Regulatory Compliance & Risk Management Flashcards
7 cards from real CCS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Regulatory Compliance & Risk Management flashcards as text
Under the Sarbanes-Oxley Act (SOX), which section requires management to assess the effectiveness of internal controls over financial reporting?
Answer: Section 404
SOX Section 404 requires management to assess and report on the effectiveness of internal controls over financial reporting, with external auditor attestation.
Which risk management framework published by COSO identifies five interrelated components including the control environment and risk assessment?
Answer: COSO ERM Framework
The COSO Internal Control – Integrated Framework identifies five components: control environment, risk assessment, control activities, information & communication, and monitoring.
A compliance officer discovers that a business unit has been underreporting customer complaints to regulators for 18 months. The FIRST action should be to:
Answer: Conduct an internal investigation to determine scope before notifying regulators
The first step is conducting an internal investigation to understand the full scope before determining the appropriate regulatory disclosure strategy.
Which principle of risk management states that risks should be transferred, avoided, mitigated, or accepted based on the organization's risk appetite?
Answer: The four T's of risk response
The four T's of risk response — Transfer, Terminate (avoid), Treat (mitigate), and Tolerate (accept) — guide how organizations respond to identified risks.
The Bank Secrecy Act (BSA) requires financial institutions to file a Currency Transaction Report (CTR) for cash transactions exceeding:
Answer: $10,000
The BSA requires financial institutions to file a CTR for any cash transaction exceeding $10,000 in a single business day.
Which type of risk assessment methodology assigns numerical values to likelihood and impact to produce a quantitative risk score?
Answer: Quantitative risk assessment
Quantitative risk assessment uses numerical values (e.g., probability percentages and dollar amounts) to calculate expected loss and prioritize risks mathematically.
Under GDPR, what is the maximum timeframe for notifying the supervisory authority of a personal data breach that poses a risk to individuals?
Answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach, where feasible.