CCM Compliance Monitoring and Reporting 3 â Questions and Answers
Question 1: Which of the following BEST describes the concept of 'control testing' within a compliance monitoring program?
- Reviewing whether written policies exist for each regulatory requirement
- Evaluating whether specific controls operate effectively in practice to mitigate identified risks (Correct answer)
- Assessing whether the compliance department has sufficient staffing
- Determining whether employees have signed the code of conduct
Correct answer: Evaluating whether specific controls operate effectively in practice to mitigate identified risks
Control testing verifies that controls actually function as intendedânot merely that they are documentedâby examining evidence of their operation over a defined period.
Question 2: In the three lines of defense model, which line is primarily responsible for day-to-day compliance monitoring of business operations?
- Internal audit (third line)
- The compliance function (second line)
- Business unit management and staff (first line) (Correct answer)
- External regulators
Correct answer: Business unit management and staff (first line)
The first line of defenseâbusiness unit managers and employeesâowns day-to-day risk management and compliance monitoring within their own processes.
Question 3: A compliance report shows that 8% of loan files reviewed are missing required disclosures, compared to a 2% threshold. How should the compliance officer categorize this result?
- An acceptable variance because it is below 10%
- A significant exception requiring escalation and corrective action (Correct answer)
- A trend to watch in the next reporting cycle before acting
- An immaterial finding because the absolute number of files is small
Correct answer: A significant exception requiring escalation and corrective action
Exceeding a defined threshold by 400% constitutes a significant exception that must be escalated and remediated regardless of the absolute file count.
Question 4: Which reporting structure is MOST effective for preserving compliance function independence?
- The Chief Compliance Officer reports to the Chief Financial Officer
- The Chief Compliance Officer reports directly to the CEO or board of directors (Correct answer)
- Compliance reports are reviewed only by the business unit they cover
- The compliance team is embedded within individual business units with no central oversight
Correct answer: The Chief Compliance Officer reports directly to the CEO or board of directors
Reporting directly to the CEO or board provides independence from business unit pressures and ensures compliance findings receive unfiltered attention at the highest level.
Question 5: What is a 'heat map' used for in compliance monitoring and reporting?
- Tracking employee training completion by geographic location
- Visually representing the likelihood and impact of identified compliance risks to prioritize monitoring efforts (Correct answer)
- Mapping regulatory citations to specific policy sections
- Displaying real-time transaction volumes by branch
Correct answer: Visually representing the likelihood and impact of identified compliance risks to prioritize monitoring efforts
A heat map plots risks on a likelihood-vs-impact matrix using color coding, enabling compliance teams to visually prioritize where monitoring resources should be concentrated.
Question 6: When a compliance monitoring program identifies a systemic control failure affecting multiple business lines, what is the MOST appropriate corrective action approach?
- Address each business line individually as issues are discovered
- Design an enterprise-wide remediation plan that addresses the root cause across all affected areas simultaneously (Correct answer)
- Assign blame to the business unit leaders and close the finding
- Wait for the next scheduled audit cycle before remediating
Correct answer: Design an enterprise-wide remediation plan that addresses the root cause across all affected areas simultaneously
Systemic failures require enterprise-wide remediation targeting the root cause; piecemeal fixes leave the underlying control weakness intact across the organization.
Question 7: Which of the following is an example of a LEADING compliance indicator, as opposed to a lagging indicator?
- Number of regulatory enforcement actions received last year
- Percentage of employees who completed annual compliance training this quarter (Correct answer)
- Total dollar amount of fines paid in the prior fiscal year
- Number of customer complaints resolved after escalation
Correct answer: Percentage of employees who completed annual compliance training this quarter
Training completion rates are leading indicators because they measure inputs that influence future compliance behavior, whereas fines, enforcement actions, and complaints reflect past failures.
Which of the following BEST describes the concept of 'control testing' within a compliance monitoring program?