Certified Compliance Technician (CCT) Exam — Questions and Answers
Question 1: A company's compliance dashboard shows 100% policy attestation completion but regulators still find widespread violations. What is the MOST likely explanation?
- The compliance dashboard software has a technical error
- Regulators are applying incorrect standards
- Policy attestations are not a required compliance activity
- Employees completed attestations without reading or understanding the policies (Correct answer)
Correct answer: Employees completed attestations without reading or understanding the policies
High attestation rates can be misleading if employees sign off without genuinely understanding policies, a phenomenon known as 'checkbox compliance.'
Question 2: Which of the following BEST describes a document retention policy?
- A policy limiting employee file sizes
- A policy specifying how long different record types must be kept and procedures for secure disposal (Correct answer)
- A marketing content calendar
- A vendor payment schedule
Correct answer: A policy specifying how long different record types must be kept and procedures for secure disposal
A document retention policy defines retention periods by record type and establishes secure disposal methods once retention periods expire.
Question 3: What does 'incident to' billing allow under Medicare Part B?
- Combining charges from multiple dates of service onto a single claim
- Billing for preventive screenings without a supporting diagnosis code
- Billing for services rendered in a hospital emergency department under one facility fee
- Billing for services provided by non-physician practitioners under direct physician supervision at the physician's full reimbursement rate (Correct answer)
Correct answer: Billing for services provided by non-physician practitioners under direct physician supervision at the physician's full reimbursement rate
'Incident to' billing allows services by non-physician practitioners (e.g., nurses, medical assistants) provided under direct physician supervision to be billed under the supervising physician's NPI at 100% of the Medicare fee schedule.
Question 4: Under the Federal Civil Penalties Inflation Adjustment Act, how are statutory maximum civil penalties adjusted over time?
- They are adjusted every five years by a committee of agency heads
- They are automatically adjusted annually based on the Consumer Price Index (CPI) (Correct answer)
- They are adjusted only when enforcement agencies request congressional approval
- They remain fixed unless Congress explicitly passes new legislation
Correct answer: They are automatically adjusted annually based on the Consumer Price Index (CPI)
The Federal Civil Penalties Inflation Adjustment Act Improvements Act of 2015 requires agencies to make annual CPI-based adjustments to civil penalty amounts.
Question 5: What is the role of a compliance officer?
- To monitor policy violations and ensure legal compliance (Correct answer)
- To manage the cafeteria menu.
- To coordinate patient appointments.
- To develop marketing campaigns.
Correct answer: To monitor policy violations and ensure legal compliance
A compliance officer's main responsibility is to oversee and ensure that an organization adheres to all applicable laws, regulations, and internal policies. This involves monitoring for policy violations, conducting investigations, and implementing corrective actions. Their role is crucial in maintaining legal integrity and promoting an ethical organizational culture.
Question 6: According to OIG compliance guidance for hospitals, which department most commonly generates high-risk billing areas?
- Facilities management
- Marketing and communications
- Emergency departments and outpatient services (Correct answer)
- Human resources
Correct answer: Emergency departments and outpatient services
OIG hospital CPGs consistently flag emergency departments and outpatient services as high-risk because of complex coding, observation vs. inpatient decisions, and high claim volumes.
Question 7: Which agency enforces workplace anti-discrimination laws including Title VII of the Civil Rights Act for private sector employers?
- Department of Justice
- EEOC (Correct answer)
- OFCCP
- Department of Labor
Correct answer: EEOC
The EEOC investigates and enforces Title VII and other federal employment discrimination laws for private sector employers.
Question 8: A board's nominating committee fails to assess diversity when recruiting new directors. Which governance best practice is being neglected?
- Shareholder engagement policy
- Executive compensation benchmarking
- Board composition and diversity oversight (Correct answer)
- Succession planning for executives
Correct answer: Board composition and diversity oversight
Nominating committees are expected under corporate governance best practices and SEC disclosure rules to consider diversity of skills, backgrounds, and perspectives when evaluating director candidates.
Question 9: Which of the following BEST describes the relationship between compliance training and a culture of compliance?
- Culture is irrelevant to compliance
- Training replaces the need for written policies
- Training reinforces values and behaviors that build a sustained compliance culture over time (Correct answer)
- Training alone creates a compliance culture
Correct answer: Training reinforces values and behaviors that build a sustained compliance culture over time
Training is one tool that, combined with leadership commitment and consistent enforcement, builds a lasting compliance culture.
Question 10: Under the Fair Credit Reporting Act (FCRA), consumers have the right to receive one free credit report per year from each nationwide credit bureau under which program?
- FinCEN Credit Portal
- CreditSafe
- FICO Score Access Program
- AnnualCreditReport.com (Correct answer)
Correct answer: AnnualCreditReport.com
AnnualCreditReport.com is the FCRA-mandated centralized service where consumers can request one free report annually from Equifax, Experian, and TransUnion.
Question 11: A compliance training program for a healthcare organization should include which of the following topics as a CORE component?
- Investment planning
- Marketing strategies
- Fraud, waste, and abuse prevention (Correct answer)
- Social media branding
Correct answer: Fraud, waste, and abuse prevention
Fraud, waste, and abuse prevention is a federally required core topic for healthcare compliance training programs.
Question 12: Which international standard provides a framework for anti-bribery management systems that organizations can certify against?
- COSO ERM
- ISO 37001 (Correct answer)
- ISO 9001
- ISO 27001
Correct answer: ISO 37001
ISO 37001 is the international standard specifically designed to help organizations establish, implement, and certify an anti-bribery management system.
Question 13: Which of the following is an example of insider trading based on the 'misappropriation theory'?
- A financial journalist trades on material nonpublic information learned during news gathering (Correct answer)
- A CEO sells stock after the company announces earnings
- A director buys stock 30 days before a scheduled earnings call
- An employee exercises vested options under a 10b5-1 plan
Correct answer: A financial journalist trades on material nonpublic information learned during news gathering
The misappropriation theory extends insider trading liability to outsiders who trade on material nonpublic information in breach of a duty owed to the information source, such as an employer.
Question 14: Which Medicare administrative appeals level involves review by a Qualified Independent Contractor (QIC)?
- Level 3 – ALJ Hearing
- Level 1 – Redetermination
- Level 4 – Medicare Appeals Council
- Level 2 – Reconsideration (Correct answer)
Correct answer: Level 2 – Reconsideration
Level 2 reconsideration is performed by a Qualified Independent Contractor (QIC), which is independent of the MAC that handled the Level 1 redetermination.
Question 15: When a company purchases cyber liability insurance to handle the financial impact of a data breach, it is employing which risk response strategy?
- Risk acceptance
- Risk mitigation
- Risk transfer (Correct answer)
- Risk avoidance
Correct answer: Risk transfer
Risk transfer shifts the financial consequence of a risk to a third party, such as an insurer, without eliminating the underlying risk.
Question 16: Which scenario represents a violation of the anti-kickback provisions of the Stark Law and Anti-Kickback Statute in the healthcare compliance context?
- A medical device company pays physicians per referral of Medicare patients (Correct answer)
- A compliance officer receives a salary from the company she oversees
- A physician group negotiates volume discounts with a supplier
- A hospital offers free parking to employees who work night shifts
Correct answer: A medical device company pays physicians per referral of Medicare patients
Paying physicians per referral of federal healthcare program patients constitutes an illegal kickback under the Anti-Kickback Statute and may trigger Stark Law liability.
Question 17: What is the maximum civil monetary penalty per violation category under HIPAA for 'reasonable cause' (not willful neglect)?
- $10,000 (Correct answer)
- $250,000
- $100,000
- $1,000
Correct answer: $10,000
HIPAA penalties for 'reasonable cause' (not willful neglect) range up to $10,000 per violation, up to $100,000 per calendar year.
Question 18: Under the Foreign Corrupt Practices Act (FCPA), which of the following is NOT considered a 'foreign official'?
- A private company employee with no government ties (Correct answer)
- An officer of a state-owned enterprise
- A candidate for foreign office
- A political party official
Correct answer: A private company employee with no government ties
The FCPA defines foreign officials as government employees, state-owned enterprise officers, and political party officials, but not employees of purely private companies.
Question 19: When OIG issues a 'Management Implication Report,' it is intended to:
- Communicate audit findings and recommendations directly to HHS leadership for systemic change (Correct answer)
- Summarize exclusion decisions made during the prior fiscal quarter
- Replace a Corporate Integrity Agreement when the provider's risk is low
- Notify individual managers that they face personal criminal prosecution
Correct answer: Communicate audit findings and recommendations directly to HHS leadership for systemic change
Management Implication Reports convey OIG audit and evaluation findings to HHS management so that agency-wide policy or operational improvements can be pursued.
Question 20: A Zone Program Integrity Contractor (ZPIC) differs from a RAC primarily because ZPICs focus on:
- Fraud investigations and law enforcement referrals (Correct answer)
- Hospital cost report reconciliation
- Underpayment recovery
- Coding accuracy and DRG validation
Correct answer: Fraud investigations and law enforcement referrals
ZPICs (now largely succeeded by UPICs) are focused on investigating suspected fraud and can refer cases to law enforcement, unlike RACs which focus on payment accuracy.
Question 21: A company discovers a data breach affecting 600 California residents. Under California's CCPA/CPRA, which action is required?
- No notification required for fewer than 1,000 residents
- Wait for a regulatory investigation before notifying consumers
- Only notify the California Attorney General
- Notify affected consumers without unreasonable delay (Correct answer)
Correct answer: Notify affected consumers without unreasonable delay
California's data breach notification law requires businesses to notify affected California residents without unreasonable delay when unencrypted personal information is breached.
Question 22: What does the acronym CMS stand for in healthcare compliance?
- Centers for Medicare & Medicaid Services (Correct answer)
- Central Medical Services
- Certified Medical Staff
- Clinical Management System
Correct answer: Centers for Medicare & Medicaid Services
In healthcare compliance, CMS stands for Centers for Medicare & Medicaid Services. This federal agency administers Medicare, Medicaid, and the Children's Health Insurance Program (CHIP), providing health coverage to millions of Americans. CMS also sets and enforces crucial healthcare standards and regulations that providers must follow to participate in these programs.
Question 23: A newly appointed compliance officer discovers the company has no formal third-party due diligence process. Which risk does this gap most directly expose the company to?
- Breach of domestic employment discrimination laws
- Liability for misconduct by agents and intermediaries under the FCPA (Correct answer)
- Violations of the Americans with Disabilities Act
- Non-compliance with product safety regulations
Correct answer: Liability for misconduct by agents and intermediaries under the FCPA
The FCPA holds companies liable for corrupt payments made through third-party agents and intermediaries, making due diligence on such parties a critical compliance safeguard.
Question 24: The EU General Data Protection Regulation (GDPR) applies to U.S. companies under which circumstance?
- Only if the company has a physical office in an EU country
- Only when the company earns more than €10 million in EU revenue
- When processing personal data of EU residents regardless of company location (Correct answer)
- When the company employs EU citizens
Correct answer: When processing personal data of EU residents regardless of company location
GDPR has extraterritorial reach and applies to any organization processing personal data of EU residents, regardless of where the company is located.
Question 25: Which training delivery format is MOST appropriate for reaching large numbers of geographically dispersed employees?
- One-on-one coaching exclusively
- Online or e-learning modules (Correct answer)
- Printed manuals only
- In-person classroom sessions only
Correct answer: Online or e-learning modules
Online e-learning modules allow consistent, trackable compliance training delivery across multiple locations simultaneously.
Question 26: Which of the following scenarios would most likely trigger a *mandatory* exclusion from federal healthcare programs by the OIG?
- Losing a medical license for reasons of professional incompetence.
- A felony conviction for healthcare fraud related to Medicare. (Correct answer)
- A misdemeanor conviction for defaulting on a health education loan.
- Submitting a few accidentally upcoded claims that are later corrected.
Correct answer: A felony conviction for healthcare fraud related to Medicare.
The OIG is required by law to exclude individuals and entities convicted of certain criminal offenses. These mandatory exclusions include felony convictions for Medicare or Medicaid fraud. Other offenses, like license revocation or misdemeanor convictions, may lead to permissive exclusion at the OIG's discretion.
Question 27: A company's compliance program includes policies, but a risk assessment has never been conducted. Which fundamental program element is missing?
- Monitoring and auditing
- Training and communication
- Risk assessment (Correct answer)
- Written policies and procedures
Correct answer: Risk assessment
The DOJ and SEC regard periodic risk assessments as foundational — without identifying and prioritizing risks, other program elements cannot be properly tailored.
Question 28: Which of the following is a detective control?
- Access card system.
- Firewall.
- Surveillance camera footage review (Correct answer)
- Password policy.
Correct answer: Surveillance camera footage review
Surveillance camera footage review is an example of a detective control. Detective controls are designed to identify errors or irregularities *after* they have occurred. By reviewing footage, an organization can detect unauthorized activities, security breaches, or other incidents that may have bypassed preventive measures, allowing for investigation and corrective action.
Question 29: The Financial Industry Regulatory Authority (FINRA) derives its authority primarily from which source?
- SEC oversight and delegation (Correct answer)
- Department of Justice authorization
- Federal Reserve Board
- Congressional statute
Correct answer: SEC oversight and delegation
FINRA is a self-regulatory organization (SRO) operating under SEC oversight, not directly created by Congress.
Question 30: Which office within HHS is primarily responsible for enforcing HIPAA Privacy and Security Rules?
- Food and Drug Administration (FDA)
- Office of the Inspector General (OIG)
- Office for Civil Rights (OCR) (Correct answer)
- Centers for Medicare & Medicaid Services (CMS)
Correct answer: Office for Civil Rights (OCR)
The HHS Office for Civil Rights (OCR) is responsible for enforcing the HIPAA Privacy, Security, and Breach Notification Rules.
Question 31: What should compliance training documentation include to demonstrate program effectiveness?
- Patient health information
- Vendor contracts
- Employee social security numbers
- Attendance records, training content, and test scores (Correct answer)
Correct answer: Attendance records, training content, and test scores
Documenting attendance, content covered, and assessment results proves that training was conducted and comprehended.
Question 32: Which metric is commonly used in quantitative risk analysis to express the expected financial loss from a specific risk over a one-year period?
- Net Present Value of Risk (NPVR)
- Risk Tolerance Level (RTL)
- Annual Loss Expectancy (ALE) (Correct answer)
- Residual Risk Quotient (RRQ)
Correct answer: Annual Loss Expectancy (ALE)
Annual Loss Expectancy (ALE) is calculated as Asset Value × Exposure Factor × Annualized Rate of Occurrence and represents the expected yearly financial impact of a risk.
Question 33: A hospital compliance officer discovers a pattern of incorrect billing for a specific procedure. According to OIG Compliance Guidance, which of the following actions is the most appropriate initial response?
- Reporting the issue to the local news to ensure transparency.
- Developing a corrective action plan and responding to the detected offense. (Correct answer)
- Ignoring the issue unless a government audit occurs.
- Immediately terminating the employees responsible.
Correct answer: Developing a corrective action plan and responding to the detected offense.
A key element of an effective compliance program is responding appropriately to detected offenses and developing corrective action initiatives. This involves investigating the issue, implementing corrective measures to prevent recurrence, and, if necessary, disclosing the issue to the appropriate governmental agency.
Question 34: A compliance officer discovers that the CEO approved a transaction that personally benefited the CEO's spouse. Which governance concept is most directly implicated?
- Whistleblower retaliation
- Duty of loyalty conflict of interest (Correct answer)
- Sarbanes-Oxley disclosure failure
- Business judgment rule violation
Correct answer: Duty of loyalty conflict of interest
A duty of loyalty conflict of interest arises when a director or officer acts in a way that benefits themselves or related parties rather than the corporation.
Question 35: Under the Seven Elements, disciplinary guidelines must be publicized to employees primarily to achieve which goal?
- Reduce HR workload by standardizing terminations
- Deter future violations through awareness of consequences (Correct answer)
- Comply with state employment law
- Satisfy external audit requirements
Correct answer: Deter future violations through awareness of consequences
Well-publicized disciplinary standards serve as a deterrent by ensuring all employees know that violations carry real, consistent consequences.
Question 36: Which Dodd-Frank provision most directly incentivizes employees to report securities law violations to the SEC?
- Whistleblower award program (Correct answer)
- Proxy access rule
- Clawback provision
- Say-on-pay vote
Correct answer: Whistleblower award program
Dodd-Frank's whistleblower award program offers monetary rewards of 10–30% of sanctions exceeding $1 million to individuals who report securities violations to the SEC.
Question 37: In compliance monitoring, what is a 'key risk indicator' (KRI)?
- A forward-looking metric that signals increasing exposure to a specific risk (Correct answer)
- A metric that measures the cost of compliance activities
- A historical report of past compliance failures
- A list of all identified risks in the risk register
Correct answer: A forward-looking metric that signals increasing exposure to a specific risk
KRIs are forward-looking metrics that provide early warning signals when risk exposure is increasing, enabling proactive management.
Question 38: How should a compliance officer handle a situation where an employee claims they did not understand training material?
- Terminate the employee
- Provide additional one-on-one education and document the remediation (Correct answer)
- Report to the OIG
- Dismiss the concern
Correct answer: Provide additional one-on-one education and document the remediation
Providing remedial education and documenting it demonstrates good-faith effort to ensure employee comprehension.
Question 39: How can an organization promote a culture of ethics?
- By reducing communication channels.
- By implementing ethics training and leadership modeling (Correct answer)
- By avoiding policy development.
- By ignoring unethical actions.
Correct answer: By implementing ethics training and leadership modeling
Promoting a culture of ethics requires active measures, including comprehensive ethics training to educate employees on expected behaviors and policies. Additionally, leadership modeling ethical conduct sets a powerful example, demonstrating that integrity is valued and expected at all levels. These actions collectively embed ethical principles into the organization's daily operations and decision-making.
Question 40: A compliance officer discovers that new hires in the billing department have not received fraud and abuse training. What is the FIRST action to take?
- Notify CMS directly
- Schedule immediate training for those employees (Correct answer)
- Report the finding to the OIG
- Terminate the employees
Correct answer: Schedule immediate training for those employees
The immediate corrective action is to schedule training so the employees gain required compliance knowledge as soon as possible.
Question 41: Which self-regulatory organization (SRO) oversees compliance for municipal securities dealers?
- SIPC
- FINRA
- MSRB (Correct answer)
- CFTC
Correct answer: MSRB
The Municipal Securities Rulemaking Board (MSRB) establishes rules for municipal securities dealers and advisors, though the SEC and FINRA enforce them.
Question 42: Which federal law requires healthcare organizations to train employees on patient privacy as part of HIPAA compliance?
- Stark Law
- Anti-Kickback Statute
- HIPAA Privacy Rule (Correct answer)
- False Claims Act
Correct answer: HIPAA Privacy Rule
The HIPAA Privacy Rule mandates that covered entities train all workforce members on privacy policies and procedures.
Question 43: What is an Advance Beneficiary Notice (ABN) primarily used for?
- To formally appeal a Medicare claim denial on behalf of a beneficiary
- To inform a Medicare beneficiary that Medicare may not cover a service and the patient may be financially responsible (Correct answer)
- To obtain prior authorization from Medicare before providing an elective service
- To notify a patient before surgery of potential medical complications
Correct answer: To inform a Medicare beneficiary that Medicare may not cover a service and the patient may be financially responsible
An ABN is given to Medicare beneficiaries before receiving potentially non-covered services so they can make an informed decision about receiving the service and assume financial responsibility if Medicare denies payment.
Question 44: A compliance monitoring review finds that exception reports are generated but never reviewed. This represents which type of control failure?
- Operating effectiveness failure (Correct answer)
- Design deficiency only
- Regulatory reporting gap
- Preventive control absence
Correct answer: Operating effectiveness failure
When a control exists but is not actually performed as designed (reports generated but not reviewed), it is an operating effectiveness failure rather than a design issue.
Question 45: Under the Telephone Consumer Protection Act (TCPA), which practice requires prior express written consent?
- Sending a transactional email confirmation
- Sending marketing text messages using an autodialer (Correct answer)
- Mailing a physical marketing brochure
- Making a manually dialed call to a business landline
Correct answer: Sending marketing text messages using an autodialer
The TCPA requires prior express written consent before sending marketing texts or calls using an automatic telephone dialing system to cell phones.
Question 46: Which of the following activities would be performed by the second line of defense in a three-lines model?
- Approving individual customer credit applications
- Processing customer transactions on a daily basis
- Conducting independent audits and reporting to the audit committee
- Designing compliance policies, monitoring risk, and providing oversight to the first line (Correct answer)
Correct answer: Designing compliance policies, monitoring risk, and providing oversight to the first line
The second line—comprising compliance, risk management, and legal functions—sets policy, monitors first-line adherence, and provides independent oversight without executing operations.
Question 47: The 'three lines of defense' model assigns internal audit to which line?
- Second line
- First line
- Third line (Correct answer)
- Fourth line
Correct answer: Third line
Internal audit serves as the third line of defense by providing independent assurance over the effectiveness of the first and second lines.
Question 48: What is the key distinction between healthcare 'fraud' and 'abuse'?
- Whether the act was committed by a physician or an administrator.
- The financial amount involved in the misconduct.
- The intent and knowledge of the individual committing the act. (Correct answer)
- Whether the service was medically necessary for the patient.
Correct answer: The intent and knowledge of the individual committing the act.
The primary difference between fraud and abuse is intent. Fraud involves an intentional deception or misrepresentation that the individual knows to be false and that could result in an unauthorized benefit. Abuse involves actions that may result in unnecessary costs to federal healthcare programs but are not the result of knowing and willful misconduct.
Question 49: Why is a code of ethics important in an organization?
- To help employees make ethical choices (Correct answer)
- To confuse employees.
- To reduce company profits.
- To increase reporting delays.
Correct answer: To help employees make ethical choices
A code of ethics provides clear guidelines and principles that help employees navigate complex situations and make decisions consistent with the organization's values. It sets expectations for professional conduct, fostering a culture of integrity and responsibility. This guidance is crucial for maintaining ethical standards across all levels of the company.
Question 50: How does management monitor internal controls?
- By conducting staff training.
- Through regular audits and performance reviews (Correct answer)
- By outsourcing accounting functions.
- By increasing marketing efforts.
Correct answer: Through regular audits and performance reviews
Management monitors internal controls through various mechanisms, most notably regular audits and performance reviews. Audits, both internal and external, assess the effectiveness and adherence to established controls. Performance reviews ensure that employees are following procedures and that the controls are functioning as intended, allowing for timely adjustments and improvements.
Question 51: Which agency enforces workplace safety regulations?
- OSHA (Correct answer)
- FDA
- DEA
- IRS
Correct answer: OSHA
OSHA, the Occupational Safety and Health Administration, is the federal agency responsible for setting and enforcing standards to ensure safe and healthful working conditions for employees. Its regulations cover a wide range of workplace hazards, aiming to prevent injuries, illnesses, and fatalities. Compliance with OSHA standards is mandatory for most U.S. employers.
Question 52: Which staff group typically requires specialized compliance training beyond general annual education?
- Security guards
- Coding and billing personnel (Correct answer)
- Cafeteria workers
- Maintenance staff
Correct answer: Coding and billing personnel
Coding and billing personnel handle sensitive claims data and face higher fraud and abuse risk, requiring specialized training.
Question 53: When an organization updates its compliance policies due to a regulatory change, training on the new policy should occur:
- Only at the next annual training cycle
- Only for managers
- Three years after the change
- Within a reasonable timeframe of the policy update (Correct answer)
Correct answer: Within a reasonable timeframe of the policy update
Employees must be trained on policy changes within a reasonable period so they can immediately comply with updated requirements.
Question 54: Which element of the Seven Elements of Compliance specifically addresses employee education and training?
- Written policies and procedures
- Training and education (Correct answer)
- Effective lines of communication
- Internal monitoring and auditing
Correct answer: Training and education
Training and education is the third element of the OIG's Seven Elements of an effective compliance program.
Question 55: In risk heat mapping, a risk plotted in the top-right quadrant (high likelihood, high impact) should receive which management response?
- Prioritize for immediate mitigation and senior oversight (Correct answer)
- Transfer to insurance carrier immediately
- Accept and monitor with no immediate action
- Defer to the next annual risk assessment cycle
Correct answer: Prioritize for immediate mitigation and senior oversight
High-likelihood, high-impact risks demand prompt, prioritized treatment and should be escalated to senior leadership for oversight and resource allocation.
Question 56: A patient submits a written request to their healthcare provider for a copy of their medical records. Under the HIPAA Privacy Rule, the provider must generally provide access to the records within what timeframe?
- 30 calendar days (Correct answer)
- Immediately upon request
- 10 business days
- 60 calendar days
Correct answer: 30 calendar days
The HIPAA Privacy Rule gives individuals the right to access and receive a copy of their PHI. A covered entity must act on the request within 30 days of receipt. If necessary, the entity can extend the time for no more than 30 additional days, provided they inform the individual in writing of the reasons for the delay.
Question 57: Which agency has primary examination authority over federally chartered credit unions?
- Federal Reserve
- OCC
- NCUA (Correct answer)
- FDIC
Correct answer: NCUA
The National Credit Union Administration (NCUA) charters, insures, and supervises federal credit unions.
Question 58: Under an OIG-recommended compliance program, who bears primary responsibility for overseeing the compliance training program?
- The Compliance Officer (Correct answer)
- The CEO
- The CFO
- The HR Director
Correct answer: The Compliance Officer
The Compliance Officer is responsible for developing, implementing, and overseeing all aspects of the compliance training program.
Question 59: Which scenario best demonstrates effective internal monitoring under the Seven Elements?
- Running quarterly claims audits comparing billed codes to documentation (Correct answer)
- Posting the Code of Conduct in the employee break room
- Requiring department managers to self-certify compliance annually
- Conducting an annual review of the compliance policy manual
Correct answer: Running quarterly claims audits comparing billed codes to documentation
Regular audits comparing billing codes to clinical documentation constitute active internal monitoring, the fifth element of an effective compliance program.
Question 60: What is the primary purpose of a compliance risk register?
- To record regulatory examination findings only
- To catalog identified risks along with their likelihood, impact, and control status (Correct answer)
- To track customer complaints received by the compliance department
- To document employee disciplinary actions
Correct answer: To catalog identified risks along with their likelihood, impact, and control status
A risk register is a centralized record that captures identified risks, their assessed severity, assigned owners, current controls, and remediation status.
Question 61: A healthcare organization's compliance training log shows several employees are overdue for annual training. Under an effective compliance program, this information should be:
- Ignored until the next audit
- Deleted from records
- Shared publicly
- Escalated to management with a remediation plan (Correct answer)
Correct answer: Escalated to management with a remediation plan
Overdue training must be escalated and remediated promptly to maintain program effectiveness and reduce risk exposure.
Question 62: What is a conflict of interest in corporate ethics?
- Making objective decisions.
- Taking on extra job duties.
- Reporting to supervisors.
- Allowing personal interests to influence actions (Correct answer)
Correct answer: Allowing personal interests to influence actions
A conflict of interest arises when an individual's personal interests, relationships, or affiliations have the potential to improperly influence their professional judgment or actions within the organization. This can compromise objectivity and lead to decisions that benefit the individual rather than the company or its stakeholders. Recognizing and managing conflicts of interest is crucial for ethical conduct.
Question 63: In the context of enforcement, what does a 'consent decree' represent?
- A court-enforceable settlement agreement between a regulator and a company (Correct answer)
- A criminal conviction entered without trial
- An internal compliance commitment with no external oversight
- A temporary restraining order against business operations
Correct answer: A court-enforceable settlement agreement between a regulator and a company
A consent decree is a negotiated, court-approved agreement that resolves an enforcement action and is legally binding and enforceable.
Question 64: When a compliance audit identifies documentation deficiencies, what should the corrective action plan include?
- Specific steps, responsible parties, deadlines, and follow-up monitoring to address the deficiencies (Correct answer)
- Notification to all patients
- Only a verbal promise to improve
- A request to extend the audit deadline indefinitely
Correct answer: Specific steps, responsible parties, deadlines, and follow-up monitoring to address the deficiencies
Effective corrective action plans are specific, assign accountability, set timelines, and include monitoring to verify the deficiency is resolved.
Question 65: Which exclusion authority allows the OIG to exclude individuals or entities convicted of program-related crimes from participation in federal healthcare programs?
- Corporate Integrity Agreement
- Permissive exclusion under 42 U.S.C. § 1320a-7(b)
- Mandatory exclusion under 42 U.S.C. § 1320a-7(a) (Correct answer)
- Civil Monetary Penalties Law
Correct answer: Mandatory exclusion under 42 U.S.C. § 1320a-7(a)
Mandatory exclusion under 42 U.S.C. § 1320a-7(a) requires the OIG to exclude individuals convicted of Medicare/Medicaid fraud, patient abuse, or felony drug offenses for a minimum of five years.
Question 66: Which fiduciary duty requires directors to act on an informed basis after adequate deliberation before making a business decision?
- Duty of loyalty
- Duty of obedience
- Duty of candor
- Duty of care (Correct answer)
Correct answer: Duty of care
The duty of care requires directors to act with the care of a reasonably prudent person, which includes being adequately informed before making decisions.
Question 67: The Occupational Safety and Health Administration (OSHA) falls under which cabinet department?
- Department of Labor (Correct answer)
- Department of Commerce
- Department of Health and Human Services
- Department of the Interior
Correct answer: Department of Labor
OSHA is an agency within the U.S. Department of Labor, responsible for workplace safety standards and enforcement.
Question 68: An employee refuses to complete mandatory annual compliance training. What is the appropriate organizational response?
- Enforce disciplinary action consistent with written policy (Correct answer)
- Ignore the refusal
- Notify the OIG immediately
- Waive the requirement for that employee
Correct answer: Enforce disciplinary action consistent with written policy
Consistent enforcement of training requirements through disciplinary action demonstrates program integrity and deters non-compliance.
Question 69: A company provides a lavish resort trip to a government procurement officer before a contract decision. Under the FCPA's antibribery provisions, this is most likely:
- Permitted if it falls under the facilitating payments exception
- Prohibited only if the value exceeds $250
- Permitted as a reasonable business entertainment expense
- Prohibited because the intent is to influence an official act (Correct answer)
Correct answer: Prohibited because the intent is to influence an official act
The FCPA prohibits giving anything of value to a foreign official to influence an official act, and lavish entertainment provided to influence a contract award meets that standard regardless of dollar amount.
Question 70: Which of the following is a key element of ethical corporate governance?
- Secrecy in board meetings.
- Bias in promotions.
- Accountability and transparency (Correct answer)
- Favoritism in hiring.
Correct answer: Accountability and transparency
Accountability and transparency are cornerstones of ethical corporate governance. Accountability ensures that individuals and the organization are responsible for their actions and decisions, while transparency means that information is openly communicated to stakeholders. Together, they build trust, reduce the likelihood of misconduct, and enable informed decision-making by all parties.
Question 71: A compliance training program that includes real-world case studies and role-playing scenarios is primarily designed to achieve what outcome?
- Satisfy OSHA requirements
- Improve employee engagement and retention of compliance concepts (Correct answer)
- Reduce training time
- Replace written policies
Correct answer: Improve employee engagement and retention of compliance concepts
Interactive methods like case studies improve retention and help employees apply compliance principles to actual situations.
Question 72: Under the HIPAA Security Rule, which of the following is a 'required' (not addressable) implementation specification?
- Automatic logoff
- Encryption of ePHI at rest
- Unique user identification for each system user (Correct answer)
- Encryption and decryption of ePHI
Correct answer: Unique user identification for each system user
Unique user identification is a required implementation specification under the Access Control standard of the HIPAA Security Rule's Technical Safeguards.
Question 73: Which ethical theory holds that the morality of an action is determined solely by its consequences and outcomes?
- Consequentialism (Correct answer)
- Social contract theory
- Virtue ethics
- Deontology
Correct answer: Consequentialism
Consequentialism (including utilitarianism) judges actions as right or wrong based solely on the outcomes they produce.
Question 74: A hospital gives physicians free office space below fair market value in exchange for referrals. This arrangement most likely violates which law?
- Stark Law (Correct answer)
- ERISA
- EMTALA
- Bayh-Dole Act
Correct answer: Stark Law
Stark Law (42 U.S.C. § 1395nn) prohibits physicians from referring Medicare/Medicaid patients for designated health services to entities with which the physician has a financial relationship, including below-market rent.
Question 75: What is the purpose of a compliance training needs assessment?
- To determine employee salaries
- To identify gaps in staff knowledge and tailor training accordingly (Correct answer)
- To review patient satisfaction scores
- To audit vendor performance
Correct answer: To identify gaps in staff knowledge and tailor training accordingly
A needs assessment identifies where knowledge deficiencies exist so training can be focused where it will have the most impact.
Question 76: A company voluntarily discloses an FCPA violation to the DOJ before an investigation begins. What is the most likely benefit of voluntary disclosure?
- Complete immunity from prosecution
- Guaranteed deferred prosecution agreement
- A presumption of declination or reduced penalty (Correct answer)
- Reduction of penalties to zero
Correct answer: A presumption of declination or reduced penalty
DOJ's FCPA Corporate Enforcement Policy creates a presumption of declination for companies that voluntarily self-disclose, fully cooperate, and remediate.
Question 77: Which of the following best describes an 'automated review' conducted by a RAC?
- A review conducted using statistical sampling and extrapolation
- A review triggered by a whistleblower complaint
- A claim review based solely on data analysis without requesting medical records (Correct answer)
- A review initiated after a provider self-discloses an error
Correct answer: A claim review based solely on data analysis without requesting medical records
Automated reviews use claims data and logic edits to identify clear payment errors without requiring the provider to submit medical records.
Question 78: Which scenario best illustrates a 'tone at the top' failure in corporate governance?
- The compliance department fails to update its policy manual
- Senior executives routinely override expense approval controls (Correct answer)
- A vendor delivers goods late without penalty
- A front-line employee submits a fraudulent reimbursement claim
Correct answer: Senior executives routinely override expense approval controls
Tone at the top refers to leadership's demonstrated commitment to ethical conduct; executives who override controls signal that rules do not apply to them, undermining the entire compliance culture.
Question 79: Which regulatory principle requires that compliance programs be proportional to the actual risks faced by an organization?
- Strict liability framework
- Zero-tolerance standard
- Risk-based approach (Correct answer)
- Prescriptive compliance
Correct answer: Risk-based approach
A risk-based approach tailors compliance resources and controls to the level and nature of risks the organization actually faces.
Question 80: What is the primary purpose of corporate governance?
- To ensure proper management and accountability (Correct answer)
- To reduce customer engagement.
- To increase employee workloads.
- To eliminate board oversight.
Correct answer: To ensure proper management and accountability
The primary purpose of corporate governance is to establish a framework of rules, practices, and processes by which a company is directed and controlled. This ensures proper management, accountability, and ethical conduct within the organization. Effective governance protects stakeholder interests and promotes long-term sustainability.
Question 81: Which of the following is NOT a patient right granted under the HIPAA Privacy Rule?
- The right to demand deletion of their entire medical record for any reason. (Correct answer)
- The right to receive an accounting of disclosures of their PHI.
- The right to request an amendment to their PHI if they believe it is inaccurate.
- The right to access and obtain a copy of their protected health information (PHI).
Correct answer: The right to demand deletion of their entire medical record for any reason.
While the HIPAA Privacy Rule grants patients several rights, including the right to access, amend, and receive an accounting of disclosures of their PHI, it does not provide an absolute right to have their entire medical record deleted. There are legal and medical requirements for retaining records for a certain period.
Question 82: When assessing whether a board director is 'independent' under NYSE listing standards, which relationship would disqualify independence?
- Membership in the same professional association as the CEO
- Service on another public company's board
- Former employee of the company within the last three years (Correct answer)
- Ownership of 2% of the company's stock
Correct answer: Former employee of the company within the last three years
NYSE standards disqualify directors who were employees of the listed company within the preceding three years from being classified as independent.
Question 83: A compliance officer learns an employee accessed a competitor's confidential files obtained through hacking. This situation most directly involves which ethical concept?
- Misappropriation of confidential information (Correct answer)
- Antitrust price fixing
- Insider trading
- Bribery of a public official
Correct answer: Misappropriation of confidential information
Accessing confidential files obtained through unauthorized means constitutes misappropriation of confidential information and potentially violates the Computer Fraud and Abuse Act.
Question 84: A healthcare organization has recently implemented a new, user-friendly portal where all employees can easily find the Code of Conduct, policies on billing and coding, and procedures for handling patient information. This initiative primarily fulfills which of the Seven Elements of an Effective Compliance Program?
- Developing effective lines of communication.
- Conducting effective training and education.
- Conducting internal monitoring and auditing.
- Implementing written policies, procedures, and standards of conduct. (Correct answer)
Correct answer: Implementing written policies, procedures, and standards of conduct.
This scenario directly relates to the foundational element of implementing and maintaining written documentation. Making policies, procedures, and standards of conduct accessible and understandable is a key requirement of this element.
Question 85: Under Sarbanes-Oxley Section 302, who must certify the accuracy of quarterly and annual financial reports?
- CEO and CFO (Correct answer)
- General counsel and CFO
- Board chairman and CEO
- External auditor and audit committee chair
Correct answer: CEO and CFO
SOX Section 302 requires the CEO and CFO to personally certify the accuracy of periodic financial reports filed with the SEC.
Question 86: A covered entity may deny a patient's request to amend their PHI if:
- The patient submits the request verbally
- The PHI was not created by the covered entity (Correct answer)
- The amendment would increase the size of the medical record
- More than 15 days have passed since the original record was created
Correct answer: The PHI was not created by the covered entity
A covered entity may deny an amendment request if it did not create the PHI and the originating entity is available to act on the request.
Question 87: What role does the board of directors play in governance?
- Provides governance and oversight (Correct answer)
- Manages HR functions.
- Handles day-to-day operations.
- Focuses solely on marketing.
Correct answer: Provides governance and oversight
The board of directors is responsible for the overall strategic direction, oversight, and governance of an organization. They provide guidance to management, ensure compliance with laws and regulations, and protect the interests of shareholders and other stakeholders. Their role is critical in setting the tone for ethical conduct and ensuring long-term success.
Question 88: As part of a civil settlement to resolve allegations of healthcare fraud, a hospital system agrees to a set of stringent compliance obligations monitored by the OIG for five years. This arrangement, which allows the hospital to continue participating in federal healthcare programs, is known as a:
- Corporate Integrity Agreement (CIA) (Correct answer)
- Corrective Action Plan (CAP)
- Federal Participation Decree (FPD)
- Settlement Compliance Mandate (SCM)
Correct answer: Corporate Integrity Agreement (CIA)
A Corporate Integrity Agreement (CIA) is an agreement between a healthcare entity and the Office of Inspector General (OIG) as part of a civil settlement. In exchange for the OIG's agreement not to seek exclusion from federal healthcare programs, the entity agrees to specific obligations to promote compliance and undergo monitoring, typically for five years.
Question 89: Which principle from the OECD Guidelines for Multinational Enterprises relates most directly to corporate governance transparency?
- Mandatory local sourcing of materials
- Disclosure of material information to shareholders and the public in a timely manner (Correct answer)
- Prohibition of all political contributions worldwide
- Elimination of all intra-group transactions
Correct answer: Disclosure of material information to shareholders and the public in a timely manner
The OECD Guidelines emphasize timely and accurate disclosure of material information on financial performance, ownership, and governance as a core transparency principle.
Question 90: Which internal control activity involves comparing financial data against prior periods or industry benchmarks to detect anomalies?
- Segregation of duties
- Analytical procedures (Correct answer)
- Authorization controls
- Physical controls
Correct answer: Analytical procedures
Analytical procedures use comparisons and ratio analyses to identify unexpected variances that may indicate errors or fraud.
Question 91: A hospital's employee inappropriately accesses the medical records of a celebrity patient. Which type of HIPAA breach is this?
- Environmental breach
- Accidental disclosure
- Unauthorized internal access (Correct answer)
- Physical theft
Correct answer: Unauthorized internal access
Accessing PHI without a valid treatment, payment, or operations reason by an insider constitutes unauthorized internal access, a common HIPAA violation.
Question 92: Under the Gramm-Leach-Bliley Act (GLBA), which agency enforces the Safeguards Rule for non-bank financial institutions not covered by a federal functional regulator?
- SEC
- OCC
- FTC (Correct answer)
- CFPB
Correct answer: FTC
The FTC enforces the GLBA Safeguards Rule for financial institutions not subject to oversight by a federal functional regulator such as a banking agency.
Question 93: Under an effective CCT compliance program, how often should general compliance training be provided to all employees?
- Only when regulations change
- Only at initial hire
- Every three years
- At least annually (Correct answer)
Correct answer: At least annually
OIG guidance recommends that compliance training be conducted at least annually for all employees to maintain awareness.
Question 94: An anti-money laundering (AML) compliance program must include all of the following EXCEPT:
- Designation of a compliance officer
- Ongoing employee training
- Annual criminal background checks on all customers (Correct answer)
- Internal controls and policies
Correct answer: Annual criminal background checks on all customers
The Bank Secrecy Act's four pillars of AML compliance are internal controls, a designated compliance officer, employee training, and independent testing — annual criminal background checks on all customers are not required.
Question 95: Which scenario best illustrates 'risk concentration' that a compliance officer should flag?
- A bank has 60% of its loan portfolio concentrated in one industry sector (Correct answer)
- An employee receives mandatory compliance training annually
- A company diversifies its vendor base across 50 suppliers
- A firm maintains duplicate transaction records in two systems
Correct answer: A bank has 60% of its loan portfolio concentrated in one industry sector
Risk concentration occurs when exposure to a single risk factor is high enough that adverse developments in that area could cause significant harm.
Question 96: What does 'role-specific' compliance training mean in practice?
- Training is only for compliance staff
- Training is optional for senior staff
- All employees receive identical training content
- Training content is tailored to the compliance risks specific to each job function (Correct answer)
Correct answer: Training content is tailored to the compliance risks specific to each job function
Role-specific training addresses the particular regulatory risks and responsibilities associated with each employee's position.
Question 97: A compliance officer wants to verify that training is effective. Which method BEST evaluates knowledge retention?
- Post-training knowledge assessments or tests (Correct answer)
- Reviewing employee timesheets
- Checking patient satisfaction surveys
- Counting attendance
Correct answer: Post-training knowledge assessments or tests
Post-training assessments directly measure whether employees retained and understood the compliance material presented.
Question 98: Under the RAC program, how are RAC contractors typically compensated?
- Fixed annual government contract fee
- Hourly rate for clinical reviewers
- Per-claim flat fee for every claim reviewed
- Contingency fee based on improper payments identified (Correct answer)
Correct answer: Contingency fee based on improper payments identified
RACs are paid on a contingency fee basis, receiving a percentage of the overpayments collected and underpayments identified.
Question 99: The SEC's Whistleblower Program under Dodd-Frank requires that awards be paid only when the whistleblower's information leads to a successful enforcement action resulting in sanctions exceeding what threshold?
- $500,000
- $1 million (Correct answer)
- $5 million
- $100,000
Correct answer: $1 million
SEC whistleblower awards are available only when the related enforcement action results in monetary sanctions exceeding $1 million.
Question 100: A 'three lines of defense' model assigns the primary ownership of risk management to which line?
- Internal audit
- Board of directors
- Business unit management (Correct answer)
- Compliance and risk functions
Correct answer: Business unit management
The first line of defense consists of business unit management, who own and manage risks in day-to-day operations.
Certified Compliance Technician (CCT) Exam
The CCT certification validates foundational knowledge in regulatory compliance, risk management, and ethical practices relevant to various industries.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds