Regulatory Frameworks & Compliance Standards Flashcards
7 cards from real CCT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Regulatory Frameworks & Compliance Standards flashcards as text
Which element is NOT typically considered one of the seven components of an effective compliance program under the U.S. Federal Sentencing Guidelines?
Answer: Mandatory arbitration clause for employees
The seven elements of an effective compliance program under the Federal Sentencing Guidelines do not include mandatory arbitration; they focus on prevention, detection, and response.
The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule primarily requires financial institutions to do which of the following?
Answer: Develop and maintain a written information security program
GLBA's Safeguards Rule requires financial institutions to develop, implement, and maintain a comprehensive written information security program to protect customer information.
Under EPA's RCRA regulations, a Conditionally Exempt Small Quantity Generator (CESQG) generates how much hazardous waste per month?
Answer: Less than 100 kg
CESQGs (now called Very Small Quantity Generators) generate less than 100 kg of hazardous waste per month and have the least stringent requirements.
A company discovers a data breach affecting 600 California residents. Under California's CCPA/CPRA, which action is required?
Answer: Notify affected consumers without unreasonable delay
California's data breach notification law requires businesses to notify affected California residents without unreasonable delay when unencrypted personal information is breached.
The SEC's Regulation FD (Fair Disclosure) prohibits public companies from doing which of the following?
Answer: Selectively disclosing material nonpublic information to select investors before the public
Reg FD requires that when a public company discloses material nonpublic information to certain individuals, it must make public disclosure simultaneously or promptly.
Which COSO framework component addresses the policies and procedures that help ensure management directives related to risk mitigation are carried out?
Answer: Control Activities
Control Activities in the COSO framework are the policies and procedures that help ensure management's risk responses are effectively carried out.
Under the Fair Labor Standards Act (FLSA), which type of employee is exempt from overtime pay requirements?
Answer: Employees meeting both salary level and duties tests for executive, administrative, or professional exemptions
FLSA exemptions require employees to meet both a minimum salary level threshold and specific duties tests related to executive, administrative, professional, or other recognized categories.