Regulatory Compliance & Risk Management Flashcards
7 cards from real CCS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Regulatory Compliance & Risk Management flashcards as text
A company operating in multiple states must comply with differing privacy laws. This scenario best illustrates which compliance challenge?
Answer: Jurisdictional fragmentation
Jurisdictional fragmentation refers to the complexity of complying with multiple, sometimes conflicting, laws across different states or countries simultaneously.
The Foreign Corrupt Practices Act (FCPA) prohibits US persons and companies from bribing foreign officials. Which defense is available under the FCPA?
Answer: Facilitating payments for routine governmental actions
The FCPA's 'facilitating payments' exception permits small payments to foreign officials to expedite or secure performance of routine, non-discretionary government actions.
Which control type is designed to detect compliance failures AFTER they have occurred, rather than preventing them?
Answer: Detective control
Detective controls identify and report on compliance failures after they occur, such as audits, reconciliations, and monitoring reports.
An organization's board of directors is responsible for which aspect of compliance risk management?
Answer: Setting risk appetite and oversight of the compliance program
The board is responsible for setting the organization's risk appetite and providing governance oversight of the compliance program, not operational tasks.
Under the three lines of defense model, which line is responsible for independent assurance and audit of risk management and controls?
Answer: Third line (internal audit)
The third line of defense — internal audit — provides independent assurance by evaluating the effectiveness of governance, risk management, and internal controls.
Which regulatory concept requires that compliance programs be reasonably designed, implemented in good faith, and enforced consistently to receive credit during enforcement actions?
Answer: Effective compliance program standard
Regulators and the DOJ evaluate whether an organization has an 'effective compliance program' when determining penalties and prosecution decisions.
A risk heat map is MOST useful for:
Answer: Visually prioritizing risks by plotting likelihood against impact
A risk heat map visualizes risks on a two-dimensional grid of likelihood vs. impact, enabling leadership to quickly prioritize which risks need immediate attention.