Risk Management and Compliance Flashcards
7 cards from real CCM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Management and Compliance flashcards as text
A commercial manager discovers that a supplier has a single-source dependency for a critical component. Which risk response strategy is MOST appropriate?
Answer: Mitigate by qualifying an alternative supplier
Qualifying an alternative supplier reduces single-source dependency and is a classic mitigation strategy for supply chain concentration risk.
Under the Foreign Corrupt Practices Act (FCPA), which of the following payments to a foreign government official is generally permissible?
Answer: Facilitating payments to expedite routine governmental actions
The FCPA provides a narrow exception for facilitating payments made to expedite routine, non-discretionary governmental actions, though many companies prohibit even these.
A risk heat map plots risks on axes of probability and impact. A risk in the upper-right quadrant should be treated as:
Answer: High priority — immediate action required
Upper-right placement indicates both high probability and high impact, making the risk a top priority requiring immediate mitigation action.
Which document formally records identified risks, their likelihood, impact, owners, and response plans?
Answer: Risk Register
A Risk Register is the primary tool for capturing, tracking, and managing all identified risks throughout the project or organization.
A company's compliance team finds that an employee submitted false expense reports totaling $4,000. This is best classified as:
Answer: Operational risk — internal fraud
Internal fraud by an employee is a textbook operational risk event under frameworks such as Basel II/III.
When conducting a Third-Party Risk Assessment (TPRA), which due diligence element is MOST critical for a supplier handling sensitive customer data?
Answer: Information security and data privacy controls
For suppliers with access to sensitive data, assessing their information security controls is the highest-priority due diligence item.
The principle of 'segregation of duties' in compliance and internal control primarily aims to:
Answer: Reduce errors and fraud by requiring multiple individuals to complete sensitive processes
Segregation of duties ensures no single individual controls all steps of a critical process, reducing the opportunity for errors or fraud.