Chief Compliance Officer (CCO) Qualifying Examination — Questions and Answers
Question 1: What is the 'compliance universe' in program management?
- A database of past violations
- The set of all third-party vendors used by the company
- The full inventory of laws, regulations, standards, and internal policies that apply to the organization (Correct answer)
- All employees subject to compliance training
Correct answer: The full inventory of laws, regulations, standards, and internal policies that apply to the organization
The compliance universe maps every applicable legal and regulatory requirement, forming the foundation for the risk assessment and program design.
Question 2: What is the GDPR requirement for reporting a personal data breach to supervisory authorities?
- Within 72 hours of becoming aware of the breach, unless it is unlikely to result in risk to individuals (Correct answer)
- Within 30 days of discovery
- Only if more than 1,000 individuals are affected
- Within 7 days of discovery
Correct answer: Within 72 hours of becoming aware of the breach, unless it is unlikely to result in risk to individuals
GDPR requires notifying the relevant supervisory authority within 72 hours of discovering a personal data breach, unless the breach is low-risk.
Question 3: What is the difference between preventive and detective controls?
- Detective controls are more important than preventive controls
- Preventive controls are manual; detective controls are automated
- Preventive controls stop violations before they occur; detective controls identify violations after they have occurred (Correct answer)
- Preventive controls apply to finances; detective controls apply to IT systems
Correct answer: Preventive controls stop violations before they occur; detective controls identify violations after they have occurred
Preventive controls (e.g., approval requirements) block violations before they happen, while detective controls (e.g., reconciliations) identify them after the fact.
Question 4: What is the California Consumer Privacy Act (CCPA)?
- A federal US data privacy law
- California's state privacy law granting consumers rights over their personal data collected by businesses (Correct answer)
- A regulation governing data centers only
- A credit reporting act specific to California
Correct answer: California's state privacy law granting consumers rights over their personal data collected by businesses
The CCPA gives California consumers the right to know, delete, and opt out of the sale of their personal information held by qualifying businesses.
Question 5: What is the most effective way to ensure that a third-party compliance program remains current as vendor relationships and regulations evolve?
- Rely exclusively on vendor self-attestations submitted at contract signing
- Implement periodic re-assessments, continuous monitoring, and annual program reviews tied to regulatory changes and vendor risk changes (Correct answer)
- Conduct a one-time comprehensive vendor review at program inception
- Assign compliance responsibilities entirely to the procurement team
Correct answer: Implement periodic re-assessments, continuous monitoring, and annual program reviews tied to regulatory changes and vendor risk changes
Third-party compliance programs must be living documents that incorporate continuous monitoring, periodic re-assessments, and updates triggered by regulatory changes or material changes in vendor risk profiles.
Question 6: What does a vendor's SOC 2 Type II report assess?
- The vendor's adherence to employment discrimination laws
- The vendor's compliance with environmental sustainability standards
- The vendor's financial solvency and credit rating
- The effectiveness of the vendor's controls related to security, availability, and confidentiality over a defined operating period (Correct answer)
Correct answer: The effectiveness of the vendor's controls related to security, availability, and confidentiality over a defined operating period
A SOC 2 Type II report evaluates whether a service organization's controls related to the Trust Service Criteria (security, availability, processing integrity, confidentiality, privacy) were operating effectively over a review period.
Question 7: What does 'reasonable assurance' mean in the context of internal controls?
- That all errors and fraud will be detected
- That controls meet the minimum regulatory standard
- That controls provide a high but not absolute level of assurance that objectives will be met, given inherent limitations of any control system (Correct answer)
- That management is satisfied with control outcomes
Correct answer: That controls provide a high but not absolute level of assurance that objectives will be met, given inherent limitations of any control system
Reasonable assurance acknowledges that no control system is perfect and that there are inherent limitations — cost/benefit tradeoffs and human fallibility mean absolute assurance is unachievable.
Question 8: What is the primary risk of a compliance program that focuses only on rules without fostering an ethical culture?
- Reduced training costs
- Excessive reporting to regulators
- Over-compliance with regulations
- Employees comply technically while evading the spirit of the rules (Correct answer)
Correct answer: Employees comply technically while evading the spirit of the rules
Rules-only programs often produce technical compliance without genuine ethical behavior, leaving organizations vulnerable to creative violations not explicitly prohibited.
Question 9: What are the three stages of the money laundering process?
- Sourcing, transferring, and concealing
- Reporting, monitoring, and sanctioning
- Placement, layering, and integration (Correct answer)
- Detection, investigation, and prosecution
Correct answer: Placement, layering, and integration
Money laundering moves through placement (introducing dirty money), layering (obscuring its trail), and integration (reintroducing it as legitimate funds).
Question 10: What is a compliance audit and how does it differ from monitoring?
- They are identical processes performed by different teams
- Monitoring is ongoing and control-focused; auditing is periodic, independent, and provides deeper assurance about the adequacy of the overall program (Correct answer)
- Monitoring is done by external parties; auditing is internal
- Auditing focuses on financial data only; monitoring covers all risk areas
Correct answer: Monitoring is ongoing and control-focused; auditing is periodic, independent, and provides deeper assurance about the adequacy of the overall program
Monitoring is the day-to-day checking of controls, while auditing is a periodic, independent deep-dive that evaluates whether the overall program is designed and operating effectively.
Question 11: What is terrorist financing and how does it differ from money laundering?
- They are identical processes
- Terrorist financing only involves foreign currencies
- Money laundering always involves larger sums than terrorist financing
- Terrorist financing funds violent acts and can involve legitimate money moved for criminal purposes, while money laundering conceals illegally obtained funds (Correct answer)
Correct answer: Terrorist financing funds violent acts and can involve legitimate money moved for criminal purposes, while money laundering conceals illegally obtained funds
While money laundering cleans dirty money, terrorist financing can involve clean money being directed to fund illegal violent activities.
Question 12: What is the purpose of a Records of Processing Activities (RoPA) under GDPR?
- To log employee access to data systems
- To satisfy financial reporting requirements
- To document all processing activities involving personal data, required for organizations with 250 or more employees or high-risk processing (Correct answer)
- To maintain customer service interaction logs
Correct answer: To document all processing activities involving personal data, required for organizations with 250 or more employees or high-risk processing
A RoPA serves as the organization's inventory of data processing activities and is a key accountability tool under GDPR Article 30.
Question 13: What is a 'key control' in an internal control system?
- The most expensive control in a control framework
- A control that, if absent or ineffective, would result in a material misstatement or significant compliance violation going undetected (Correct answer)
- A password or access credential
- Any control approved by the CFO
Correct answer: A control that, if absent or ineffective, would result in a material misstatement or significant compliance violation going undetected
Key controls are the most critical controls that directly prevent or detect the most significant risks — their failure has material consequences.
Question 14: How should an organization prioritize risks in a risk management plan?
- By addressing risks as they occur
- By focusing only on risks with the highest financial impact
- By outsourcing all risk management responsibilities
- By considering both the likelihood and impact of each risk (Correct answer)
Correct answer: By considering both the likelihood and impact of each risk
Prioritizing risks involves assessing both their likelihood and potential impact on the organization.
Question 15: Which of the following is a key component of an effective risk management framework?
- Outsourcing all risk management activities
- Regularly assessing and updating risk management policies and procedures (Correct answer)
- Ignoring low-probability risks
- Focusing only on financial risks
Correct answer: Regularly assessing and updating risk management policies and procedures
Regularly assessing and updating risk management policies and procedures is crucial for maintaining an effective risk management framework.
Question 16: What is 'de-risking' and what concern does it raise for regulators?
- Eliminating high-risk investments from portfolios
- Reducing credit risk in loan portfolios
- Lowering interest rates to reduce defaults
- Financial institutions exiting entire customer segments to avoid AML compliance burden, raising financial inclusion concerns (Correct answer)
Correct answer: Financial institutions exiting entire customer segments to avoid AML compliance burden, raising financial inclusion concerns
De-risking occurs when banks terminate services for entire categories of customers, which raises financial inclusion concerns and can push activity to less-regulated channels.
Question 17: What is 'Know Your Customer' (KYC)?
- The process of verifying customer identity and assessing financial crime risk before and during a business relationship (Correct answer)
- A customer service initiative
- A marketing segmentation strategy
- A credit scoring method
Correct answer: The process of verifying customer identity and assessing financial crime risk before and during a business relationship
KYC requires financial institutions to verify the identity of clients and assess potential risks of illegal intentions to prevent financial crimes.
Question 18: What is dual-hatting in the context of compliance and legal functions?
- Wearing two hats in cold weather during site visits
- A governance model where two boards share oversight
- A practice of having two compliance officers for redundancy
- When the CCO also serves as General Counsel, potentially creating conflicts between legal privilege and compliance transparency (Correct answer)
Correct answer: When the CCO also serves as General Counsel, potentially creating conflicts between legal privilege and compliance transparency
Dual-hatting the CCO and GC roles can create tension between attorney-client privilege, which favors confidentiality, and compliance obligations, which favor transparency.
Question 19: What is the primary responsibility of a Chief Compliance Officer (CCO)?
- Ensuring the organization complies with regulatory requirements (Correct answer)
- Managing financial statements
- Overseeing marketing strategies
- Supervising human resources
Correct answer: Ensuring the organization complies with regulatory requirements
The CCO is primarily responsible for overseeing and managing regulatory compliance within the organization.
Question 20: What is 'ethical fading'?
- The gradual obsolescence of a Code of Conduct
- A reduction in ethics training frequency
- The psychological process by which ethical considerations recede from awareness during decision-making (Correct answer)
- A decrease in employee engagement
Correct answer: The psychological process by which ethical considerations recede from awareness during decision-making
Ethical fading occurs when the moral dimensions of a decision become less salient due to pressures, habits, or rationalizations.
Question 21: In the context of anti-bribery compliance, what is a 'red flag' that should heighten scrutiny of a third-party intermediary?
- The intermediary operates in multiple countries simultaneously
- The intermediary requests unusual payment structures such as cash payments or payments to a third country (Correct answer)
- The intermediary has staff who previously worked at a competitor
- The intermediary charges standard market rates for its services
Correct answer: The intermediary requests unusual payment structures such as cash payments or payments to a third country
Unusual payment requests—such as cash, payments to undisclosed parties, or payments routed through unrelated jurisdictions—are classic red flags for potential bribery or money laundering through third parties.
Question 22: What does 'pseudonymization' mean in data privacy?
- Encrypting all data at rest
- Replacing directly identifying information with artificial identifiers so data cannot be attributed to a specific person without additional information (Correct answer)
- Sharing data in aggregate form only
- Permanently deleting personal data
Correct answer: Replacing directly identifying information with artificial identifiers so data cannot be attributed to a specific person without additional information
Pseudonymization replaces identifying fields with artificial identifiers, reducing re-identification risk while still allowing data utility, though it differs from full anonymization.
Question 23: A CCO discovers that a third-party vendor has been convicted of bribery in a foreign jurisdiction. Under the Foreign Corrupt Practices Act (FCPA), what is the primary concern for the organization?
- The organization must report the vendor to the SEC within 30 days
- The vendor's contract must be renegotiated immediately
- Only the vendor's executives face FCPA liability
- The organization may be held liable for the vendor's corrupt acts performed on its behalf (Correct answer)
Correct answer: The organization may be held liable for the vendor's corrupt acts performed on its behalf
The FCPA extends liability to companies for corrupt acts committed by third parties acting on their behalf, making thorough vendor vetting essential.
Question 24: Which metric is most useful for measuring the effectiveness of an ethics hotline?
- Reports submitted, investigation closure rate, and substantiation rate (Correct answer)
- Number of callers per day
- Cost of running the hotline
- Number of anonymous versus named reporters
Correct answer: Reports submitted, investigation closure rate, and substantiation rate
Reports submitted, closure rates, and substantiation rates together indicate whether the hotline is functioning as an effective reporting channel.
Question 25: What does the Sarbanes-Oxley Act (SOX) require of public company CEOs and CFOs?
- Quarterly reporting to the SEC on personal transactions
- Personal certification of the accuracy of financial statements and the effectiveness of internal controls (Correct answer)
- Annual ethics training completion
- Publication of their personal financial statements
Correct answer: Personal certification of the accuracy of financial statements and the effectiveness of internal controls
SOX Section 302 requires CEOs and CFOs to personally certify the accuracy of financial reports and the effectiveness of internal controls, creating personal accountability.
Question 26: What is the purpose of an Audit Committee in corporate governance?
- To perform the annual external audit
- To oversee financial reporting, internal controls, risk management, and the internal audit function on behalf of the Board (Correct answer)
- To manage relationships with external auditors only
- To approve the company's budget
Correct answer: To oversee financial reporting, internal controls, risk management, and the internal audit function on behalf of the Board
The Audit Committee provides Board-level oversight of financial integrity, internal controls, and the independence of both internal and external audit functions.
Question 27: What should a CCO do when they discover that a senior executive is violating the Code of Conduct?
- Report it to the appropriate governance body, such as the Audit Committee or Board (Correct answer)
- Terminate the executive immediately without investigation
- Handle it informally without documentation
- Ignore it to avoid conflict
Correct answer: Report it to the appropriate governance body, such as the Audit Committee or Board
CCOs must escalate executive misconduct to the appropriate governance body, such as the Audit Committee, ensuring accountability at all levels.
Question 28: How often should an organization's compliance policies and procedures be reviewed?
- Annually or as needed when regulations change (Correct answer)
- When an issue arises
- Only during external audits
- Every 10 years
Correct answer: Annually or as needed when regulations change
Compliance policies and procedures should be reviewed regularly, typically annually, or when regulations change.
Question 29: What is 'vendor concentration risk' in a third-party compliance program?
- The risk that vendor pricing is concentrated among high-cost providers
- The risk that one vendor supplies competing firms
- The risk that a vendor's workforce is too concentrated in one geographic area
- The risk arising when too many critical functions depend on a single vendor, creating a single point of failure (Correct answer)
Correct answer: The risk arising when too many critical functions depend on a single vendor, creating a single point of failure
Vendor concentration risk occurs when an organization relies too heavily on a single third party for critical functions, so any disruption to that vendor can cripple the organization's operations and compliance posture.
Question 30: Which type of risk is associated with regulatory changes and compliance requirements?
- Operational risk
- Compliance risk (Correct answer)
- Credit risk
- Market risk
Correct answer: Compliance risk
Compliance risk is associated with regulatory changes and the need to adhere to compliance requirements.
Question 31: Which regulation requires financial institutions to develop and implement a written information security plan?
- Gramm-Leach-Bliley Act (GLBA) (Correct answer)
- Fair Labor Standards Act (FLSA)
- Sarbanes-Oxley Act
- Health Insurance Portability and Accountability Act (HIPAA)
Correct answer: Gramm-Leach-Bliley Act (GLBA)
GLBA requires financial institutions to develop and implement a written information security plan.
Question 32: What is continuous auditing?
- A process where all employees continuously audit their own work
- Using automated tools to analyze transactions and controls on an ongoing basis, providing near-real-time assurance rather than periodic spot checks (Correct answer)
- Performing audits every day of the week
- Auditing the same area in consecutive years
Correct answer: Using automated tools to analyze transactions and controls on an ongoing basis, providing near-real-time assurance rather than periodic spot checks
Continuous auditing uses technology to monitor transactions and controls in near-real-time, enabling earlier detection of anomalies than traditional periodic audits.
Question 33: What is an audit risk model?
- A financial model estimating audit costs
- A risk rating system for regulatory violations
- A model for assessing auditor independence
- A framework combining inherent risk, control risk, and detection risk to determine the audit procedures needed to achieve acceptable assurance levels (Correct answer)
Correct answer: A framework combining inherent risk, control risk, and detection risk to determine the audit procedures needed to achieve acceptable assurance levels
The audit risk model helps auditors calibrate the nature, timing, and extent of procedures based on the combination of inherent, control, and detection risks in each area.
Question 34: What is the 'reasonable person standard' in compliance?
- A benchmark asking whether a reasonable, objective person would conclude that actions taken were appropriate given the circumstances (Correct answer)
- A legal definition of negligence in criminal law
- A threshold for triggering a compliance investigation
- A standard measuring average employee performance
Correct answer: A benchmark asking whether a reasonable, objective person would conclude that actions taken were appropriate given the circumstances
The reasonable person standard evaluates whether conduct meets the expected norm of a thoughtful, objective person in similar circumstances, used in both legal and compliance contexts.
Question 35: When offboarding a vendor who handled sensitive personal data, what is the compliance officer's primary obligation?
- Ensure the vendor provides a positive reference for future business
- Verify that the vendor has returned or securely destroyed all personal data per contractual and regulatory requirements (Correct answer)
- Notify the vendor's competitors that they may now solicit the business
- Transfer the vendor's employees to the organization's payroll
Correct answer: Verify that the vendor has returned or securely destroyed all personal data per contractual and regulatory requirements
Data destruction or return upon offboarding is a critical regulatory and contractual requirement under frameworks like GDPR and CCPA to prevent unauthorized retention or use of personal data by former vendors.
Question 36: What is the role of a whistleblower in the context of regulatory compliance?
- To oversee financial reporting
- To create new regulations
- To report misconduct or violations within the organization (Correct answer)
- To implement marketing campaigns
Correct answer: To report misconduct or violations within the organization
A whistleblower reports misconduct or regulatory violations within the organization.
Question 37: What is a security incident response plan in the context of data privacy compliance?
- A plan for responding to negative media coverage
- A marketing communication plan for after a breach
- An IT disaster recovery plan for hardware failures
- A documented process for detecting, containing, assessing, notifying, and recovering from data security incidents (Correct answer)
Correct answer: A documented process for detecting, containing, assessing, notifying, and recovering from data security incidents
An incident response plan ensures the organization can act quickly and methodically when a data breach occurs, meeting notification timelines and minimizing harm.
Question 38: What is a management response to an audit finding?
- A regulatory notification of audit results
- A rebuttal challenging the auditor's conclusions
- A formal response from management agreeing with or disputing the finding and committing to specific corrective actions with timelines (Correct answer)
- A press release about audit outcomes
Correct answer: A formal response from management agreeing with or disputing the finding and committing to specific corrective actions with timelines
Management responses commit the business to remediation actions, owners, and deadlines for each audit finding, creating accountability for resolving control deficiencies.
Question 39: What is the role of internal audit in a fraud investigation?
- To discipline employees found to have committed fraud
- To publicly report fraud findings
- To provide investigative skills, data analysis, and process knowledge to support or conduct investigations, typically under direction of legal counsel (Correct answer)
- To serve as primary law enforcement investigators
Correct answer: To provide investigative skills, data analysis, and process knowledge to support or conduct investigations, typically under direction of legal counsel
Internal audit contributes analytical capabilities to fraud investigations but typically operates under legal counsel's direction to preserve privilege and ensure investigative integrity.
Question 40: What is risk appetite?
- The strategy to eliminate all risks
- The total number of risks an organization can face
- The amount and type of risk an organization is willing to accept in pursuit of its objectives (Correct answer)
- The focus on short-term risks only
Correct answer: The amount and type of risk an organization is willing to accept in pursuit of its objectives
Risk appetite refers to the level and type of risk an organization is willing to take on in pursuit of its goals.
Question 41: What is the significance of cross-border data transfer restrictions under GDPR?
- They prevent all international business communications
- They prohibit cloud storage in non-EU countries entirely
- They restrict transferring personal data to countries outside the EEA that do not have adequate data protection levels (Correct answer)
- They apply only to financial data
Correct answer: They restrict transferring personal data to countries outside the EEA that do not have adequate data protection levels
GDPR restricts transfers of personal data to third countries unless the destination has an adequacy decision or appropriate safeguards like Standard Contractual Clauses are in place.
Question 42: What is the significance of the Federal Sentencing Guidelines for compliance programs?
- They set regulatory fines for financial institutions
- They define SEC enforcement standards
- They establish the criteria for an 'effective compliance program' that can reduce organizational culpability and fines if violations occur (Correct answer)
- They determine criminal sentences only
Correct answer: They establish the criteria for an 'effective compliance program' that can reduce organizational culpability and fines if violations occur
The Federal Sentencing Guidelines' seven elements of an effective compliance program are the foundational benchmark used by prosecutors and regulators to evaluate program quality.
Question 43: What is the primary purpose of a vendor risk tiering system in a compliance program?
- To rank vendors by annual contract value for budget planning
- To determine which vendors qualify for most-favored-nation pricing
- To schedule vendor audits in alphabetical order
- To allocate oversight resources proportionally based on the risk each vendor poses (Correct answer)
Correct answer: To allocate oversight resources proportionally based on the risk each vendor poses
Risk tiering allows a compliance program to focus its limited oversight resources on vendors that pose the greatest potential harm, making the program more efficient and effective.
Question 44: What is a control deficiency and how does it differ from a material weakness?
- They are identical terms used interchangeably
- Material weaknesses apply only to cybersecurity controls
- A control deficiency is any shortfall; a material weakness is one that creates a reasonable possibility of a material misstatement going undetected (Correct answer)
- A control deficiency is discovered by external auditors; a material weakness is found internally
Correct answer: A control deficiency is any shortfall; a material weakness is one that creates a reasonable possibility of a material misstatement going undetected
Control deficiencies exist on a spectrum — a material weakness is the most severe, representing a significant risk that financial statements could be materially misstated.
Question 45: Which phase of the third-party lifecycle is most critical for identifying compliance risks before a vendor relationship begins?
- Ongoing monitoring
- Offboarding and termination
- Due diligence and onboarding (Correct answer)
- Contract negotiation
Correct answer: Due diligence and onboarding
Due diligence during onboarding is the most critical phase because it identifies compliance, legal, and reputational risks before the organization is exposed through the relationship.
Question 46: What is the three-way match in procurement controls?
- Comparing the purchase order, receiving report, and vendor invoice to verify all three agree before payment is approved (Correct answer)
- A three-signature approval requirement
- Matching three regulatory requirements to a single policy
- Matching three bids for every purchase
Correct answer: Comparing the purchase order, receiving report, and vendor invoice to verify all three agree before payment is approved
Three-way matching is a preventive control that ensures payment is only made when the ordered, received, and invoiced quantities and amounts all agree.
Question 47: What is the significance of annual ethics certifications signed by employees?
- They are primarily a legal technicality
- They are only required for executives
- They confirm employee awareness and acknowledgment of ethics obligations (Correct answer)
- They replace the need for ethics training
Correct answer: They confirm employee awareness and acknowledgment of ethics obligations
Annual certifications confirm that employees have read, understood, and agreed to abide by the Code of Conduct, creating a documented record of acknowledgment.
Question 48: Which federal agency is primarily responsible for enforcing securities laws in the United States?
- Environmental Protection Agency (EPA)
- Federal Communications Commission (FCC)
- Federal Trade Commission (FTC)
- Securities and Exchange Commission (SEC) (Correct answer)
Correct answer: Securities and Exchange Commission (SEC)
The SEC is the federal agency responsible for enforcing securities laws and regulating the securities industry.
Question 49: What does GDPR stand for and which organizations must comply with it?
- Global Data Privacy Rules; applies to US multinational companies only
- Government Data Protection Regulation; applies to public sector entities
- General Data Reporting Regulation; applies only to EU companies
- General Data Protection Regulation; applies to any organization processing personal data of EU residents (Correct answer)
Correct answer: General Data Protection Regulation; applies to any organization processing personal data of EU residents
GDPR is the EU's comprehensive data protection law that applies to any organization, regardless of location, that processes personal data of EU residents.
Question 50: What is Enhanced Due Diligence (EDD) and when is it required?
- A simplified process for low-risk customers
- A one-time review at account opening
- Additional scrutiny applied to high-risk customers, such as politically exposed persons or customers from high-risk jurisdictions (Correct answer)
- Standard due diligence for all customers
Correct answer: Additional scrutiny applied to high-risk customers, such as politically exposed persons or customers from high-risk jurisdictions
EDD requires more rigorous verification and ongoing monitoring for customers who pose elevated AML risks, including PEPs and those from high-risk countries.
Question 51: What does a Suspicious Activity Report (SAR) require from a financial institution?
- Public disclosure to law enforcement
- Notification to the customer that they are under review
- Immediate freezing of the customer's account
- Confidential filing with FinCEN when suspicious transactions are detected (Correct answer)
Correct answer: Confidential filing with FinCEN when suspicious transactions are detected
SARs must be filed confidentially with FinCEN when transactions suggest money laundering, fraud, or other financial crimes without alerting the subject.
Question 52: Which element is typically included in a vendor contract's compliance addendum?
- Audit rights allowing the organization to inspect the vendor's compliance records (Correct answer)
- Guaranteed profit margins for the vendor
- Exclusivity clauses preventing the vendor from serving competitors
- Indemnification solely in favor of the vendor
Correct answer: Audit rights allowing the organization to inspect the vendor's compliance records
Audit rights in compliance addenda give organizations the ability to verify that vendors are meeting their contractual and regulatory obligations.
Question 53: What is the purpose of a third-party code of conduct?
- To extend the company's ethical standards to vendors, suppliers, and partners (Correct answer)
- To replace vendor contracts
- To serve as a marketing tool for suppliers
- To comply with SEC reporting requirements
Correct answer: To extend the company's ethical standards to vendors, suppliers, and partners
A third-party code of conduct sets ethical expectations for business partners, reducing the risk of reputational or legal harm from partner misconduct.
Question 54: Which regulatory framework specifically requires financial institutions to conduct due diligence on third-party vendors who handle sensitive customer data?
- Gramm-Leach-Bliley Act (GLBA) (Correct answer)
- Robinson-Patman Act
- Sarbanes-Oxley Act (SOX)
- Sherman Antitrust Act
Correct answer: Gramm-Leach-Bliley Act (GLBA)
The GLBA requires financial institutions to have programs ensuring customer financial information remains protected even when shared with or processed by third-party service providers.
Question 55: What is the purpose of the Sarbanes-Oxley Act (SOX)?
- To manage labor relations
- To oversee telecommunications
- To regulate environmental standards
- To protect investors by improving the accuracy and reliability of corporate disclosures (Correct answer)
Correct answer: To protect investors by improving the accuracy and reliability of corporate disclosures
SOX was enacted to protect investors by enhancing the accuracy and reliability of corporate disclosures.
Question 56: What is 'succession planning' in the context of CCO governance?
- Planning for regulatory succession during mergers
- Ensuring qualified candidates are identified and developed to assume the CCO role if the position becomes vacant (Correct answer)
- Planning for the company's eventual dissolution
- A retirement planning service for executives
Correct answer: Ensuring qualified candidates are identified and developed to assume the CCO role if the position becomes vacant
CCO succession planning ensures continuity of compliance leadership and program effectiveness, preventing gaps in oversight when the CCO role changes.
Question 57: What is a compliance training needs analysis?
- A survey of training preferences
- An evaluation of training vendor costs
- An assessment of whether employees enjoy compliance training
- The process of identifying which employees need what training based on their roles, risk exposure, and past training gaps (Correct answer)
Correct answer: The process of identifying which employees need what training based on their roles, risk exposure, and past training gaps
A training needs analysis ensures compliance training is targeted, relevant, and proportionate to the actual risks faced by each employee group.
Question 58: What is the purpose of compliance monitoring?
- To routinely check that controls are in place and functioning as intended, detecting issues before they become violations (Correct answer)
- To conduct investigations into past misconduct
- To replace internal audit functions
- To manage regulatory relationships
Correct answer: To routinely check that controls are in place and functioning as intended, detecting issues before they become violations
Compliance monitoring uses ongoing checks to verify that policies and controls are operating effectively and to detect deviations before they escalate.
Question 59: Which action demonstrates a commitment to a culture of compliance within an organization?
- Focusing solely on profit maximization
- Providing transparent communication and support for compliance initiatives (Correct answer)
- Punishing employees for reporting issues
- Discouraging employee involvement in compliance matters
Correct answer: Providing transparent communication and support for compliance initiatives
A commitment to a culture of compliance includes transparent communication and support for compliance initiatives, encouraging employees to uphold and participate in compliance efforts.
Question 60: What does OFAC stand for and what is its role?
- Office of Financial Accounting and Compliance; sets GAAP standards
- Office of Federal Audit Control; oversees bank examinations
- Office of Foreign Acquisitions and Commerce; reviews mergers
- Office of Foreign Assets Control; administers US economic and trade sanctions (Correct answer)
Correct answer: Office of Foreign Assets Control; administers US economic and trade sanctions
OFAC is the US Treasury bureau that administers and enforces economic and trade sanctions against targeted foreign countries, entities, and individuals.
Question 61: What is the purpose of a transaction monitoring system in AML compliance?
- To generate customer account statements
- To process payments faster
- To automatically detect unusual patterns of activity that may indicate money laundering or other financial crimes (Correct answer)
- To maximize transaction fees
Correct answer: To automatically detect unusual patterns of activity that may indicate money laundering or other financial crimes
Transaction monitoring systems use rules and analytics to flag unusual activity patterns for investigation by compliance analysts.
Question 62: What is the primary governance role of the Board of Directors regarding compliance?
- Day-to-day management of compliance operations
- Drafting individual compliance policies
- Setting the ethical tone, overseeing the compliance program, and holding management accountable (Correct answer)
- Conducting internal investigations personally
Correct answer: Setting the ethical tone, overseeing the compliance program, and holding management accountable
The Board sets strategic direction and ethical culture, oversees the compliance program's effectiveness, and holds management accountable for its operation.
Question 63: What is the purpose of a compliance program effectiveness review?
- To evaluate individual employee compliance
- To identify ways to reduce compliance staff
- To assess whether the compliance program is adequately designed, resourced, and operating effectively to prevent and detect violations (Correct answer)
- To satisfy an annual budgeting exercise
Correct answer: To assess whether the compliance program is adequately designed, resourced, and operating effectively to prevent and detect violations
Effectiveness reviews assess whether the program's design and operation actually prevent and detect misconduct, using metrics, surveys, testing, and benchmarking.
Question 64: What is the COSO Internal Control Framework?
- A risk management framework specific to banking
- A widely used framework defining internal control components: control environment, risk assessment, control activities, information/communication, and monitoring (Correct answer)
- A mandatory auditing standard for public companies
- A financial reporting standard issued by the SEC
Correct answer: A widely used framework defining internal control components: control environment, risk assessment, control activities, information/communication, and monitoring
The COSO framework provides the structure used by most organizations to design and evaluate internal controls across five integrated components.
Question 65: What is the role of internal audits in risk management?
- To handle customer service complaints
- To manage employee payroll
- To independently assess and evaluate the effectiveness of risk management processes (Correct answer)
- To promote new products
Correct answer: To independently assess and evaluate the effectiveness of risk management processes
Internal audits play a role in independently assessing and evaluating the effectiveness of an organization's risk management processes.
Question 66: Which due diligence tool is most effective for screening third-party vendors against global sanctions lists and politically exposed persons (PEPs)?
- An automated screening solution integrated with OFAC, UN, and other global watchlists (Correct answer)
- Reviewing the vendor's annual report
- Checking the vendor's LinkedIn company page
- A general internet search
Correct answer: An automated screening solution integrated with OFAC, UN, and other global watchlists
Automated screening tools that continuously check vendors against OFAC, EU, UN, and other sanctions and PEP lists provide the most reliable and scalable compliance coverage for anti-money laundering and sanctions obligations.
Question 67: What is the primary purpose of a corporate Code of Conduct?
- To serve as a marketing document
- To define acceptable and unacceptable behaviors within the organization (Correct answer)
- To outline employee benefits
- To list all company policies verbatim
Correct answer: To define acceptable and unacceptable behaviors within the organization
A Code of Conduct defines the ethical standards and behavioral expectations for all employees and leaders.
Question 68: What is Customer Due Diligence (CDD) in AML compliance?
- A process for resolving customer complaints
- A credit review process
- The process of identifying and verifying customer identity and assessing the nature of their business relationship to detect suspicious activity (Correct answer)
- Annual account rebalancing
Correct answer: The process of identifying and verifying customer identity and assessing the nature of their business relationship to detect suspicious activity
CDD requires firms to collect and verify customer identity information and understand the expected nature of their transactions to detect anomalies.
Question 69: Which of the following best describes an 'ethical dilemma'?
- A documented compliance failure
- A disagreement between managers
- A clear-cut violation of company policy
- A situation where two or more ethical principles conflict, making the right choice unclear (Correct answer)
Correct answer: A situation where two or more ethical principles conflict, making the right choice unclear
An ethical dilemma presents competing values or principles where no option is clearly right or wrong, requiring careful judgment.
Question 70: A CCO learns that a key supplier is experiencing severe financial distress. From a compliance perspective, what is the primary risk?
- Financial distress automatically voids the compliance terms of the contract
- The supplier may cut corners on compliance controls, increasing regulatory and reputational risk (Correct answer)
- The supplier may hire away your compliance staff
- The supplier may increase prices, affecting the organization's margins
Correct answer: The supplier may cut corners on compliance controls, increasing regulatory and reputational risk
Financially distressed vendors often reduce compliance spending as a cost-cutting measure, which can lead to regulatory violations, data breaches, or other compliance failures that expose the contracting organization.
Question 71: What is a conflict of interest in a corporate ethics context?
- A situation where personal interests could improperly influence professional decisions (Correct answer)
- Differences in audit findings
- Disagreement between two departments
- Competing regulatory requirements
Correct answer: A situation where personal interests could improperly influence professional decisions
A conflict of interest arises when an individual's personal interests could interfere with their duty to act in the organization's best interest.
Question 72: How can a Chief Compliance Officer mitigate compliance risks?
- By focusing solely on financial audits
- By ignoring minor regulatory changes
- By implementing comprehensive compliance programs and regular training for employees (Correct answer)
- By reducing the compliance team size
Correct answer: By implementing comprehensive compliance programs and regular training for employees
Mitigating compliance risks involves implementing comprehensive compliance programs and providing regular training for employees.
Question 73: An employee reports a potential ethics violation through the company hotline but fears retaliation. What should the CCO ensure is in place?
- Strong whistleblower protections and non-retaliation policies (Correct answer)
- A reward system tied to job performance
- A policy to identify the reporter immediately
- Mandatory disclosure of all reporters to management
Correct answer: Strong whistleblower protections and non-retaliation policies
Effective ethics programs must include robust non-retaliation policies to encourage employees to report misconduct without fear.
Question 74: What is a 'red flag' in AML monitoring?
- A mandatory stop on all transactions
- A customer complaint requiring immediate resolution
- A declined payment notification
- An indicator of potentially suspicious activity that warrants further review (Correct answer)
Correct answer: An indicator of potentially suspicious activity that warrants further review
Red flags are warning signs — such as unusual transaction patterns, inconsistent customer behavior, or involvement with high-risk jurisdictions — that trigger further AML review.
Question 75: What is a Politically Exposed Person (PEP)?
- An individual who holds or has held a prominent public function, making them higher risk for bribery and corruption (Correct answer)
- Any foreign national doing business in the US
- A customer who donates to political campaigns
- A customer who trades in commodities
Correct answer: An individual who holds or has held a prominent public function, making them higher risk for bribery and corruption
PEPs are individuals such as heads of state, senior officials, or their close associates who carry elevated corruption risk due to their public positions.
Question 76: Which of the following is an example of a financial risk?
- Regulatory fines
- Natural disasters
- Data breaches
- Market fluctuations affecting investments (Correct answer)
Correct answer: Market fluctuations affecting investments
Financial risk includes market fluctuations that can affect an organization's investments.
Question 77: What is a Data Protection Impact Assessment (DPIA)?
- An annual IT security audit
- A financial assessment of data storage costs
- A structured process to identify and minimize data protection risks in high-risk processing activities (Correct answer)
- A customer survey on data handling preferences
Correct answer: A structured process to identify and minimize data protection risks in high-risk processing activities
DPIAs are required under GDPR for processing activities that pose high risks to individuals' rights, helping organizations identify and mitigate those risks before implementation.
Question 78: What is the purpose of a 'right to audit' clause in a vendor contract?
- To give the organization the contractual right to review and inspect the vendor's compliance-related records and processes (Correct answer)
- To satisfy accounting standards for revenue recognition
- To allow the vendor to audit the organization's financial records
- To permit the vendor to audit competitors on the organization's behalf
Correct answer: To give the organization the contractual right to review and inspect the vendor's compliance-related records and processes
A right-to-audit clause preserves the organization's ability to independently verify that the vendor is complying with contractual, regulatory, and ethical obligations throughout the relationship.
Question 79: What is the role of incentives in a compliance program?
- Only financial penalties, not rewards, drive compliance behavior
- Incentives are irrelevant to compliance outcomes
- Rewarding compliance-positive behaviors reinforces the compliance culture and encourages employees to prioritize integrity over short-term gains (Correct answer)
- Incentives should only be used for sales performance
Correct answer: Rewarding compliance-positive behaviors reinforces the compliance culture and encourages employees to prioritize integrity over short-term gains
Positive incentives — such as recognition, performance evaluations tied to ethical behavior, and advancement criteria — signal that compliance matters and reinforce desired behaviors.
Question 80: What is the purpose of a walkthrough in an internal audit?
- An introductory tour for new compliance staff
- A regulatory examination process
- A procedure where the auditor follows a transaction from initiation to completion to verify that controls exist and operate as described (Correct answer)
- A physical inspection of company facilities
Correct answer: A procedure where the auditor follows a transaction from initiation to completion to verify that controls exist and operate as described
Walkthroughs trace individual transactions through the entire process to confirm that documented controls are actually in place and functioning in practice.
Question 81: What role does the CCO typically play in M&A due diligence?
- Assessing the target's compliance risks, pending investigations, and program maturity to inform deal terms and integration planning (Correct answer)
- Conducting financial statement audits
- Approving the deal valuation
- Managing investor communications
Correct answer: Assessing the target's compliance risks, pending investigations, and program maturity to inform deal terms and integration planning
CCO involvement in M&A due diligence identifies compliance liabilities, regulatory exposure, and cultural risks that could affect deal value or post-merger liability.
Question 82: What is the importance of audit independence?
- Independence means auditors have no contact with business units
- Auditors should work closely with the business to understand operations
- Only external auditors require independence
- Independence ensures auditors can objectively assess controls and report findings without being influenced by the areas they audit (Correct answer)
Correct answer: Independence ensures auditors can objectively assess controls and report findings without being influenced by the areas they audit
Audit independence is fundamental to objectivity — auditors who report to or are influenced by the functions they audit cannot provide unbiased assurance.
Question 83: What is the purpose of a compliance hotline benchmarking study?
- To comply with a mandatory regulatory reporting requirement
- To compare the organization's hotline usage, substantiation rates, and report categories to industry peers to assess program health (Correct answer)
- To evaluate hotline software vendors
- To compare hotline costs across industries
Correct answer: To compare the organization's hotline usage, substantiation rates, and report categories to industry peers to assess program health
Benchmarking against industry peers helps assess whether the organization's hotline volume, report types, and outcomes are consistent with well-functioning programs.
Question 84: Under the OCC's guidance on third-party risk management, which of the following is considered a 'critical activity' requiring heightened oversight?
- Outsourcing core banking processes or functions that could harm customers if disrupted (Correct answer)
- Purchasing office supplies from an approved vendor
- Using a standard cloud storage provider for non-sensitive files
- Engaging a one-time consultant for a training seminar
Correct answer: Outsourcing core banking processes or functions that could harm customers if disrupted
The OCC defines critical activities as those that could cause significant customer harm, reputational damage, or safety and soundness concerns if the third party fails to perform, requiring enhanced due diligence.
Question 85: What is segregation of duties and why is it important?
- Separating legal and compliance functions
- Dividing the compliance function across multiple departments
- Organizing employees into specialized teams
- Requiring that no single employee controls all critical steps in a financial or operational process, reducing the risk of fraud or error (Correct answer)
Correct answer: Requiring that no single employee controls all critical steps in a financial or operational process, reducing the risk of fraud or error
Segregation of duties prevents a single individual from both executing and recording transactions, reducing the risk of undetected fraud or error.
Question 86: What is 'privacy by design'?
- Designing aesthetically pleasing privacy notices
- A customer-facing transparency tool
- A method for encrypting databases
- Embedding privacy protections into the design of systems, processes, and products from the outset rather than adding them later (Correct answer)
Correct answer: Embedding privacy protections into the design of systems, processes, and products from the outset rather than adding them later
Privacy by design integrates data protection into the development of technologies, processes, and business practices before they go live, rather than retrofitting protections afterward.
Question 87: What is an example of an operational risk?
- Product innovation
- Interest rate changes
- Employee turnover
- Cybersecurity threats (Correct answer)
Correct answer: Cybersecurity threats
Operational risks include threats to the organization's operations, such as cybersecurity threats.
Question 88: What is HIPAA and what type of data does it protect?
- A privacy law specific to Medicare and Medicaid
- A cybersecurity law protecting financial data
- The Health Insurance Portability and Accountability Act, which protects protected health information (PHI) in the US (Correct answer)
- An international standard for hospital records
Correct answer: The Health Insurance Portability and Accountability Act, which protects protected health information (PHI) in the US
HIPAA establishes national standards for protecting sensitive patient health information from disclosure without the patient's consent or knowledge.
Question 89: Which of the following is a key indicator that a third-party vendor's compliance program is inadequate?
- The vendor's compliance program mirrors the organization's own program exactly
- The vendor is unable to provide documentation of its compliance policies, training records, or audit results (Correct answer)
- The vendor's compliance officer has less tenure than the organization's CCO
- The vendor has fewer compliance staff than the hiring organization
Correct answer: The vendor is unable to provide documentation of its compliance policies, training records, or audit results
An inability to produce compliance documentation is a red flag that the vendor's program exists only on paper or not at all, signaling significant risk to the contracting organization.
Question 90: What is a risk assessment?
- The process of marketing new products
- The process of hiring new employees
- The process of identifying and analyzing potential risks (Correct answer)
- The process of ignoring potential threats
Correct answer: The process of identifying and analyzing potential risks
A risk assessment involves identifying and analyzing potential risks that could affect the organization.
Question 91: Which body typically has ultimate oversight responsibility for a company's ethics program?
- The HR department
- The CFO
- The Board of Directors or Audit Committee (Correct answer)
- The legal team
Correct answer: The Board of Directors or Audit Committee
The Board of Directors or its Audit Committee holds ultimate fiduciary and oversight responsibility for the ethics and compliance program.
Question 92: A vendor notifies your organization of a data breach affecting data it processes on your behalf. Under GDPR, who bears primary accountability to the affected data subjects?
- The organization (data controller), which remains accountable to data subjects for how their data was processed (Correct answer)
- The national supervisory authority
- The cloud provider hosting the vendor's infrastructure
- The vendor, as it controls the systems where the breach occurred
Correct answer: The organization (data controller), which remains accountable to data subjects for how their data was processed
Under GDPR, the data controller retains accountability to data subjects regardless of delegation to a processor; the organization must notify supervisory authorities and affected individuals within required timeframes.
Question 93: What is a whistleblower program and why is it critical to corporate governance?
- A social media monitoring program
- A structured mechanism allowing employees and others to report misconduct confidentially, enabling early detection of governance failures (Correct answer)
- An external regulatory reporting system
- A public relations tool for managing media inquiries
Correct answer: A structured mechanism allowing employees and others to report misconduct confidentially, enabling early detection of governance failures
Whistleblower programs create safe reporting channels that help boards and executives detect problems before they escalate into major violations or scandals.
Question 94: What is a control self-assessment (CSA)?
- A regulatory examination methodology
- A process where business units assess their own controls against defined criteria, often facilitated by internal audit or compliance (Correct answer)
- An external auditor assessment of management's controls
- An employee self-evaluation form
Correct answer: A process where business units assess their own controls against defined criteria, often facilitated by internal audit or compliance
CSAs engage business management and employees in evaluating the effectiveness of their own controls, building ownership and providing an early warning of control gaps.
Question 95: What is the Bank Secrecy Act (BSA)?
- A regulation governing international wire transfers only
- A law requiring banks to keep customer information secret
- A law preventing banks from sharing data with third parties
- The primary US anti-money laundering law requiring financial institutions to assist government agencies in detecting and preventing money laundering (Correct answer)
Correct answer: The primary US anti-money laundering law requiring financial institutions to assist government agencies in detecting and preventing money laundering
The BSA is the foundational US AML law that requires financial institutions to maintain records and file reports to help identify and prevent money laundering.
Question 96: What is an internal audit charter?
- A regulatory requirement for financial institutions
- A formal document that defines the internal audit function's purpose, authority, responsibility, and independence within the organization (Correct answer)
- A contract with an external audit firm
- A list of audit findings
Correct answer: A formal document that defines the internal audit function's purpose, authority, responsibility, and independence within the organization
The internal audit charter establishes the function's organizational authority, independence, scope, and accountability structure, typically approved by the Audit Committee.
Question 97: What is 'personal data' under GDPR?
- Only social security numbers and financial records
- Anonymized statistical data
- Business transaction records
- Any information relating to an identified or identifiable natural person (Correct answer)
Correct answer: Any information relating to an identified or identifiable natural person
Personal data under GDPR includes any information that can directly or indirectly identify a natural person, including names, email addresses, location data, and online identifiers.
Question 98: Which of the following is an example of a facilitation payment?
- A legitimate sales commission
- A contract bonus
- A small payment to a foreign official to expedite a routine government service (Correct answer)
- A charitable donation on behalf of a client
Correct answer: A small payment to a foreign official to expedite a routine government service
Facilitation payments are small bribes paid to government officials to speed up routine actions and are prohibited under the FCPA and many other anti-bribery laws.
Question 99: What is the role of ethics training in a compliance program?
- To replace the Code of Conduct
- To satisfy only senior management requirements
- To fulfill a one-time onboarding requirement
- To continuously reinforce ethical standards and decision-making skills (Correct answer)
Correct answer: To continuously reinforce ethical standards and decision-making skills
Ongoing ethics training reinforces expected behaviors, helps employees recognize ethical dilemmas, and strengthens the compliance culture.
Question 100: Under FinCEN's Customer Due Diligence rule, covered financial institutions must identify beneficial owners holding what percentage or more of a legal entity?
- 10%
- 50%
- 5%
- 25% (Correct answer)
Correct answer: 25%
FinCEN's CDD rule requires identifying all beneficial owners holding 25% or more equity in a legal entity customer.
Question 101: What is the purpose of an exit conference in an internal audit?
- A meeting to discuss the audit team's departure from the company
- To formally end the employment of audited staff
- A regulatory debrief session
- To communicate audit findings and recommendations to management before the final report, allowing management to respond and correct factual errors (Correct answer)
Correct answer: To communicate audit findings and recommendations to management before the final report, allowing management to respond and correct factual errors
Exit conferences give management the opportunity to hear, discuss, and respond to findings before the final audit report is issued, improving accuracy and buy-in.
Question 102: What is a charter for a compliance committee?
- A list of compliance policies
- A report to regulators about committee activities
- A formal document that establishes the committee's purpose, authority, composition, and responsibilities (Correct answer)
- A founding document for a new company
Correct answer: A formal document that establishes the committee's purpose, authority, composition, and responsibilities
The committee charter defines its mandate, membership, meeting frequency, reporting lines, and scope of authority, providing a governance framework for its operations.
Question 103: What is the role of a compliance officer in relation to regulatory changes?
- To consult with marketing teams about regulatory impacts
- To ensure the organization adapts and complies with new regulatory requirements (Correct answer)
- To disregard regulatory updates
- To focus only on historical regulations
Correct answer: To ensure the organization adapts and complies with new regulatory requirements
The compliance officer ensures that the organization stays updated and complies with new regulatory changes.
Question 104: What is beneficial ownership in AML compliance?
- The registered agent of a company
- The largest shareholder by share count
- The natural person(s) who ultimately own or control a legal entity, even if ownership is indirect (Correct answer)
- The legal owner of a corporation as shown in public filings
Correct answer: The natural person(s) who ultimately own or control a legal entity, even if ownership is indirect
Beneficial ownership identifies the real human beings who ultimately own or control a company, preventing criminals from hiding behind shell companies.
Question 105: What is an unqualified (clean) audit opinion?
- An opinion given without sufficient evidence
- An informal verbal audit conclusion
- An opinion issued quickly without full procedures
- An auditor's conclusion that financial statements present a fair view in all material respects, with no exceptions or qualifications (Correct answer)
Correct answer: An auditor's conclusion that financial statements present a fair view in all material respects, with no exceptions or qualifications
An unqualified opinion is the best audit outcome, indicating the financial statements are free of material misstatements and comply with applicable accounting standards.
Question 106: Which best describes the 'flow-down' requirement in third-party compliance programs?
- Requiring regulators to share audit findings with vendors
- Requiring compliance reports to flow downward from executives to staff
- Requiring vendors to pass cost savings on to the organization
- Requiring vendors to impose the same compliance standards on their subcontractors that the organization imposes on the vendors (Correct answer)
Correct answer: Requiring vendors to impose the same compliance standards on their subcontractors that the organization imposes on the vendors
Flow-down clauses extend the organization's compliance requirements through the supply chain, ensuring that fourth parties and beyond are also bound by the same ethical and regulatory standards.
Question 107: What is 'executive compensation clawback' policy?
- A provision requiring executives to return compensation if financial results are later found to be inaccurate due to misconduct or restatement (Correct answer)
- A policy allowing executives to reclaim approved bonuses
- A mechanism for reducing pay during poor performance periods
- A policy for deferring executive compensation to future years
Correct answer: A provision requiring executives to return compensation if financial results are later found to be inaccurate due to misconduct or restatement
Clawback provisions, required under Dodd-Frank for public companies, allow companies to recover incentive compensation paid based on misstated financials.
Question 108: What is the primary purpose of the General Data Protection Regulation (GDPR)?
- To regulate trade practices
- To manage corporate taxes
- To protect personal data and privacy of individuals within the European Union (EU) (Correct answer)
- To oversee environmental protections
Correct answer: To protect personal data and privacy of individuals within the European Union (EU)
GDPR aims to protect the personal data and privacy of individuals within the EU.
Question 109: What is the maximum fine for a serious GDPR violation?
- $1 million
- There is no fine for first-time violations
- €20 million or 4% of global annual turnover, whichever is higher (Correct answer)
- €1 million or 1% of turnover
Correct answer: €20 million or 4% of global annual turnover, whichever is higher
GDPR's highest tier of fines reaches €20 million or 4% of total worldwide annual revenue, whichever is greater.
Question 110: What is the Financial Action Task Force (FATF)?
- A private banking association
- A US federal law enforcement agency
- An intergovernmental body that sets international AML and counter-terrorist financing standards (Correct answer)
- A United Nations subcommittee on sanctions
Correct answer: An intergovernmental body that sets international AML and counter-terrorist financing standards
FATF is the global standard-setter for anti-money laundering and counter-terrorist financing policies, whose recommendations countries are expected to implement.
Question 111: What is the function of a compliance program gap analysis?
- To identify gaps in employee compliance knowledge
- To compare the current state of the compliance program against best practices or regulatory expectations to identify areas needing improvement (Correct answer)
- To assess technology gaps in compliance software
- To audit financial reporting gaps
Correct answer: To compare the current state of the compliance program against best practices or regulatory expectations to identify areas needing improvement
A gap analysis identifies where the current program falls short of best practices, regulatory standards, or prior commitments, producing a prioritized roadmap for improvement.
Chief Compliance Officer (CCO) Qualifying Examination
The CIRO/CSI Chief Compliance Officer Qualifying Examination tests knowledge of Canadian securities regulations, compliance program design, risk management, governance, ethics, AML obligations, and the responsibilities of a CCO under CIRO rules and NI 31-103.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds