to measure training effectiveness
Correct answer: Know Your Customer; to verify client identity and assess risk
Know Your Customer (KYC) refers to the process of verifying the identity of clients and assessing their suitability and risk profile to prevent financial crime.
Question 5: The Dodd-Frank Wall Street Reform and Consumer Protection Act established which agency to protect consumers in financial transactions?
- Financial Industry Regulatory Authority (FINRA)
- Consumer Financial Protection Bureau (CFPB) (Correct answer)
- Office of the Comptroller of the Currency (OCC)
- Federal Deposit Insurance Corporation (FDIC)
Correct answer: Consumer Financial Protection Bureau (CFPB)
Dodd-Frank created the CFPB in 2010 as an independent agency to protect consumers from unfair, deceptive, or abusive practices by financial service providers.
Question 6: Under ISO 37001 (Anti-Bribery Management Systems), which element is NOT a required component of an anti-bribery management system?
- Leadership commitment and top management support
- Anti-bribery policy and risk assessment
- Mandatory criminal background checks for all employees (Correct answer)
- Due diligence on business associates
Correct answer: Mandatory criminal background checks for all employees
ISO 37001 does not mandate criminal background checks for all employees; it focuses on proportionate, risk-based controls including policy, due diligence, and oversight.
Question 7: Which principle under the OECD Anti-Bribery Convention requires signatory countries to establish criminal offenses for bribing foreign public officials?
- The mutual legal assistance principle
- The active bribery of foreign officials principle (Correct answer)
- The extraterritorial jurisdiction principle
- The corporate liability principle
Correct answer: The active bribery of foreign officials principle
The OECD Convention's core obligation requires signatory countries to criminalize the active bribery of foreign public officials in international business transactions.
Under the False Claims Act (FCA), what percentage of the government's recovery can a whistleblower (relator) receive when the government intervenes in a qui tam lawsuit?