CCEP Risk Assessment & Monitoring 4 — Questions and Answers
Question 1: What is the primary purpose of a compliance 'heat map'?
- To display the geographic distribution of the company's offices
- To visually represent risks by likelihood and impact for prioritization (Correct answer)
- To show employee attendance in compliance training sessions
- To map the organizational reporting structure
Correct answer: To visually represent risks by likelihood and impact for prioritization
A compliance heat map plots risks on a grid of likelihood versus impact, enabling quick visual identification of the highest-priority risks.
Question 2: Which of the following BEST describes the 'three lines of defense' model as applied to compliance risk monitoring?
- Legal, compliance, and HR each independently report to the regulator
- Business operations, compliance/risk functions, and internal audit provide layered oversight (Correct answer)
- The CEO, CFO, and CLO each approve all compliance controls
- Three separate compliance audits are conducted annually
Correct answer: Business operations, compliance/risk functions, and internal audit provide layered oversight
The three lines model assigns risk ownership to business units (first line), compliance and risk management (second line), and internal audit (third line) for layered oversight.
Question 3: A company's compliance risk assessment reveals a high-impact risk with a very low likelihood of occurrence. What is the MOST appropriate response?
- Ignore it because the likelihood is low
- Accept the risk without any controls
- Implement cost-effective monitoring controls and document the risk (Correct answer)
- Treat it identically to a high-likelihood, high-impact risk
Correct answer: Implement cost-effective monitoring controls and document the risk
Low-likelihood but high-impact risks warrant cost-proportionate monitoring and documentation to ensure they are watched and can be acted upon if conditions change.
Question 4: When assessing corruption risk under the FCPA, which factor most significantly increases inherent risk for a multinational company?
- Having a large domestic workforce
- Operating in countries with high corruption perception index scores (Correct answer)
- Offering a broad product portfolio
- Conducting business-to-consumer transactions
Correct answer: Operating in countries with high corruption perception index scores
Countries with high corruption scores significantly increase the inherent risk of FCPA violations due to the prevalence of bribery in those environments.
Question 5: Which element is ESSENTIAL for a risk monitoring program to be considered effective under the DOJ's compliance program evaluation framework?
- The program must be unchanged since it was first implemented
- The program must be continuously evaluated and improved based on performance data (Correct answer)
- All compliance functions must be outsourced to external auditors
- Monitoring must occur no more than once per year to avoid disruption
Correct answer: The program must be continuously evaluated and improved based on performance data
The DOJ expects compliance programs to be living systems that evolve based on testing, monitoring results, and lessons learned.
Question 6: An internal audit identifies a control that has been operating effectively for five years but is now outdated due to a regulatory change. What should a compliance officer do?
- Keep the control in place because it has a proven track record
- Immediately remove the control and replace it with a manual review
- Update or redesign the control to align with the current regulatory requirement (Correct answer)
- Wait until the next scheduled audit cycle to address the gap
Correct answer: Update or redesign the control to align with the current regulatory requirement
Controls must be kept current with applicable regulations; an outdated control that no longer meets requirements must be updated or replaced promptly.
Question 7: What is the key distinction between 'risk tolerance' and 'risk appetite' in a compliance context?
- They are interchangeable terms with no meaningful difference
- Risk appetite is the desired risk level; risk tolerance is the acceptable deviation from that level (Correct answer)
- Risk tolerance is set by regulators; risk appetite is set by employees
- Risk appetite applies only to financial risks; risk tolerance applies to operational risks
Correct answer: Risk appetite is the desired risk level; risk tolerance is the acceptable deviation from that level
Risk appetite defines the desired level of risk, while risk tolerance specifies the permissible variation around that level before action is required.
What is the primary purpose of a compliance 'heat map'?