← All CCM Flashcard Decks

Risk Management and Compliance Flashcards

7 cards from real CCM practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Management and Compliance flashcards as text
  1. Anti-money laundering (AML) programs require financial institutions and certain businesses to file a Suspicious Activity Report (SAR) when:

    Answer: Transactions are suspected to involve proceeds of illegal activity

    SARs must be filed when a firm knows, suspects, or has reason to suspect that a transaction involves funds derived from illegal activity or is designed to evade reporting requirements.

  2. A 'black swan' event in risk management refers to:

    Answer: An extremely rare, high-impact event that is difficult to predict in advance

    A black swan is a rare, outlier event with massive impact that defies conventional prediction, as coined by Nassim Taleb.

  3. The 'tone at the top' concept in compliance refers to:

    Answer: Senior leadership's visible commitment to ethical conduct setting the cultural standard for the organization

    Tone at the top means that senior executives model ethical behavior and prioritize compliance, which cascades through the entire organizational culture.

  4. A contractual 'indemnification' clause requires one party to:

    Answer: Compensate or hold harmless the other party for specific losses or liabilities

    An indemnification clause obligates one party to compensate the other for losses, damages, or liabilities arising from specified events or breaches.

  5. Risk scenarios involving interconnected failures across multiple systems or parties are known as:

    Answer: Systemic or cascading risks

    Systemic or cascading risks describe situations where a failure in one component triggers failures across connected systems, amplifying overall impact.

  6. A company implements a vendor code of conduct as part of its supply chain compliance program. The PRIMARY purpose is to:

    Answer: Ensure vendors meet the company's ethical, environmental, and legal standards

    A vendor code of conduct sets explicit expectations for supplier behavior regarding ethics, labor, environment, and legal compliance, extending the company's standards into the supply chain.

  7. In enterprise risk management (ERM), the 'three lines of defense' model assigns internal audit as the:

    Answer: Third line — providing independent assurance to the board and senior management

    Internal audit serves as the third line of defense by independently assessing the effectiveness of risk management and controls implemented by the first and second lines.