CCEP Regulatory Frameworks 5 — Questions and Answers
Question 1: When a compliance officer identifies a potential conflict between two applicable regulatory frameworks governing the same business activity, which approach is MOST consistent with best practices?
- Apply whichever regulation is less burdensome to reduce operational costs
- Apply the stricter standard and document the analysis supporting the decision (Correct answer)
- Seek a formal regulatory waiver before proceeding with any business activity
- Default to the older regulation as it represents established precedent
Correct answer: Apply the stricter standard and document the analysis supporting the decision
Best practice is to apply the more stringent requirement and document the analysis, demonstrating good faith compliance efforts and protecting the organization from liability.
Question 2: The Financial Action Task Force (FATF) is best described as which type of body?
- A United Nations treaty organization with binding enforcement authority
- An intergovernmental policy-making body that sets international AML/CFT standards (Correct answer)
- A private sector self-regulatory organization for banks and financial institutions
- A regional regulatory agency covering European Union member states
Correct answer: An intergovernmental policy-making body that sets international AML/CFT standards
FATF is an intergovernmental organization that develops and promotes policies to combat money laundering and terrorist financing, issuing Recommendations that member countries implement into national law.
Question 3: Under the Americans with Disabilities Act (ADA), which standard applies to determine whether an employer must provide a reasonable accommodation?
- The accommodation must cost less than $5,000 regardless of company size
- The accommodation must not cause undue hardship considering the employer's specific circumstances (Correct answer)
- The accommodation must be specifically requested in writing by the employee's physician
- The accommodation must be the exact same type provided to other employees with similar conditions
Correct answer: The accommodation must not cause undue hardship considering the employer's specific circumstances
Employers must provide reasonable accommodations unless doing so would impose an undue hardship, which is evaluated based on factors such as cost, the employer's resources, and the nature of operations.
Question 4: Which element is considered the MOST critical factor in establishing that an organization has an 'effective' compliance program under the DOJ's Evaluation of Corporate Compliance Programs guidance?
- The size of the compliance department relative to the organization
- Whether the program is well-designed, adequately resourced, and actually works in practice (Correct answer)
- The number of compliance training hours completed annually per employee
- Whether the company has achieved ISO 37001 certification
Correct answer: Whether the program is well-designed, adequately resourced, and actually works in practice
The DOJ evaluates whether a compliance program is 'well-designed, adequately resourced and empowered, and whether it works in practice,' focusing on real-world effectiveness over paper compliance.
Question 5: Under the EU's NIS2 Directive (Network and Information Security), which category of organizations faces the MOST stringent cybersecurity obligations?
- Important entities operating in digital infrastructure sectors
- Essential entities in critical sectors such as energy, transport, and banking (Correct answer)
- All organizations processing personal data under GDPR
- Any company with more than 250 employees in the EU
Correct answer: Essential entities in critical sectors such as energy, transport, and banking
NIS2 creates a two-tier system where 'essential entities' in critical sectors face stricter supervision and penalties than 'important entities,' reflecting their higher risk impact.
Question 6: A compliance officer is conducting a gap analysis against a new regulatory requirement. Which of the following BEST describes the purpose of a gap analysis in this context?
- Calculating the estimated fines for non-compliance to determine if compliance is cost-effective
- Comparing current practices against the new requirement to identify areas needing remediation (Correct answer)
- Lobbying regulators to modify requirements that are operationally difficult to meet
- Documenting existing controls to demonstrate to regulators that no changes are needed
Correct answer: Comparing current practices against the new requirement to identify areas needing remediation
A gap analysis systematically compares an organization's current state against required standards to identify deficiencies that must be addressed through a remediation plan.
Question 7: Under the California Consumer Privacy Act (CCPA) as amended by CPRA, which right allows consumers to correct inaccurate personal information held by a business?
- Right to deletion
- Right to rectification (Correct answer)
- Right to opt-out of sale
- Right to data portability
Correct answer: Right to rectification
The CPRA amendment to the CCPA added the right to correction (rectification), allowing consumers to request that businesses correct inaccurate personal information the business holds about them.
When a compliance officer identifies a potential conflict between two applicable regulatory frameworks governing the same business activity, which approach is MOST consistent with best practices?