CCM Policy Development & Implementation 3 — Questions and Answers
Question 1: Which of the following BEST describes a 'principles-based' compliance policy approach?
- Policies list every prohibited action in exhaustive detail
- Policies articulate broad ethical principles and rely on employee judgment for application (Correct answer)
- Policies are driven entirely by regulator-issued checklists
- Policies apply only to senior management
Correct answer: Policies articulate broad ethical principles and rely on employee judgment for application
Principles-based policies set high-level ethical standards and expect employees to apply judgment, contrasting with rules-based approaches that enumerate specific prohibitions.
Question 2: A financial services firm is implementing a new conflicts-of-interest policy. Which control mechanism BEST reinforces policy compliance?
- Publishing the policy PDF on the employee portal
- Requiring annual written disclosures and review by a compliance committee (Correct answer)
- Mentioning the policy in new-hire orientation once
- Relying on employees to self-identify conflicts voluntarily
Correct answer: Requiring annual written disclosures and review by a compliance committee
Mandatory annual disclosures reviewed by a compliance committee create ongoing accountability and a documented trail of conflict management.
Question 3: Policy ownership is BEST assigned to whom?
- The CEO, who bears ultimate accountability
- The business unit leader most directly affected by the policy's subject matter (Correct answer)
- An external consultant who drafted the policy
- The IT department as system custodian
Correct answer: The business unit leader most directly affected by the policy's subject matter
Assigning policy ownership to the relevant business unit leader ensures accountability rests with those closest to the operational impact.
Question 4: During a policy review cycle, legal counsel recommends adding a provision that operations believes will create unworkable procedures. What should the compliance manager do?
- Adopt the legal provision verbatim without modification
- Ignore the legal recommendation and finalize the policy without it
- Facilitate a cross-functional discussion to find a provision that is both legally sound and operationally feasible (Correct answer)
- Escalate immediately to the board of directors
Correct answer: Facilitate a cross-functional discussion to find a provision that is both legally sound and operationally feasible
Effective policy development requires balancing legal requirements with operational feasibility, achieved through structured cross-functional collaboration.
Question 5: A U.S. bank issues a policy that all wire transfer requests above $10,000 must receive dual authorization. This policy is PRIMARILY designed to comply with which requirement?
- OSHA workplace safety standards
- Bank Secrecy Act / Anti-Money Laundering requirements (Correct answer)
- Americans with Disabilities Act
- Fair Labor Standards Act
Correct answer: Bank Secrecy Act / Anti-Money Laundering requirements
The Bank Secrecy Act and associated AML regulations require financial institutions to implement controls over large transactions to detect and report suspicious activity.
Question 6: Which metric BEST measures policy implementation effectiveness after rollout?
- Number of pages in the policy document
- Employee attestation completion rate combined with audit finding rates (Correct answer)
- Time elapsed since the last policy revision
- Number of executives who approved the policy
Correct answer: Employee attestation completion rate combined with audit finding rates
Combining attestation completion rates with audit findings gives a balanced view of both reach and actual behavioral compliance.
Question 7: When implementing a data privacy policy under CCPA for a California-based company, which element is legally REQUIRED to be included?
- A mandatory arbitration clause for all data disputes
- Consumer rights to know, delete, and opt out of the sale of personal information (Correct answer)
- A prohibition on all data sharing with third parties
- Annual board-level data privacy certification
Correct answer: Consumer rights to know, delete, and opt out of the sale of personal information
The California Consumer Privacy Act requires businesses to disclose and honor consumer rights to know what data is collected, request deletion, and opt out of data sales.
Which of the following BEST describes a 'principles-based' compliance policy approach?