CCEP Standards, Policies & Procedures 5 — Questions and Answers
Question 1: What is the main risk of having too many overly detailed compliance procedures?
- Employees will become too compliant and avoid all risk-taking
- Procedures may become outdated faster and employees may focus on technical compliance over ethical intent (Correct answer)
- Regulators will penalize organizations for excessive documentation
- The compliance department will have insufficient work to justify its budget
Correct answer: Procedures may become outdated faster and employees may focus on technical compliance over ethical intent
Overly prescriptive procedures can create 'checkbox compliance,' cause frequent obsolescence, and cause employees to lose sight of the underlying ethical purpose.
Question 2: Which principle should guide the prioritization of which policies to develop first in a new compliance program?
- Alphabetical order of regulatory citations
- Risk-based prioritization, addressing highest-risk areas before lower-risk ones (Correct answer)
- Starting with the easiest policies to draft to build early momentum
- Following the order regulators list requirements in guidance documents
Correct answer: Risk-based prioritization, addressing highest-risk areas before lower-risk ones
A risk-based approach ensures that limited compliance resources are directed toward the areas of greatest potential harm or regulatory exposure first.
Question 3: An employee follows a procedure exactly as written but still causes a compliance violation. What does this most likely indicate?
- The employee acted in bad faith
- The procedure itself is flawed or outdated and needs revision (Correct answer)
- Compliance violations are inevitable regardless of procedures
- The employee should be terminated immediately
Correct answer: The procedure itself is flawed or outdated and needs revision
If following a procedure correctly still produces a violation, the procedure fails to adequately implement the underlying policy and must be corrected.
Question 4: What distinguishes 'mandatory' training from 'recommended' training in communicating compliance policies?
- Mandatory training is always delivered in person; recommended training is online
- Mandatory training is required for all applicable employees and tracked for completion; recommended training is optional (Correct answer)
- Mandatory training is only for new hires; recommended training is for veterans
- Mandatory training replaces the need for written policies
Correct answer: Mandatory training is required for all applicable employees and tracked for completion; recommended training is optional
Mandatory training is a required compliance control with tracked completion rates, while recommended training is voluntary and not tracked for accountability purposes.
Question 5: How does the CCEP Body of Knowledge suggest handling a situation where local law prohibits disclosing details required by a global company policy?
- Always apply global company policy and disregard local law
- Apply the more stringent of global policy or local law without disclosing the conflict
- Document the legal conflict, seek legal counsel, and implement a local variance while notifying appropriate governance bodies (Correct answer)
- Withdraw from the jurisdiction to avoid the conflict
Correct answer: Document the legal conflict, seek legal counsel, and implement a local variance while notifying appropriate governance bodies
When local law conflicts with global policy, the proper response is to document the conflict, obtain legal guidance, create a documented local variance, and escalate to appropriate oversight.
Question 6: Which element makes a compliance hotline policy most effective in encouraging employees to report concerns?
- Requiring employees to use their full name when reporting
- Guaranteeing anonymity or confidentiality and non-retaliation protections (Correct answer)
- Limiting the hotline to senior employees only
- Publicizing the identities of employees who make reports to deter false claims
Correct answer: Guaranteeing anonymity or confidentiality and non-retaliation protections
Research consistently shows that non-retaliation protections and confidentiality options are the most critical factors in encouraging employees to use reporting channels.
Question 7: What is the significance of including a 'version control' section in a compliance policy document?
- It allows multiple employees to edit the policy simultaneously
- It tracks revision history so stakeholders can identify what changed, when, and why (Correct answer)
- It restricts access to the policy to authorized reviewers only
- It automatically updates the policy when regulations change
Correct answer: It tracks revision history so stakeholders can identify what changed, when, and why
Version control provides an auditable history of policy changes, supporting accountability, regulatory inquiries, and consistent enforcement of the correct version.
What is the main risk of having too many overly detailed compliance procedures?