Compliance Monitoring & Reporting Flashcards
7 cards from real CCT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Compliance Monitoring & Reporting flashcards as text
A compliance officer preparing a board report should PRIMARILY focus on which type of information?
Answer: Trending risk indicators, material exceptions, and corrective action status
Board reports should provide decision-relevant information such as risk trends, significant exceptions, and status of remediation rather than granular operational data.
What does 'three lines of defense' mean in the context of compliance monitoring?
Answer: Operational management, compliance/risk functions, and internal audit serving distinct oversight roles
The three lines of defense model assigns ownership of controls to operational management (1st), oversight to compliance and risk functions (2nd), and independent assurance to internal audit (3rd).
A compliance monitoring review finds that exception reports are generated but never reviewed. This represents which type of control failure?
Answer: Operating effectiveness failure
When a control exists but is not actually performed as designed (reports generated but not reviewed), it is an operating effectiveness failure rather than a design issue.
Which of the following is the BEST example of a preventive compliance control?
Answer: System-enforced transaction limits that block unauthorized amounts
Preventive controls stop violations before they occur; system-enforced limits block non-compliant transactions in real-time rather than detecting them after the fact.
An organization is required to report its compliance program effectiveness to a federal regulator annually. Which document would MOST comprehensively satisfy this requirement?
Answer: Comprehensive compliance management system (CMS) assessment report
A CMS assessment report documents the organization's policies, training, monitoring, and corrective action processes, providing regulators with a full picture of program effectiveness.
A 'gap analysis' in compliance monitoring compares which two elements?
Answer: Current state of controls versus required state under applicable regulations
A compliance gap analysis assesses where an organization currently stands against what regulations or standards require, identifying areas needing remediation.
Under the Sarbanes-Oxley Act (SOX) Section 302, corporate executives must certify which of the following in quarterly and annual filings?
Answer: That they have reviewed the report and that internal controls are effective
SOX Section 302 requires CEOs and CFOs to personally certify that they have reviewed SEC filings and that internal controls over financial reporting are effective.