CCEP Risk Assessment & Monitoring 5 — Questions and Answers
Question 1: Which scenario represents a failure of the 'monitoring' component of an effective compliance program?
- Employees complete annual compliance training
- Compliance risks are identified during an initial assessment
- Control deficiencies identified in testing are never remediated or tracked (Correct answer)
- The compliance officer presents risk findings to the board quarterly
Correct answer: Control deficiencies identified in testing are never remediated or tracked
Monitoring must include remediation tracking; failing to close identified control gaps renders the monitoring process ineffective.
Question 2: A compliance officer wants to assess the effectiveness of employee training as a risk control. Which method is MOST appropriate?
- Count how many employees attended training sessions
- Measure post-training knowledge retention and track related incident rates (Correct answer)
- Review the length and cost of training materials
- Compare training schedules with competitor organizations
Correct answer: Measure post-training knowledge retention and track related incident rates
Measuring knowledge retention and linking training to incident trends provides evidence of whether training is actually reducing compliance risk.
Question 3: What risk is most directly associated with a compliance program that relies solely on self-reporting for incident detection?
- Overreporting of minor violations
- Under-detection of violations due to fear of retaliation or lack of awareness (Correct answer)
- Excessive workload for the compliance team
- Difficulty maintaining confidentiality of reports
Correct answer: Under-detection of violations due to fear of retaliation or lack of awareness
Self-reporting programs can miss violations when employees fear retaliation or do not recognize misconduct, making independent monitoring equally essential.
Question 4: When a compliance risk assessment reveals that a risk has been 'transferred,' what does this mean?
- The risk has been assigned to another department for monitoring
- The financial or operational consequence of the risk has been shifted to a third party, such as through insurance (Correct answer)
- The risk has been documented and archived
- The risk has been eliminated through policy changes
Correct answer: The financial or operational consequence of the risk has been shifted to a third party, such as through insurance
Risk transfer involves shifting the financial or operational burden of a risk to another party, most commonly through insurance or contractual arrangements.
Question 5: In the COSO ERM framework, which component most directly supports ongoing compliance risk monitoring?
- Control environment
- Risk identification
- Monitoring activities (Correct answer)
- Event inventory
Correct answer: Monitoring activities
The 'Monitoring Activities' component of COSO ERM encompasses ongoing evaluations and separate assessments that ensure controls remain effective over time.
Question 6: A compliance officer notices that a high-risk process has no assigned risk owner. What is the MOST significant consequence of this gap?
- The risk will automatically be escalated to the CEO
- Accountability for monitoring and remediating the risk is unclear, increasing the chance it goes unaddressed (Correct answer)
- The risk will be reclassified as low priority
- Regulators will immediately investigate the company
Correct answer: Accountability for monitoring and remediating the risk is unclear, increasing the chance it goes unaddressed
Without a designated owner, no one is accountable for monitoring or mitigating the risk, making it likely to persist unaddressed.
Question 7: Which practice BEST demonstrates that a compliance program's risk assessment is 'dynamic' rather than static?
- The risk assessment was completed at the company's founding and filed for reference
- Risk assessments are refreshed whenever significant internal changes, external events, or regulatory updates occur (Correct answer)
- The same risk questionnaire is sent to all departments every five years
- Risk levels are set by the board and unchanged until a major scandal occurs
Correct answer: Risk assessments are refreshed whenever significant internal changes, external events, or regulatory updates occur
A dynamic risk assessment is updated in response to triggering events — business changes, regulatory shifts, or external incidents — ensuring it reflects current reality.
Which scenario represents a failure of the 'monitoring' component of an effective compliance program?