CCO Corporate Governance and Board Relations 2 — Questions and Answers
Question 1: What information should a CCO regularly report to the Board or Audit Committee?
- Only major violations that have resulted in regulatory action
- Program effectiveness metrics, investigation outcomes, regulatory developments, and emerging risks (Correct answer)
- Employee performance reviews
- Budget variance reports only
Correct answer: Program effectiveness metrics, investigation outcomes, regulatory developments, and emerging risks
Board reporting should cover the health of the compliance program, key metrics, investigation results, regulatory landscape, and significant risk areas.
Question 2: What is the 'three lines of defense' model in governance?
- A military strategy applied to corporate security
- A governance framework where business units (1st), compliance/risk (2nd), and internal audit (3rd) each provide distinct levels of risk management (Correct answer)
- A model for layering cybersecurity controls
- A framework for three-level management hierarchies
Correct answer: A governance framework where business units (1st), compliance/risk (2nd), and internal audit (3rd) each provide distinct levels of risk management
The three lines model assigns risk management roles to operational management, risk/compliance oversight functions, and independent audit assurance, each playing distinct roles.
Question 3: What is 'say on pay' in corporate governance?
- A requirement that employees vote on their own salaries
- A shareholder advisory vote on executive compensation packages (Correct answer)
- A board rule prohibiting salary increases during poor performance periods
- A regulation setting maximum executive pay ratios
Correct answer: A shareholder advisory vote on executive compensation packages
'Say on pay' gives shareholders a non-binding advisory vote on senior executive compensation, enhancing transparency and accountability.
Question 4: What is dual-hatting in the context of compliance and legal functions?
- Wearing two hats in cold weather during site visits
- When the CCO also serves as General Counsel, potentially creating conflicts between legal privilege and compliance transparency (Correct answer)
- A practice of having two compliance officers for redundancy
- A governance model where two boards share oversight
Correct answer: When the CCO also serves as General Counsel, potentially creating conflicts between legal privilege and compliance transparency
Dual-hatting the CCO and GC roles can create tension between attorney-client privilege, which favors confidentiality, and compliance obligations, which favor transparency.
Question 5: What is a charter for a compliance committee?
- A founding document for a new company
- A formal document that establishes the committee's purpose, authority, composition, and responsibilities (Correct answer)
- A list of compliance policies
- A report to regulators about committee activities
Correct answer: A formal document that establishes the committee's purpose, authority, composition, and responsibilities
The committee charter defines its mandate, membership, meeting frequency, reporting lines, and scope of authority, providing a governance framework for its operations.
Question 6: What is 'fiduciary duty' for corporate directors?
- A financial obligation to pay dividends
- Legal obligations requiring directors to act in the best interests of the corporation and its shareholders, including duties of care and loyalty (Correct answer)
- An obligation to maximize short-term shareholder returns
- A requirement to personally fund corporate losses
Correct answer: Legal obligations requiring directors to act in the best interests of the corporation and its shareholders, including duties of care and loyalty
Directors owe the corporation duties of care (informed, deliberate decisions) and loyalty (putting corporate interests above personal interests).
What information should a CCO regularly report to the Board or Audit Committee?