CCEP Risk Assessment & Monitoring 3 — Questions and Answers
Question 1: A company is expanding into a new country. Which risk assessment step should be completed FIRST?
- Establish local compliance training
- Identify all applicable local laws and regulations (Correct answer)
- Appoint a local compliance officer
- Implement existing corporate controls without modification
Correct answer: Identify all applicable local laws and regulations
Identifying applicable local laws and regulations is the foundational step that informs all subsequent compliance planning in a new jurisdiction.
Question 2: Which metric is MOST useful for evaluating the effectiveness of a compliance monitoring program over time?
- Total number of compliance policies written
- Trend analysis of compliance violations and near-misses (Correct answer)
- Number of employees in the compliance department
- Size of the compliance training budget
Correct answer: Trend analysis of compliance violations and near-misses
Tracking trends in violations and near-misses over time reveals whether the monitoring program is effectively reducing compliance failures.
Question 3: What is 'residual risk' in the context of compliance risk management?
- Risk identified but not yet assessed
- Risk that remains after controls have been applied (Correct answer)
- Risk transferred to a third party
- Risk eliminated through policy changes
Correct answer: Risk that remains after controls have been applied
Residual risk is the level of risk that persists after existing controls and mitigation measures have been implemented.
Question 4: A compliance team conducts 'stress testing' of its risk controls. What does this process evaluate?
- Employee performance under deadline pressure
- How controls perform under adverse or extreme scenarios (Correct answer)
- The financial cost of implementing controls
- Regulatory approval of internal control frameworks
Correct answer: How controls perform under adverse or extreme scenarios
Stress testing evaluates whether compliance controls would hold up under severe or unlikely scenarios, revealing hidden vulnerabilities.
Question 5: Third-party risk management in a compliance program primarily addresses which concern?
- That vendors may offer lower prices than expected
- That third parties may expose the organization to compliance violations through their conduct (Correct answer)
- That internal staff may prefer third-party services
- That auditors may have conflicts of interest
Correct answer: That third parties may expose the organization to compliance violations through their conduct
Third-party risk management ensures that vendors, suppliers, and partners do not create compliance liability for the organization through their own conduct or practices.
Question 6: Which scenario BEST illustrates an 'emerging risk' in compliance monitoring?
- A recurring violation in a department with known control gaps
- A new data privacy regulation enacted in a key market where the company operates (Correct answer)
- A historical fraud case that has been fully resolved
- A routine audit finding with a standard remediation plan
Correct answer: A new data privacy regulation enacted in a key market where the company operates
Emerging risks are new or evolving threats, such as recently enacted regulations, that have not yet been fully assessed or addressed.
Question 7: How does a compliance program use 'leading indicators' differently from 'lagging indicators'?
- Leading indicators measure past violations; lagging indicators predict future ones
- Leading indicators signal potential future problems; lagging indicators reflect past outcomes (Correct answer)
- Leading indicators are used only in financial audits; lagging indicators are used in HR reviews
- Leading indicators are reported annually; lagging indicators are reported monthly
Correct answer: Leading indicators signal potential future problems; lagging indicators reflect past outcomes
Leading indicators provide early warning of future compliance issues, while lagging indicators measure what has already occurred.
A company is expanding into a new country.
Which risk assessment step should be completed FIRST?