Chief Compliance Officer (CCO) Qualifying Examination — Questions and Answers
Question 1: What is the role of an AML compliance officer?
- To oversee the AML program, ensure regulatory compliance, conduct training, and act as liaison with regulators and law enforcement (Correct answer)
- To approve all customer transactions personally
- To manage the bank's investment portfolio
- To serve as a customer relationship manager
Correct answer: To oversee the AML program, ensure regulatory compliance, conduct training, and act as liaison with regulators and law enforcement
The AML compliance officer is responsible for designing, implementing, and overseeing the institution's AML program and regulatory obligations.
Question 2: What is a conflict of interest in a corporate ethics context?
- Disagreement between two departments
- Differences in audit findings
- Competing regulatory requirements
- A situation where personal interests could improperly influence professional decisions (Correct answer)
Correct answer: A situation where personal interests could improperly influence professional decisions
A conflict of interest arises when an individual's personal interests could interfere with their duty to act in the organization's best interest.
Question 3: What is the most effective way to ensure that a third-party compliance program remains current as vendor relationships and regulations evolve?
- Conduct a one-time comprehensive vendor review at program inception
- Rely exclusively on vendor self-attestations submitted at contract signing
- Implement periodic re-assessments, continuous monitoring, and annual program reviews tied to regulatory changes and vendor risk changes (Correct answer)
- Assign compliance responsibilities entirely to the procurement team
Correct answer: Implement periodic re-assessments, continuous monitoring, and annual program reviews tied to regulatory changes and vendor risk changes
Third-party compliance programs must be living documents that incorporate continuous monitoring, periodic re-assessments, and updates triggered by regulatory changes or material changes in vendor risk profiles.
Question 4: What is an audit risk model?
- A risk rating system for regulatory violations
- A model for assessing auditor independence
- A framework combining inherent risk, control risk, and detection risk to determine the audit procedures needed to achieve acceptable assurance levels (Correct answer)
- A financial model estimating audit costs
Correct answer: A framework combining inherent risk, control risk, and detection risk to determine the audit procedures needed to achieve acceptable assurance levels
The audit risk model helps auditors calibrate the nature, timing, and extent of procedures based on the combination of inherent, control, and detection risks in each area.
Question 5: What is the COSO Internal Control Framework?
- A widely used framework defining internal control components: control environment, risk assessment, control activities, information/communication, and monitoring (Correct answer)
- A financial reporting standard issued by the SEC
- A mandatory auditing standard for public companies
- A risk management framework specific to banking
Correct answer: A widely used framework defining internal control components: control environment, risk assessment, control activities, information/communication, and monitoring
The COSO framework provides the structure used by most organizations to design and evaluate internal controls across five integrated components.
Question 6: What is beneficial ownership in AML compliance?
- The largest shareholder by share count
- The natural person(s) who ultimately own or control a legal entity, even if ownership is indirect (Correct answer)
- The legal owner of a corporation as shown in public filings
- The registered agent of a company
Correct answer: The natural person(s) who ultimately own or control a legal entity, even if ownership is indirect
Beneficial ownership identifies the real human beings who ultimately own or control a company, preventing criminals from hiding behind shell companies.
Question 7: What is the 'reasonable person standard' in compliance?
- A standard measuring average employee performance
- A legal definition of negligence in criminal law
- A benchmark asking whether a reasonable, objective person would conclude that actions taken were appropriate given the circumstances (Correct answer)
- A threshold for triggering a compliance investigation
Correct answer: A benchmark asking whether a reasonable, objective person would conclude that actions taken were appropriate given the circumstances
The reasonable person standard evaluates whether conduct meets the expected norm of a thoughtful, objective person in similar circumstances, used in both legal and compliance contexts.
Question 8: What is the purpose of a risk register?
- To document and track identified risks, their impact, and mitigation strategies (Correct answer)
- To manage employee benefits
- To create marketing strategies
- To hire risk management personnel
Correct answer: To document and track identified risks, their impact, and mitigation strategies
A risk register is used to document and track identified risks, their impact, and the strategies for mitigating them.
Question 9: What is the purpose of an exit conference in an internal audit?
- To formally end the employment of audited staff
- A meeting to discuss the audit team's departure from the company
- To communicate audit findings and recommendations to management before the final report, allowing management to respond and correct factual errors (Correct answer)
- A regulatory debrief session
Correct answer: To communicate audit findings and recommendations to management before the final report, allowing management to respond and correct factual errors
Exit conferences give management the opportunity to hear, discuss, and respond to findings before the final audit report is issued, improving accuracy and buy-in.
Question 10: What is a risk assessment?
- The process of marketing new products
- The process of hiring new employees
- The process of identifying and analyzing potential risks (Correct answer)
- The process of ignoring potential threats
Correct answer: The process of identifying and analyzing potential risks
A risk assessment involves identifying and analyzing potential risks that could affect the organization.
Question 11: Which of the following is a key element of an effective compliance program?
- Providing ongoing training and education to employees (Correct answer)
- Hiring only external consultants
- Minimizing communication about compliance policies
- Reducing the number of internal audits
Correct answer: Providing ongoing training and education to employees
Ongoing training and education for employees are essential for an effective compliance program.
Question 12: What is the role of a whistleblower in the context of regulatory compliance?
- To create new regulations
- To report misconduct or violations within the organization (Correct answer)
- To implement marketing campaigns
- To oversee financial reporting
Correct answer: To report misconduct or violations within the organization
A whistleblower reports misconduct or regulatory violations within the organization.
Question 13: What is the primary purpose of a corporate Code of Conduct?
- To outline employee benefits
- To define acceptable and unacceptable behaviors within the organization (Correct answer)
- To serve as a marketing document
- To list all company policies verbatim
Correct answer: To define acceptable and unacceptable behaviors within the organization
A Code of Conduct defines the ethical standards and behavioral expectations for all employees and leaders.
Question 14: Which type of risk is associated with regulatory changes and compliance requirements?
- Compliance risk (Correct answer)
- Operational risk
- Market risk
- Credit risk
Correct answer: Compliance risk
Compliance risk is associated with regulatory changes and the need to adhere to compliance requirements.
Question 15: What is the role of ethics training in a compliance program?
- To satisfy only senior management requirements
- To continuously reinforce ethical standards and decision-making skills (Correct answer)
- To replace the Code of Conduct
- To fulfill a one-time onboarding requirement
Correct answer: To continuously reinforce ethical standards and decision-making skills
Ongoing ethics training reinforces expected behaviors, helps employees recognize ethical dilemmas, and strengthens the compliance culture.
Question 16: What is an unqualified (clean) audit opinion?
- An opinion issued quickly without full procedures
- An auditor's conclusion that financial statements present a fair view in all material respects, with no exceptions or qualifications (Correct answer)
- An opinion given without sufficient evidence
- An informal verbal audit conclusion
Correct answer: An auditor's conclusion that financial statements present a fair view in all material respects, with no exceptions or qualifications
An unqualified opinion is the best audit outcome, indicating the financial statements are free of material misstatements and comply with applicable accounting standards.
Question 17: A vendor notifies your organization of a data breach affecting data it processes on your behalf. Under GDPR, who bears primary accountability to the affected data subjects?
- The vendor, as it controls the systems where the breach occurred
- The national supervisory authority
- The organization (data controller), which remains accountable to data subjects for how their data was processed (Correct answer)
- The cloud provider hosting the vendor's infrastructure
Correct answer: The organization (data controller), which remains accountable to data subjects for how their data was processed
Under GDPR, the data controller retains accountability to data subjects regardless of delegation to a processor; the organization must notify supervisory authorities and affected individuals within required timeframes.
Question 18: What is a whistleblower program and why is it critical to corporate governance?
- An external regulatory reporting system
- A structured mechanism allowing employees and others to report misconduct confidentially, enabling early detection of governance failures (Correct answer)
- A social media monitoring program
- A public relations tool for managing media inquiries
Correct answer: A structured mechanism allowing employees and others to report misconduct confidentially, enabling early detection of governance failures
Whistleblower programs create safe reporting channels that help boards and executives detect problems before they escalate into major violations or scandals.
Question 19: What is Customer Due Diligence (CDD) in AML compliance?
- Annual account rebalancing
- The process of identifying and verifying customer identity and assessing the nature of their business relationship to detect suspicious activity (Correct answer)
- A process for resolving customer complaints
- A credit review process
Correct answer: The process of identifying and verifying customer identity and assessing the nature of their business relationship to detect suspicious activity
CDD requires firms to collect and verify customer identity information and understand the expected nature of their transactions to detect anomalies.
Question 20: What is the purpose of a compliance hotline benchmarking study?
- To comply with a mandatory regulatory reporting requirement
- To evaluate hotline software vendors
- To compare hotline costs across industries
- To compare the organization's hotline usage, substantiation rates, and report categories to industry peers to assess program health (Correct answer)
Correct answer: To compare the organization's hotline usage, substantiation rates, and report categories to industry peers to assess program health
Benchmarking against industry peers helps assess whether the organization's hotline volume, report types, and outcomes are consistent with well-functioning programs.
Question 21: When offboarding a vendor who handled sensitive personal data, what is the compliance officer's primary obligation?
- Transfer the vendor's employees to the organization's payroll
- Verify that the vendor has returned or securely destroyed all personal data per contractual and regulatory requirements (Correct answer)
- Ensure the vendor provides a positive reference for future business
- Notify the vendor's competitors that they may now solicit the business
Correct answer: Verify that the vendor has returned or securely destroyed all personal data per contractual and regulatory requirements
Data destruction or return upon offboarding is a critical regulatory and contractual requirement under frameworks like GDPR and CCPA to prevent unauthorized retention or use of personal data by former vendors.
Question 22: In third-party compliance management, what is the significance of 'residual risk'?
- It is the risk posed by vendors who have left the supply chain
- It is the risk that remains after all mitigating controls and contractual protections have been applied (Correct answer)
- It is the initial risk level before any controls are applied
- It is the financial liability left unpaid after insurance coverage
Correct answer: It is the risk that remains after all mitigating controls and contractual protections have been applied
Residual risk is what the organization accepts after controls are in place; if residual risk exceeds the organization's risk appetite, additional controls or relationship termination may be required.
Question 23: What is a 'key control' in an internal control system?
- The most expensive control in a control framework
- Any control approved by the CFO
- A password or access credential
- A control that, if absent or ineffective, would result in a material misstatement or significant compliance violation going undetected (Correct answer)
Correct answer: A control that, if absent or ineffective, would result in a material misstatement or significant compliance violation going undetected
Key controls are the most critical controls that directly prevent or detect the most significant risks — their failure has material consequences.
Question 24: How can a Chief Compliance Officer mitigate compliance risks?
- By ignoring minor regulatory changes
- By reducing the compliance team size
- By focusing solely on financial audits
- By implementing comprehensive compliance programs and regular training for employees (Correct answer)
Correct answer: By implementing comprehensive compliance programs and regular training for employees
Mitigating compliance risks involves implementing comprehensive compliance programs and providing regular training for employees.
Question 25: Which phase of the third-party lifecycle is most critical for identifying compliance risks before a vendor relationship begins?
- Offboarding and termination
- Due diligence and onboarding (Correct answer)
- Ongoing monitoring
- Contract negotiation
Correct answer: Due diligence and onboarding
Due diligence during onboarding is the most critical phase because it identifies compliance, legal, and reputational risks before the organization is exposed through the relationship.
Question 26: What is a management response to an audit finding?
- A rebuttal challenging the auditor's conclusions
- A regulatory notification of audit results
- A press release about audit outcomes
- A formal response from management agreeing with or disputing the finding and committing to specific corrective actions with timelines (Correct answer)
Correct answer: A formal response from management agreeing with or disputing the finding and committing to specific corrective actions with timelines
Management responses commit the business to remediation actions, owners, and deadlines for each audit finding, creating accountability for resolving control deficiencies.
Question 27: What is the significance of annual ethics certifications signed by employees?
- They replace the need for ethics training
- They are only required for executives
- They are primarily a legal technicality
- They confirm employee awareness and acknowledgment of ethics obligations (Correct answer)
Correct answer: They confirm employee awareness and acknowledgment of ethics obligations
Annual certifications confirm that employees have read, understood, and agreed to abide by the Code of Conduct, creating a documented record of acknowledgment.
Question 28: What is 'vendor concentration risk' in a third-party compliance program?
- The risk arising when too many critical functions depend on a single vendor, creating a single point of failure (Correct answer)
- The risk that vendor pricing is concentrated among high-cost providers
- The risk that a vendor's workforce is too concentrated in one geographic area
- The risk that one vendor supplies competing firms
Correct answer: The risk arising when too many critical functions depend on a single vendor, creating a single point of failure
Vendor concentration risk occurs when an organization relies too heavily on a single third party for critical functions, so any disruption to that vendor can cripple the organization's operations and compliance posture.
Question 29: Which due diligence tool is most effective for screening third-party vendors against global sanctions lists and politically exposed persons (PEPs)?
- An automated screening solution integrated with OFAC, UN, and other global watchlists (Correct answer)
- Checking the vendor's LinkedIn company page
- Reviewing the vendor's annual report
- A general internet search
Correct answer: An automated screening solution integrated with OFAC, UN, and other global watchlists
Automated screening tools that continuously check vendors against OFAC, EU, UN, and other sanctions and PEP lists provide the most reliable and scalable compliance coverage for anti-money laundering and sanctions obligations.
Question 30: Which metric is most useful for measuring the effectiveness of an ethics hotline?
- Reports submitted, investigation closure rate, and substantiation rate (Correct answer)
- Cost of running the hotline
- Number of callers per day
- Number of anonymous versus named reporters
Correct answer: Reports submitted, investigation closure rate, and substantiation rate
Reports submitted, closure rates, and substantiation rates together indicate whether the hotline is functioning as an effective reporting channel.
Question 31: What does 'tone in the middle' refer to in ethics programs?
- A neutral stance on controversial topics
- Mid-level pricing strategies
- The ethical behaviors modeled by middle managers that reinforce or undermine senior leadership's tone (Correct answer)
- Internal audit findings for mid-sized departments
Correct answer: The ethical behaviors modeled by middle managers that reinforce or undermine senior leadership's tone
Middle managers translate executive ethics commitments into daily team behavior, making their personal ethics conduct critical to program success.
Question 32: Which of the following best describes an 'ethical dilemma'?
- A disagreement between managers
- A situation where two or more ethical principles conflict, making the right choice unclear (Correct answer)
- A clear-cut violation of company policy
- A documented compliance failure
Correct answer: A situation where two or more ethical principles conflict, making the right choice unclear
An ethical dilemma presents competing values or principles where no option is clearly right or wrong, requiring careful judgment.
Question 33: What is the primary purpose of the General Data Protection Regulation (GDPR)?
- To regulate trade practices
- To protect personal data and privacy of individuals within the European Union (EU) (Correct answer)
- To manage corporate taxes
- To oversee environmental protections
Correct answer: To protect personal data and privacy of individuals within the European Union (EU)
GDPR aims to protect the personal data and privacy of individuals within the EU.
Question 34: Under the OCC's guidance on third-party risk management, which of the following is considered a 'critical activity' requiring heightened oversight?
- Using a standard cloud storage provider for non-sensitive files
- Engaging a one-time consultant for a training seminar
- Outsourcing core banking processes or functions that could harm customers if disrupted (Correct answer)
- Purchasing office supplies from an approved vendor
Correct answer: Outsourcing core banking processes or functions that could harm customers if disrupted
The OCC defines critical activities as those that could cause significant customer harm, reputational damage, or safety and soundness concerns if the third party fails to perform, requiring enhanced due diligence.
Question 35: What is the purpose of a 'right to audit' clause in a vendor contract?
- To allow the vendor to audit the organization's financial records
- To satisfy accounting standards for revenue recognition
- To permit the vendor to audit competitors on the organization's behalf
- To give the organization the contractual right to review and inspect the vendor's compliance-related records and processes (Correct answer)
Correct answer: To give the organization the contractual right to review and inspect the vendor's compliance-related records and processes
A right-to-audit clause preserves the organization's ability to independently verify that the vendor is complying with contractual, regulatory, and ethical obligations throughout the relationship.
Question 36: What is an independent director in corporate governance?
- A director who works full-time at the company
- A director appointed by the government
- A board member who has no material relationship with the company that could influence their judgment (Correct answer)
- A non-voting advisory board member
Correct answer: A board member who has no material relationship with the company that could influence their judgment
Independent directors have no significant financial, familial, or other relationship with the company that could compromise their objectivity in board decisions.
Question 37: What is 'say on pay' in corporate governance?
- A shareholder advisory vote on executive compensation packages (Correct answer)
- A board rule prohibiting salary increases during poor performance periods
- A regulation setting maximum executive pay ratios
- A requirement that employees vote on their own salaries
Correct answer: A shareholder advisory vote on executive compensation packages
'Say on pay' gives shareholders a non-binding advisory vote on senior executive compensation, enhancing transparency and accountability.
Question 38: What does OFAC stand for and what is its role?
- Office of Federal Audit Control; oversees bank examinations
- Office of Financial Accounting and Compliance; sets GAAP standards
- Office of Foreign Acquisitions and Commerce; reviews mergers
- Office of Foreign Assets Control; administers US economic and trade sanctions (Correct answer)
Correct answer: Office of Foreign Assets Control; administers US economic and trade sanctions
OFAC is the US Treasury bureau that administers and enforces economic and trade sanctions against targeted foreign countries, entities, and individuals.
Question 39: What is the principle of data minimization under GDPR?
- Limiting data to a single database
- Reducing the number of employees with data access
- Storing data in the smallest possible file format
- Collecting only the personal data that is necessary for the specified purpose (Correct answer)
Correct answer: Collecting only the personal data that is necessary for the specified purpose
Data minimization requires that organizations collect and process only the personal data that is adequate, relevant, and limited to what is necessary for the stated purpose.
Question 40: What does 'pseudonymization' mean in data privacy?
- Sharing data in aggregate form only
- Encrypting all data at rest
- Replacing directly identifying information with artificial identifiers so data cannot be attributed to a specific person without additional information (Correct answer)
- Permanently deleting personal data
Correct answer: Replacing directly identifying information with artificial identifiers so data cannot be attributed to a specific person without additional information
Pseudonymization replaces identifying fields with artificial identifiers, reducing re-identification risk while still allowing data utility, though it differs from full anonymization.
Question 41: What is the three-way match in procurement controls?
- Matching three bids for every purchase
- Comparing the purchase order, receiving report, and vendor invoice to verify all three agree before payment is approved (Correct answer)
- Matching three regulatory requirements to a single policy
- A three-signature approval requirement
Correct answer: Comparing the purchase order, receiving report, and vendor invoice to verify all three agree before payment is approved
Three-way matching is a preventive control that ensures payment is only made when the ordered, received, and invoiced quantities and amounts all agree.
Question 42: What is a control deficiency and how does it differ from a material weakness?
- Material weaknesses apply only to cybersecurity controls
- They are identical terms used interchangeably
- A control deficiency is discovered by external auditors; a material weakness is found internally
- A control deficiency is any shortfall; a material weakness is one that creates a reasonable possibility of a material misstatement going undetected (Correct answer)
Correct answer: A control deficiency is any shortfall; a material weakness is one that creates a reasonable possibility of a material misstatement going undetected
Control deficiencies exist on a spectrum — a material weakness is the most severe, representing a significant risk that financial statements could be materially misstated.
Question 43: What is a Politically Exposed Person (PEP)?
- Any foreign national doing business in the US
- A customer who donates to political campaigns
- An individual who holds or has held a prominent public function, making them higher risk for bribery and corruption (Correct answer)
- A customer who trades in commodities
Correct answer: An individual who holds or has held a prominent public function, making them higher risk for bribery and corruption
PEPs are individuals such as heads of state, senior officials, or their close associates who carry elevated corruption risk due to their public positions.
Question 44: Which body typically has ultimate oversight responsibility for a company's ethics program?
- The HR department
- The legal team
- The Board of Directors or Audit Committee (Correct answer)
- The CFO
Correct answer: The Board of Directors or Audit Committee
The Board of Directors or its Audit Committee holds ultimate fiduciary and oversight responsibility for the ethics and compliance program.
Question 45: What is 'ethical fading'?
- The psychological process by which ethical considerations recede from awareness during decision-making (Correct answer)
- The gradual obsolescence of a Code of Conduct
- A reduction in ethics training frequency
- A decrease in employee engagement
Correct answer: The psychological process by which ethical considerations recede from awareness during decision-making
Ethical fading occurs when the moral dimensions of a decision become less salient due to pressures, habits, or rationalizations.
Question 46: What is the 'business judgment rule' in corporate governance?
- A legal presumption that directors acted on an informed basis, in good faith, and in the honest belief that decisions were in the company's best interest (Correct answer)
- A requirement to maximize short-term profits
- A rule that limits board decisions to pre-approved categories
- A rule requiring board members to have business experience
Correct answer: A legal presumption that directors acted on an informed basis, in good faith, and in the honest belief that decisions were in the company's best interest
The business judgment rule protects directors from liability for decisions made in good faith after reasonable deliberation, even if those decisions turn out poorly.
Question 47: What is Enhanced Due Diligence (EDD) and when is it required?
- Additional scrutiny applied to high-risk customers, such as politically exposed persons or customers from high-risk jurisdictions (Correct answer)
- Standard due diligence for all customers
- A one-time review at account opening
- A simplified process for low-risk customers
Correct answer: Additional scrutiny applied to high-risk customers, such as politically exposed persons or customers from high-risk jurisdictions
EDD requires more rigorous verification and ongoing monitoring for customers who pose elevated AML risks, including PEPs and those from high-risk countries.
Question 48: What are the seven elements of an effective compliance program according to the Federal Sentencing Guidelines?
- Mission statement, budget, staffing, policies, audits, metrics, and reports
- Leadership, culture, systems, controls, reporting, discipline, and improvement
- Policy, training, testing, reporting, investigation, remediation, and communication
- Standards and procedures, oversight, training, monitoring, reporting, enforcement, and response/prevention (Correct answer)
Correct answer: Standards and procedures, oversight, training, monitoring, reporting, enforcement, and response/prevention
The USSG seven elements are: standards/procedures, high-level oversight, due care in delegation, training/communication, monitoring/auditing, enforcement/discipline, and response/prevention.
Question 49: Which regulation requires financial institutions to develop and implement a written information security plan?
- Health Insurance Portability and Accountability Act (HIPAA)
- Fair Labor Standards Act (FLSA)
- Sarbanes-Oxley Act
- Gramm-Leach-Bliley Act (GLBA) (Correct answer)
Correct answer: Gramm-Leach-Bliley Act (GLBA)
GLBA requires financial institutions to develop and implement a written information security plan.
Question 50: Which action demonstrates a commitment to a culture of compliance within an organization?
- Punishing employees for reporting issues
- Focusing solely on profit maximization
- Discouraging employee involvement in compliance matters
- Providing transparent communication and support for compliance initiatives (Correct answer)
Correct answer: Providing transparent communication and support for compliance initiatives
A commitment to a culture of compliance includes transparent communication and support for compliance initiatives, encouraging employees to uphold and participate in compliance efforts.
Question 51: A CCO discovers that a third-party vendor has been convicted of bribery in a foreign jurisdiction. Under the Foreign Corrupt Practices Act (FCPA), what is the primary concern for the organization?
- The organization must report the vendor to the SEC within 30 days
- Only the vendor's executives face FCPA liability
- The organization may be held liable for the vendor's corrupt acts performed on its behalf (Correct answer)
- The vendor's contract must be renegotiated immediately
Correct answer: The organization may be held liable for the vendor's corrupt acts performed on its behalf
The FCPA extends liability to companies for corrupt acts committed by third parties acting on their behalf, making thorough vendor vetting essential.
Question 52: What is a control self-assessment (CSA)?
- A process where business units assess their own controls against defined criteria, often facilitated by internal audit or compliance (Correct answer)
- An employee self-evaluation form
- An external auditor assessment of management's controls
- A regulatory examination methodology
Correct answer: A process where business units assess their own controls against defined criteria, often facilitated by internal audit or compliance
CSAs engage business management and employees in evaluating the effectiveness of their own controls, building ownership and providing an early warning of control gaps.
Question 53: What is 'de-risking' and what concern does it raise for regulators?
- Eliminating high-risk investments from portfolios
- Lowering interest rates to reduce defaults
- Reducing credit risk in loan portfolios
- Financial institutions exiting entire customer segments to avoid AML compliance burden, raising financial inclusion concerns (Correct answer)
Correct answer: Financial institutions exiting entire customer segments to avoid AML compliance burden, raising financial inclusion concerns
De-risking occurs when banks terminate services for entire categories of customers, which raises financial inclusion concerns and can push activity to less-regulated channels.
Question 54: Under FinCEN's Customer Due Diligence rule, covered financial institutions must identify beneficial owners holding what percentage or more of a legal entity?
- 50%
- 25% (Correct answer)
- 5%
- 10%
Correct answer: 25%
FinCEN's CDD rule requires identifying all beneficial owners holding 25% or more equity in a legal entity customer.
Question 55: What does 'inherent risk' mean in the context of third-party vendor risk assessment?
- The risk that remains after all controls are applied
- The level of risk present before any mitigating controls are considered (Correct answer)
- The risk transferred to the vendor through contract terms
- The financial risk of vendor non-performance
Correct answer: The level of risk present before any mitigating controls are considered
Inherent risk is the gross or unmitigated risk that a vendor relationship poses before any controls, contractual protections, or monitoring activities are applied.
Question 56: What is the purpose of a third-party code of conduct?
- To comply with SEC reporting requirements
- To extend the company's ethical standards to vendors, suppliers, and partners (Correct answer)
- To replace vendor contracts
- To serve as a marketing tool for suppliers
Correct answer: To extend the company's ethical standards to vendors, suppliers, and partners
A third-party code of conduct sets ethical expectations for business partners, reducing the risk of reputational or legal harm from partner misconduct.
Question 57: What is 'personal data' under GDPR?
- Any information relating to an identified or identifiable natural person (Correct answer)
- Anonymized statistical data
- Business transaction records
- Only social security numbers and financial records
Correct answer: Any information relating to an identified or identifiable natural person
Personal data under GDPR includes any information that can directly or indirectly identify a natural person, including names, email addresses, location data, and online identifiers.
Question 58: What role does the CCO typically play in M&A due diligence?
- Conducting financial statement audits
- Managing investor communications
- Approving the deal valuation
- Assessing the target's compliance risks, pending investigations, and program maturity to inform deal terms and integration planning (Correct answer)
Correct answer: Assessing the target's compliance risks, pending investigations, and program maturity to inform deal terms and integration planning
CCO involvement in M&A due diligence identifies compliance liabilities, regulatory exposure, and cultural risks that could affect deal value or post-merger liability.
Question 59: What is the importance of audit independence?
- Independence means auditors have no contact with business units
- Independence ensures auditors can objectively assess controls and report findings without being influenced by the areas they audit (Correct answer)
- Only external auditors require independence
- Auditors should work closely with the business to understand operations
Correct answer: Independence ensures auditors can objectively assess controls and report findings without being influenced by the areas they audit
Audit independence is fundamental to objectivity — auditors who report to or are influenced by the functions they audit cannot provide unbiased assurance.
Question 60: What is dual-hatting in the context of compliance and legal functions?
- When the CCO also serves as General Counsel, potentially creating conflicts between legal privilege and compliance transparency (Correct answer)
- A governance model where two boards share oversight
- A practice of having two compliance officers for redundancy
- Wearing two hats in cold weather during site visits
Correct answer: When the CCO also serves as General Counsel, potentially creating conflicts between legal privilege and compliance transparency
Dual-hatting the CCO and GC roles can create tension between attorney-client privilege, which favors confidentiality, and compliance obligations, which favor transparency.
Question 61: What is a Data Protection Impact Assessment (DPIA)?
- A customer survey on data handling preferences
- A financial assessment of data storage costs
- A structured process to identify and minimize data protection risks in high-risk processing activities (Correct answer)
- An annual IT security audit
Correct answer: A structured process to identify and minimize data protection risks in high-risk processing activities
DPIAs are required under GDPR for processing activities that pose high risks to individuals' rights, helping organizations identify and mitigate those risks before implementation.
Question 62: What is segregation of duties and why is it important?
- Organizing employees into specialized teams
- Dividing the compliance function across multiple departments
- Requiring that no single employee controls all critical steps in a financial or operational process, reducing the risk of fraud or error (Correct answer)
- Separating legal and compliance functions
Correct answer: Requiring that no single employee controls all critical steps in a financial or operational process, reducing the risk of fraud or error
Segregation of duties prevents a single individual from both executing and recording transactions, reducing the risk of undetected fraud or error.
Question 63: What is the GDPR requirement for reporting a personal data breach to supervisory authorities?
- Within 7 days of discovery
- Within 72 hours of becoming aware of the breach, unless it is unlikely to result in risk to individuals (Correct answer)
- Within 30 days of discovery
- Only if more than 1,000 individuals are affected
Correct answer: Within 72 hours of becoming aware of the breach, unless it is unlikely to result in risk to individuals
GDPR requires notifying the relevant supervisory authority within 72 hours of discovering a personal data breach, unless the breach is low-risk.
Question 64: What is a compliance management system (CMS)?
- A software tool for scheduling compliance meetings
- An integrated set of policies, procedures, controls, and systems that manage the organization's compliance obligations holistically (Correct answer)
- A communication system for the compliance department
- A database of regulatory fines
Correct answer: An integrated set of policies, procedures, controls, and systems that manage the organization's compliance obligations holistically
A CMS provides the organizational infrastructure — policies, controls, training, monitoring, and reporting — needed to systematically manage compliance across the enterprise.
Question 65: How should an organization prioritize risks in a risk management plan?
- By outsourcing all risk management responsibilities
- By considering both the likelihood and impact of each risk (Correct answer)
- By focusing only on risks with the highest financial impact
- By addressing risks as they occur
Correct answer: By considering both the likelihood and impact of each risk
Prioritizing risks involves assessing both their likelihood and potential impact on the organization.
Question 66: Which of the following best defines 'ethical leadership'?
- Following only mandatory legal requirements
- Making decisions that maximize short-term profit
- Avoiding all risk-taking
- Leading by example through transparent, fair, and principled behavior that others can emulate (Correct answer)
Correct answer: Leading by example through transparent, fair, and principled behavior that others can emulate
Ethical leadership means modeling integrity and fairness in ways that inspire and set standards for others throughout the organization.
Question 67: Which best describes the 'flow-down' requirement in third-party compliance programs?
- Requiring regulators to share audit findings with vendors
- Requiring vendors to impose the same compliance standards on their subcontractors that the organization imposes on the vendors (Correct answer)
- Requiring vendors to pass cost savings on to the organization
- Requiring compliance reports to flow downward from executives to staff
Correct answer: Requiring vendors to impose the same compliance standards on their subcontractors that the organization imposes on the vendors
Flow-down clauses extend the organization's compliance requirements through the supply chain, ensuring that fourth parties and beyond are also bound by the same ethical and regulatory standards.
Question 68: What is the purpose of compliance monitoring?
- To routinely check that controls are in place and functioning as intended, detecting issues before they become violations (Correct answer)
- To replace internal audit functions
- To manage regulatory relationships
- To conduct investigations into past misconduct
Correct answer: To routinely check that controls are in place and functioning as intended, detecting issues before they become violations
Compliance monitoring uses ongoing checks to verify that policies and controls are operating effectively and to detect deviations before they escalate.
Question 69: What is the significance of the Federal Sentencing Guidelines for compliance programs?
- They set regulatory fines for financial institutions
- They establish the criteria for an 'effective compliance program' that can reduce organizational culpability and fines if violations occur (Correct answer)
- They define SEC enforcement standards
- They determine criminal sentences only
Correct answer: They establish the criteria for an 'effective compliance program' that can reduce organizational culpability and fines if violations occur
The Federal Sentencing Guidelines' seven elements of an effective compliance program are the foundational benchmark used by prosecutors and regulators to evaluate program quality.
Question 70: What does 'reasonable assurance' mean in the context of internal controls?
- That controls meet the minimum regulatory standard
- That management is satisfied with control outcomes
- That controls provide a high but not absolute level of assurance that objectives will be met, given inherent limitations of any control system (Correct answer)
- That all errors and fraud will be detected
Correct answer: That controls provide a high but not absolute level of assurance that objectives will be met, given inherent limitations of any control system
Reasonable assurance acknowledges that no control system is perfect and that there are inherent limitations — cost/benefit tradeoffs and human fallibility mean absolute assurance is unachievable.
Question 71: What is the purpose of a walkthrough in an internal audit?
- An introductory tour for new compliance staff
- A physical inspection of company facilities
- A regulatory examination process
- A procedure where the auditor follows a transaction from initiation to completion to verify that controls exist and operate as described (Correct answer)
Correct answer: A procedure where the auditor follows a transaction from initiation to completion to verify that controls exist and operate as described
Walkthroughs trace individual transactions through the entire process to confirm that documented controls are actually in place and functioning in practice.
Question 72: What is the role of internal audit in a fraud investigation?
- To publicly report fraud findings
- To serve as primary law enforcement investigators
- To discipline employees found to have committed fraud
- To provide investigative skills, data analysis, and process knowledge to support or conduct investigations, typically under direction of legal counsel (Correct answer)
Correct answer: To provide investigative skills, data analysis, and process knowledge to support or conduct investigations, typically under direction of legal counsel
Internal audit contributes analytical capabilities to fraud investigations but typically operates under legal counsel's direction to preserve privilege and ensure investigative integrity.
Question 73: What is the significance of cross-border data transfer restrictions under GDPR?
- They apply only to financial data
- They restrict transferring personal data to countries outside the EEA that do not have adequate data protection levels (Correct answer)
- They prevent all international business communications
- They prohibit cloud storage in non-EU countries entirely
Correct answer: They restrict transferring personal data to countries outside the EEA that do not have adequate data protection levels
GDPR restricts transfers of personal data to third countries unless the destination has an adequacy decision or appropriate safeguards like Standard Contractual Clauses are in place.
Question 74: Which of the following is a key indicator that a third-party vendor's compliance program is inadequate?
- The vendor has fewer compliance staff than the hiring organization
- The vendor is unable to provide documentation of its compliance policies, training records, or audit results (Correct answer)
- The vendor's compliance officer has less tenure than the organization's CCO
- The vendor's compliance program mirrors the organization's own program exactly
Correct answer: The vendor is unable to provide documentation of its compliance policies, training records, or audit results
An inability to produce compliance documentation is a red flag that the vendor's program exists only on paper or not at all, signaling significant risk to the contracting organization.
Question 75: What is a 'finding' in an internal audit report?
- A documented gap between the desired control state and actual practice, including criteria, condition, cause, effect, and recommendation (Correct answer)
- A positive observation about strong controls
- Any observation made during the audit
- A summary of all transactions tested
Correct answer: A documented gap between the desired control state and actual practice, including criteria, condition, cause, effect, and recommendation
An audit finding uses a structured format (criteria, condition, cause, effect, recommendation) to clearly document a control gap and its impact, enabling effective remediation.
Question 76: What is the significance of 'proportionality' in compliance program design?
- That all business units receive identical compliance programs
- That all violations should receive equal penalties
- That all employees should receive equal compliance resources
- That program resources, controls, and oversight should be scaled to the size, nature, and risk profile of the organization (Correct answer)
Correct answer: That program resources, controls, and oversight should be scaled to the size, nature, and risk profile of the organization
A well-designed program allocates resources based on risk — higher-risk areas get more controls and oversight, and program complexity matches the organization's size and risk profile.
Question 77: What is a 'red flag' in AML monitoring?
- A mandatory stop on all transactions
- A customer complaint requiring immediate resolution
- An indicator of potentially suspicious activity that warrants further review (Correct answer)
- A declined payment notification
Correct answer: An indicator of potentially suspicious activity that warrants further review
Red flags are warning signs — such as unusual transaction patterns, inconsistent customer behavior, or involvement with high-risk jurisdictions — that trigger further AML review.
Question 78: What is 'operationalizing compliance' in a large organization?
- Automating all compliance reporting to regulators
- Hiring more compliance staff
- Embedding compliance requirements into day-to-day business processes, systems, and decision-making so compliance becomes automatic rather than separate (Correct answer)
- Creating an independent compliance department
Correct answer: Embedding compliance requirements into day-to-day business processes, systems, and decision-making so compliance becomes automatic rather than separate
Operationalized compliance integrates requirements into business workflows, making it easier for employees to do the right thing without needing to consult compliance for every decision.
Question 79: When a vendor operates as a 'fourth party' (a subcontractor to your direct vendor), what is the organization's best practice?
- Ignore fourth parties since there is no direct contractual relationship
- Require direct vendors to flow down compliance obligations and monitor their subcontractors (Correct answer)
- Report all fourth parties to the relevant regulatory authority
- Conduct the same level of due diligence on fourth parties as on direct employees
Correct answer: Require direct vendors to flow down compliance obligations and monitor their subcontractors
Organizations manage fourth-party risk by requiring direct vendors to impose equivalent compliance requirements on their subcontractors and to monitor compliance accordingly.
Question 80: In the context of anti-bribery compliance, what is a 'red flag' that should heighten scrutiny of a third-party intermediary?
- The intermediary requests unusual payment structures such as cash payments or payments to a third country (Correct answer)
- The intermediary charges standard market rates for its services
- The intermediary has staff who previously worked at a competitor
- The intermediary operates in multiple countries simultaneously
Correct answer: The intermediary requests unusual payment structures such as cash payments or payments to a third country
Unusual payment requests—such as cash, payments to undisclosed parties, or payments routed through unrelated jurisdictions—are classic red flags for potential bribery or money laundering through third parties.
Question 81: A company's vendor code of conduct should primarily do which of the following?
- Replace the need for individual vendor contracts
- Guarantee vendor performance against SLAs
- Set pricing benchmarks for vendor negotiations
- Communicate the organization's compliance expectations to all vendors and require written acknowledgment (Correct answer)
Correct answer: Communicate the organization's compliance expectations to all vendors and require written acknowledgment
A vendor code of conduct formally communicates the compliance, ethical, and legal standards the organization expects from its vendors and typically requires vendors to sign an acknowledgment of these requirements.
Question 82: What is a compliance risk assessment?
- A financial audit of the compliance budget
- An external regulatory examination
- A systematic process to identify, prioritize, and address the compliance risks most relevant to the organization (Correct answer)
- A performance review of compliance staff
Correct answer: A systematic process to identify, prioritize, and address the compliance risks most relevant to the organization
A compliance risk assessment evaluates the organization's exposure to violations across risk areas, prioritizing where to focus compliance resources and controls.
Question 83: What is a compliance audit and how does it differ from monitoring?
- Monitoring is ongoing and control-focused; auditing is periodic, independent, and provides deeper assurance about the adequacy of the overall program (Correct answer)
- Monitoring is done by external parties; auditing is internal
- Auditing focuses on financial data only; monitoring covers all risk areas
- They are identical processes performed by different teams
Correct answer: Monitoring is ongoing and control-focused; auditing is periodic, independent, and provides deeper assurance about the adequacy of the overall program
Monitoring is the day-to-day checking of controls, while auditing is a periodic, independent deep-dive that evaluates whether the overall program is designed and operating effectively.
Question 84: What is the California Consumer Privacy Act (CCPA)?
- A federal US data privacy law
- A regulation governing data centers only
- A credit reporting act specific to California
- California's state privacy law granting consumers rights over their personal data collected by businesses (Correct answer)
Correct answer: California's state privacy law granting consumers rights over their personal data collected by businesses
The CCPA gives California consumers the right to know, delete, and opt out of the sale of their personal information held by qualifying businesses.
Question 85: What is the purpose of a transaction monitoring system in AML compliance?
- To generate customer account statements
- To automatically detect unusual patterns of activity that may indicate money laundering or other financial crimes (Correct answer)
- To process payments faster
- To maximize transaction fees
Correct answer: To automatically detect unusual patterns of activity that may indicate money laundering or other financial crimes
Transaction monitoring systems use rules and analytics to flag unusual activity patterns for investigation by compliance analysts.
Question 86: What is the Bank Secrecy Act (BSA)?
- The primary US anti-money laundering law requiring financial institutions to assist government agencies in detecting and preventing money laundering (Correct answer)
- A law requiring banks to keep customer information secret
- A regulation governing international wire transfers only
- A law preventing banks from sharing data with third parties
Correct answer: The primary US anti-money laundering law requiring financial institutions to assist government agencies in detecting and preventing money laundering
The BSA is the foundational US AML law that requires financial institutions to maintain records and file reports to help identify and prevent money laundering.
Question 87: What is the role of internal audits in risk management?
- To promote new products
- To manage employee payroll
- To independently assess and evaluate the effectiveness of risk management processes (Correct answer)
- To handle customer service complaints
Correct answer: To independently assess and evaluate the effectiveness of risk management processes
Internal audits play a role in independently assessing and evaluating the effectiveness of an organization's risk management processes.
Question 88: What is the 'compliance universe' in program management?
- The set of all third-party vendors used by the company
- The full inventory of laws, regulations, standards, and internal policies that apply to the organization (Correct answer)
- All employees subject to compliance training
- A database of past violations
Correct answer: The full inventory of laws, regulations, standards, and internal policies that apply to the organization
The compliance universe maps every applicable legal and regulatory requirement, forming the foundation for the risk assessment and program design.
Question 89: What is a corrective action plan (CAP) in compliance?
- A documented plan addressing identified compliance deficiencies, specifying remediation steps, owners, and timelines (Correct answer)
- A plan for upgrading compliance software
- A regulatory filing requirement
- A disciplinary procedure for employees
Correct answer: A documented plan addressing identified compliance deficiencies, specifying remediation steps, owners, and timelines
A CAP translates audit or investigation findings into concrete remediation actions with assigned ownership and deadlines, ensuring deficiencies are resolved.
Question 90: What is HIPAA and what type of data does it protect?
- A cybersecurity law protecting financial data
- The Health Insurance Portability and Accountability Act, which protects protected health information (PHI) in the US (Correct answer)
- An international standard for hospital records
- A privacy law specific to Medicare and Medicaid
Correct answer: The Health Insurance Portability and Accountability Act, which protects protected health information (PHI) in the US
HIPAA establishes national standards for protecting sensitive patient health information from disclosure without the patient's consent or knowledge.
Question 91: How often should an organization's compliance policies and procedures be reviewed?
- Every 10 years
- Annually or as needed when regulations change (Correct answer)
- When an issue arises
- Only during external audits
Correct answer: Annually or as needed when regulations change
Compliance policies and procedures should be reviewed regularly, typically annually, or when regulations change.
Question 92: What is the 'three lines of defense' model in governance?
- A governance framework where business units (1st), compliance/risk (2nd), and internal audit (3rd) each provide distinct levels of risk management (Correct answer)
- A framework for three-level management hierarchies
- A military strategy applied to corporate security
- A model for layering cybersecurity controls
Correct answer: A governance framework where business units (1st), compliance/risk (2nd), and internal audit (3rd) each provide distinct levels of risk management
The three lines model assigns risk management roles to operational management, risk/compliance oversight functions, and independent audit assurance, each playing distinct roles.
Question 93: What is a charter for a compliance committee?
- A founding document for a new company
- A list of compliance policies
- A formal document that establishes the committee's purpose, authority, composition, and responsibilities (Correct answer)
- A report to regulators about committee activities
Correct answer: A formal document that establishes the committee's purpose, authority, composition, and responsibilities
The committee charter defines its mandate, membership, meeting frequency, reporting lines, and scope of authority, providing a governance framework for its operations.
Question 94: What is a security incident response plan in the context of data privacy compliance?
- An IT disaster recovery plan for hardware failures
- A marketing communication plan for after a breach
- A plan for responding to negative media coverage
- A documented process for detecting, containing, assessing, notifying, and recovering from data security incidents (Correct answer)
Correct answer: A documented process for detecting, containing, assessing, notifying, and recovering from data security incidents
An incident response plan ensures the organization can act quickly and methodically when a data breach occurs, meeting notification timelines and minimizing harm.
Question 95: What is the purpose of a compliance program effectiveness review?
- To identify ways to reduce compliance staff
- To evaluate individual employee compliance
- To satisfy an annual budgeting exercise
- To assess whether the compliance program is adequately designed, resourced, and operating effectively to prevent and detect violations (Correct answer)
Correct answer: To assess whether the compliance program is adequately designed, resourced, and operating effectively to prevent and detect violations
Effectiveness reviews assess whether the program's design and operation actually prevent and detect misconduct, using metrics, surveys, testing, and benchmarking.
Question 96: What is the best practice when an employee faces pressure from a supervisor to falsify records?
- Discuss it only with peers
- Comply to avoid job loss
- Refuse and report the incident through the compliance hotline or to the CCO (Correct answer)
- Wait and see if the supervisor repeats the request
Correct answer: Refuse and report the incident through the compliance hotline or to the CCO
Employees must refuse to falsify records and report such pressure through established reporting channels to protect themselves and the organization.
Question 97: What is 'structuring' in the context of AML?
- Building a financial model
- Organizing a compliance department
- Deliberately breaking up transactions to avoid CTR reporting thresholds (Correct answer)
- Layering investments across asset classes
Correct answer: Deliberately breaking up transactions to avoid CTR reporting thresholds
Structuring, also called 'smurfing,' is the illegal act of breaking large cash transactions into smaller ones specifically to evade the $10,000 CTR filing requirement.
Question 98: What is a compliance training needs analysis?
- An assessment of whether employees enjoy compliance training
- A survey of training preferences
- The process of identifying which employees need what training based on their roles, risk exposure, and past training gaps (Correct answer)
- An evaluation of training vendor costs
Correct answer: The process of identifying which employees need what training based on their roles, risk exposure, and past training gaps
A training needs analysis ensures compliance training is targeted, relevant, and proportionate to the actual risks faced by each employee group.
Question 99: What does a vendor's SOC 2 Type II report assess?
- The effectiveness of the vendor's controls related to security, availability, and confidentiality over a defined operating period (Correct answer)
- The vendor's financial solvency and credit rating
- The vendor's compliance with environmental sustainability standards
- The vendor's adherence to employment discrimination laws
Correct answer: The effectiveness of the vendor's controls related to security, availability, and confidentiality over a defined operating period
A SOC 2 Type II report evaluates whether a service organization's controls related to the Trust Service Criteria (security, availability, processing integrity, confidentiality, privacy) were operating effectively over a review period.
Question 100: What is continuous auditing?
- Using automated tools to analyze transactions and controls on an ongoing basis, providing near-real-time assurance rather than periodic spot checks (Correct answer)
- A process where all employees continuously audit their own work
- Auditing the same area in consecutive years
- Performing audits every day of the week
Correct answer: Using automated tools to analyze transactions and controls on an ongoing basis, providing near-real-time assurance rather than periodic spot checks
Continuous auditing uses technology to monitor transactions and controls in near-real-time, enabling earlier detection of anomalies than traditional periodic audits.
Question 101: What is the function of a compliance program gap analysis?
- To audit financial reporting gaps
- To compare the current state of the compliance program against best practices or regulatory expectations to identify areas needing improvement (Correct answer)
- To identify gaps in employee compliance knowledge
- To assess technology gaps in compliance software
Correct answer: To compare the current state of the compliance program against best practices or regulatory expectations to identify areas needing improvement
A gap analysis identifies where the current program falls short of best practices, regulatory standards, or prior commitments, producing a prioritized roadmap for improvement.
Question 102: What information should a CCO regularly report to the Board or Audit Committee?
- Program effectiveness metrics, investigation outcomes, regulatory developments, and emerging risks (Correct answer)
- Employee performance reviews
- Only major violations that have resulted in regulatory action
- Budget variance reports only
Correct answer: Program effectiveness metrics, investigation outcomes, regulatory developments, and emerging risks
Board reporting should cover the health of the compliance program, key metrics, investigation results, regulatory landscape, and significant risk areas.
Question 103: What does a Suspicious Activity Report (SAR) require from a financial institution?
- Confidential filing with FinCEN when suspicious transactions are detected (Correct answer)
- Public disclosure to law enforcement
- Notification to the customer that they are under review
- Immediate freezing of the customer's account
Correct answer: Confidential filing with FinCEN when suspicious transactions are detected
SARs must be filed confidentially with FinCEN when transactions suggest money laundering, fraud, or other financial crimes without alerting the subject.
Question 104: Which federal agency is primarily responsible for enforcing securities laws in the United States?
- Federal Communications Commission (FCC)
- Environmental Protection Agency (EPA)
- Securities and Exchange Commission (SEC) (Correct answer)
- Federal Trade Commission (FTC)
Correct answer: Securities and Exchange Commission (SEC)
The SEC is the federal agency responsible for enforcing securities laws and regulating the securities industry.
Question 105: What does GDPR stand for and which organizations must comply with it?
- General Data Protection Regulation; applies to any organization processing personal data of EU residents (Correct answer)
- Global Data Privacy Rules; applies to US multinational companies only
- Government Data Protection Regulation; applies to public sector entities
- General Data Reporting Regulation; applies only to EU companies
Correct answer: General Data Protection Regulation; applies to any organization processing personal data of EU residents
GDPR is the EU's comprehensive data protection law that applies to any organization, regardless of location, that processes personal data of EU residents.
Question 106: What is the primary goal of risk management in an organization?
- Reducing employee turnover
- Expanding market share
- Identifying, assessing, and mitigating risks to minimize impact on the organization (Correct answer)
- Maximizing profits
Correct answer: Identifying, assessing, and mitigating risks to minimize impact on the organization
The primary goal of risk management is to identify, assess, and mitigate risks to reduce their impact on the organization.
Question 107: What is terrorist financing and how does it differ from money laundering?
- Terrorist financing only involves foreign currencies
- Terrorist financing funds violent acts and can involve legitimate money moved for criminal purposes, while money laundering conceals illegally obtained funds (Correct answer)
- Money laundering always involves larger sums than terrorist financing
- They are identical processes
Correct answer: Terrorist financing funds violent acts and can involve legitimate money moved for criminal purposes, while money laundering conceals illegally obtained funds
While money laundering cleans dirty money, terrorist financing can involve clean money being directed to fund illegal violent activities.
Question 108: An employee reports a potential ethics violation through the company hotline but fears retaliation. What should the CCO ensure is in place?
- Mandatory disclosure of all reporters to management
- Strong whistleblower protections and non-retaliation policies (Correct answer)
- A policy to identify the reporter immediately
- A reward system tied to job performance
Correct answer: Strong whistleblower protections and non-retaliation policies
Effective ethics programs must include robust non-retaliation policies to encourage employees to report misconduct without fear.
Question 109: What is the difference between preventive and detective controls?
- Detective controls are more important than preventive controls
- Preventive controls are manual; detective controls are automated
- Preventive controls apply to finances; detective controls apply to IT systems
- Preventive controls stop violations before they occur; detective controls identify violations after they have occurred (Correct answer)
Correct answer: Preventive controls stop violations before they occur; detective controls identify violations after they have occurred
Preventive controls (e.g., approval requirements) block violations before they happen, while detective controls (e.g., reconciliations) identify them after the fact.
Question 110: What is an internal audit charter?
- A contract with an external audit firm
- A formal document that defines the internal audit function's purpose, authority, responsibility, and independence within the organization (Correct answer)
- A regulatory requirement for financial institutions
- A list of audit findings
Correct answer: A formal document that defines the internal audit function's purpose, authority, responsibility, and independence within the organization
The internal audit charter establishes the function's organizational authority, independence, scope, and accountability structure, typically approved by the Audit Committee.
Question 111: What is the role of a Data Protection Officer (DPO)?
- To manage the company's IT infrastructure
- To oversee data protection strategy and ensure compliance with GDPR and related privacy laws (Correct answer)
- To serve as the company's legal counsel for all matters
- To process customer data requests only
Correct answer: To oversee data protection strategy and ensure compliance with GDPR and related privacy laws
A DPO advises on data protection obligations, monitors compliance with GDPR, and acts as the contact point for supervisory authorities and data subjects.
Chief Compliance Officer (CCO) Qualifying Examination
The CIRO/CSI Chief Compliance Officer Qualifying Examination tests knowledge of Canadian securities regulations, compliance program design, risk management, governance, ethics, AML obligations, and the responsibilities of a CCO under CIRO rules and NI 31-103.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds