CCS Regulatory Compliance & Risk Management 3 — Questions and Answers
Question 1: A company operating in multiple states must comply with differing privacy laws. This scenario best illustrates which compliance challenge?
- Regulatory arbitrage
- Jurisdictional fragmentation (Correct answer)
- Preemption conflict
- Compliance fatigue
Correct answer: Jurisdictional fragmentation
Jurisdictional fragmentation refers to the complexity of complying with multiple, sometimes conflicting, laws across different states or countries simultaneously.
Question 2: The Foreign Corrupt Practices Act (FCPA) prohibits US persons and companies from bribing foreign officials. Which defense is available under the FCPA?
- Reasonable reliance on legal counsel
- Payments that were customary in the local market
- Facilitating payments for routine governmental actions (Correct answer)
- Lack of knowledge of local laws
Correct answer: Facilitating payments for routine governmental actions
The FCPA's 'facilitating payments' exception permits small payments to foreign officials to expedite or secure performance of routine, non-discretionary government actions.
Question 3: Which control type is designed to detect compliance failures AFTER they have occurred, rather than preventing them?
- Preventive control
- Detective control (Correct answer)
- Corrective control
- Directive control
Correct answer: Detective control
Detective controls identify and report on compliance failures after they occur, such as audits, reconciliations, and monitoring reports.
Question 4: An organization's board of directors is responsible for which aspect of compliance risk management?
- Day-to-day transaction monitoring
- Setting risk appetite and oversight of the compliance program (Correct answer)
- Filing regulatory reports with government agencies
- Conducting employee compliance training sessions
Correct answer: Setting risk appetite and oversight of the compliance program
The board is responsible for setting the organization's risk appetite and providing governance oversight of the compliance program, not operational tasks.
Question 5: Under the three lines of defense model, which line is responsible for independent assurance and audit of risk management and controls?
- First line (business operations)
- Second line (risk and compliance functions)
- Third line (internal audit) (Correct answer)
- Fourth line (external regulators)
Correct answer: Third line (internal audit)
The third line of defense — internal audit — provides independent assurance by evaluating the effectiveness of governance, risk management, and internal controls.
Question 6: Which regulatory concept requires that compliance programs be reasonably designed, implemented in good faith, and enforced consistently to receive credit during enforcement actions?
- Strict liability standard
- Effective compliance program standard (Correct answer)
- Respondeat superior doctrine
- Good faith reliance defense
Correct answer: Effective compliance program standard
Regulators and the DOJ evaluate whether an organization has an 'effective compliance program' when determining penalties and prosecution decisions.
Question 7: A risk heat map is MOST useful for:
- Calculating precise financial loss estimates from each risk
- Visually prioritizing risks by plotting likelihood against impact (Correct answer)
- Documenting the chain of custody for compliance evidence
- Assigning individual accountability for each risk category
Correct answer: Visually prioritizing risks by plotting likelihood against impact
A risk heat map visualizes risks on a two-dimensional grid of likelihood vs. impact, enabling leadership to quickly prioritize which risks need immediate attention.
A company operating in multiple states must comply with differing privacy laws.
This scenario best illustrates which compliance challenge?