CCS Regulatory Compliance & Risk Management 2 — Questions and Answers
Question 1: Under the Sarbanes-Oxley Act (SOX), which section requires management to assess the effectiveness of internal controls over financial reporting?
- Section 302
- Section 404 (Correct answer)
- Section 906
- Section 201
Correct answer: Section 404
SOX Section 404 requires management to assess and report on the effectiveness of internal controls over financial reporting, with external auditor attestation.
Question 2: Which risk management framework published by COSO identifies five interrelated components including the control environment and risk assessment?
- ISO 31000
- COSO ERM Framework (Correct answer)
- NIST RMF
- COBIT
Correct answer: COSO ERM Framework
The COSO Internal Control – Integrated Framework identifies five components: control environment, risk assessment, control activities, information & communication, and monitoring.
Question 3: A compliance officer discovers that a business unit has been underreporting customer complaints to regulators for 18 months. The FIRST action should be to:
- Terminate the business unit manager immediately
- Conduct an internal investigation to determine scope before notifying regulators (Correct answer)
- Immediately self-report to all relevant regulators
- Issue a press release disclosing the violation
Correct answer: Conduct an internal investigation to determine scope before notifying regulators
The first step is conducting an internal investigation to understand the full scope before determining the appropriate regulatory disclosure strategy.
Question 4: Which principle of risk management states that risks should be transferred, avoided, mitigated, or accepted based on the organization's risk appetite?
- Risk tolerance principle
- The four T's of risk response (Correct answer)
- Risk aggregation principle
- Defense in depth
Correct answer: The four T's of risk response
The four T's of risk response — Transfer, Terminate (avoid), Treat (mitigate), and Tolerate (accept) — guide how organizations respond to identified risks.
Question 5: The Bank Secrecy Act (BSA) requires financial institutions to file a Currency Transaction Report (CTR) for cash transactions exceeding:
- $5,000
- $7,500
- $10,000 (Correct answer)
- $25,000
Correct answer: $10,000
The BSA requires financial institutions to file a CTR for any cash transaction exceeding $10,000 in a single business day.
Question 6: Which type of risk assessment methodology assigns numerical values to likelihood and impact to produce a quantitative risk score?
- Qualitative risk assessment
- Quantitative risk assessment (Correct answer)
- Hybrid risk assessment
- Inherent risk analysis
Correct answer: Quantitative risk assessment
Quantitative risk assessment uses numerical values (e.g., probability percentages and dollar amounts) to calculate expected loss and prioritize risks mathematically.
Question 7: Under GDPR, what is the maximum timeframe for notifying the supervisory authority of a personal data breach that poses a risk to individuals?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach, where feasible.
Under the Sarbanes-Oxley Act (SOX), which section requires management to assess the effectiveness of internal controls over financial reporting?