← All CCT Flashcard Decks

Regulatory Frameworks & Compliance Standards Flashcards

7 cards from real CCT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Regulatory Frameworks & Compliance Standards flashcards as text
  1. Which federal agency enforces the Bank Secrecy Act (BSA) and oversees anti-money laundering compliance for financial institutions?

    Answer: Financial Crimes Enforcement Network (FinCEN)

    FinCEN, a bureau of the U.S. Treasury Department, administers and enforces the Bank Secrecy Act and AML regulations.

  2. Under the Sarbanes-Oxley Act, which section requires management to assess and report on the effectiveness of internal controls over financial reporting?

    Answer: Section 404

    SOX Section 404 mandates that management assess internal controls over financial reporting and that external auditors attest to that assessment.

  3. The EU General Data Protection Regulation (GDPR) applies to U.S. companies under which circumstance?

    Answer: When processing personal data of EU residents regardless of company location

    GDPR has extraterritorial reach and applies to any organization processing personal data of EU residents, regardless of where the company is located.

  4. Which compliance framework specifically addresses payment card data security and is maintained by a council of major card brands?

    Answer: PCI DSS

    PCI DSS (Payment Card Industry Data Security Standard) is maintained by the PCI Security Standards Council and governs protection of cardholder data.

  5. A company subject to HIPAA must provide patients access to their Protected Health Information (PHI) within how many days of a request?

    Answer: 30 days

    HIPAA's Privacy Rule requires covered entities to provide individuals access to their PHI within 30 days of a request, with a possible 30-day extension.

  6. The Foreign Corrupt Practices Act (FCPA) prohibits which type of conduct by U.S. companies and their agents?

    Answer: Bribing foreign government officials to obtain business

    The FCPA prohibits U.S. persons and businesses from bribing foreign government officials to obtain or retain business.

  7. Which regulatory principle requires that compliance programs be proportional to the actual risks faced by an organization?

    Answer: Risk-based approach

    A risk-based approach tailors compliance resources and controls to the level and nature of risks the organization actually faces.