← All CCM Flashcard Decks

Risk Management and Compliance Flashcards

7 cards from real CCM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Management and Compliance flashcards as text
  1. A commercial manager discovers that a supplier has a single-source dependency for a critical component. Which risk response strategy is MOST appropriate?

    Answer: Mitigate by qualifying an alternative supplier

    Qualifying an alternative supplier reduces single-source dependency and is a classic mitigation strategy for supply chain concentration risk.

  2. Under the Foreign Corrupt Practices Act (FCPA), which of the following payments to a foreign government official is generally permissible?

    Answer: Facilitating payments to expedite routine governmental actions

    The FCPA provides a narrow exception for facilitating payments made to expedite routine, non-discretionary governmental actions, though many companies prohibit even these.

  3. A risk heat map plots risks on axes of probability and impact. A risk in the upper-right quadrant should be treated as:

    Answer: High priority — immediate action required

    Upper-right placement indicates both high probability and high impact, making the risk a top priority requiring immediate mitigation action.

  4. Which document formally records identified risks, their likelihood, impact, owners, and response plans?

    Answer: Risk Register

    A Risk Register is the primary tool for capturing, tracking, and managing all identified risks throughout the project or organization.

  5. A company's compliance team finds that an employee submitted false expense reports totaling $4,000. This is best classified as:

    Answer: Operational risk — internal fraud

    Internal fraud by an employee is a textbook operational risk event under frameworks such as Basel II/III.

  6. When conducting a Third-Party Risk Assessment (TPRA), which due diligence element is MOST critical for a supplier handling sensitive customer data?

    Answer: Information security and data privacy controls

    For suppliers with access to sensitive data, assessing their information security controls is the highest-priority due diligence item.

  7. The principle of 'segregation of duties' in compliance and internal control primarily aims to:

    Answer: Reduce errors and fraud by requiring multiple individuals to complete sensitive processes

    Segregation of duties ensures no single individual controls all steps of a critical process, reducing the opportunity for errors or fraud.