โ† All CCT Flashcard Decks

Compliance Monitoring & Reporting Flashcards

7 cards from real CCT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Compliance Monitoring & Reporting flashcards as text
  1. A company's compliance dashboard shows 100% policy attestation completion but regulators still find widespread violations. What is the MOST likely explanation?

    Answer: Employees completed attestations without reading or understanding the policies

    High attestation rates can be misleading if employees sign off without genuinely understanding policies, a phenomenon known as 'checkbox compliance.'

  2. Which regulatory body requires broker-dealers to file Form BD and maintain specific books and records under SEC Rule 17a-3?

    Answer: FINRA/SEC

    The SEC and FINRA regulate broker-dealers, requiring them to maintain books and records under SEC Rule 17a-3 and file registration forms including Form BD.

  3. In compliance monitoring, what is a 'key risk indicator' (KRI)?

    Answer: A forward-looking metric that signals increasing exposure to a specific risk

    KRIs are forward-looking metrics that provide early warning signals when risk exposure is increasing, enabling proactive management.

  4. A compliance officer must escalate a potential FCPA violation discovered during monitoring. To whom should this be escalated FIRST according to best practice?

    Answer: Legal counsel and senior management or the board

    FCPA violations carry serious criminal and civil penalties, so they should be escalated immediately to legal counsel and senior management or the board for proper handling.

  5. What is the purpose of a 'testing calendar' in a compliance monitoring program?

    Answer: To ensure all controls are tested at defined intervals across the year

    A testing calendar schedules when each control will be tested, ensuring consistent coverage and preventing gaps where controls go untested for extended periods.

  6. Under GDPR, if a personal data breach is likely to result in a risk to individuals' rights, within what timeframe must a controller notify the supervisory authority?

    Answer: 72 hours

    GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach that poses a risk to individuals.

  7. Which approach to compliance monitoring involves selecting a random sample of transactions to test, regardless of risk level?

    Answer: Statistical random sampling

    Statistical random sampling selects transactions randomly without regard to risk, giving every transaction an equal probability of selection.