โ† All CCM Flashcard Decks

Risk Management and Compliance Flashcards

7 cards from real CCM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Management and Compliance flashcards as text
  1. A residual risk is best defined as the risk that remains after:

    Answer: Application of controls and mitigation measures

    Residual risk is the level of risk remaining after controls and mitigation strategies have been applied to the inherent risk.

  2. Which international standard provides a framework specifically for anti-bribery management systems?

    Answer: ISO 37001

    ISO 37001 specifies requirements for establishing, implementing, and maintaining an anti-bribery management system.

  3. A 'whistle-blower' policy in a compliance program is designed primarily to:

    Answer: Provide a safe channel for employees to report suspected violations without retaliation

    Whistle-blower policies create protected reporting channels, encouraging employees to surface misconduct without fear of retaliation.

  4. In contract risk management, a 'limitation of liability' clause is designed to:

    Answer: Cap the maximum financial exposure either party bears under the contract

    A limitation of liability clause sets a ceiling on damages recoverable under the contract, protecting parties from open-ended financial exposure.

  5. Regulatory compliance risk refers to the risk that an organization will suffer penalties due to:

    Answer: Violating laws, regulations, or industry codes

    Regulatory compliance risk arises when an organization fails to adhere to applicable laws, regulations, or standards, leading to fines, sanctions, or reputational damage.

  6. A company uses Key Risk Indicators (KRIs) to:

    Answer: Provide early warning signals that risk levels may be changing

    KRIs are forward-looking metrics that signal when risks are trending toward or beyond acceptable thresholds, enabling proactive management.

  7. Under US export control regulations (EAR/ITAR), 'deemed exports' refer to:

    Answer: Technology disclosed to foreign nationals within the United States

    A deemed export occurs when controlled technology or software is released to a foreign national in the US, which is treated as an export to their home country.