CCT Compliance Monitoring & Reporting 2 — Questions and Answers
Question 1: A compliance officer discovers that a key control has been failing silently for 60 days with no alert generated. What does this scenario most likely indicate?
- The control was intentionally disabled by management
- A gap in the monitoring system's alert thresholds or coverage (Correct answer)
- The control failure is not material and requires no action
- External auditors are responsible for detecting such failures
Correct answer: A gap in the monitoring system's alert thresholds or coverage
Silent control failures typically expose gaps in monitoring coverage, alert thresholds, or logging configurations that allowed the issue to go undetected.
Question 2: Under the Bank Secrecy Act (BSA), a financial institution must file a Suspicious Activity Report (SAR) within how many calendar days of detecting a suspicious transaction?
- 15 days
- 30 days (Correct answer)
- 45 days
- 60 days
Correct answer: 30 days
BSA regulations require SARs to be filed within 30 calendar days of the date the suspicious activity is detected.
Question 3: Which metric is MOST useful for measuring the effectiveness of a compliance monitoring program over time?
- Total number of policies in the policy library
- Repeat findings rate across audit cycles (Correct answer)
- Number of compliance staff hired annually
- Volume of training sessions delivered
Correct answer: Repeat findings rate across audit cycles
A high repeat findings rate indicates that corrective actions are not resolving root causes, making it a key effectiveness indicator.
Question 4: A compliance team uses a heat map to prioritize its monitoring activities. What two dimensions does a risk heat map typically plot?
- Cost and time required
- Likelihood and impact (Correct answer)
- Frequency and complexity
- Staffing and budget
Correct answer: Likelihood and impact
Risk heat maps plot likelihood (probability) on one axis and impact (severity) on the other to prioritize risks visually.
Question 5: When an organization conducts a 'look-back review,' what is the primary purpose?
- To forecast future compliance risks
- To retroactively examine past transactions or activities for compliance violations (Correct answer)
- To assess vendor contract renewal terms
- To train new compliance officers on historical events
Correct answer: To retroactively examine past transactions or activities for compliance violations
A look-back review examines historical records to identify whether past activities violated regulations that may not have been flagged at the time.
Question 6: Which of the following BEST describes 'continuous monitoring' in a compliance context?
- Conducting annual internal audits on a fixed schedule
- Automated, ongoing review of controls and transactions in near real-time (Correct answer)
- Hiring external auditors to review all transactions monthly
- Requiring employees to self-certify compliance quarterly
Correct answer: Automated, ongoing review of controls and transactions in near real-time
Continuous monitoring uses automated tools to review controls and data on an ongoing basis, enabling faster detection of issues than periodic reviews.
Question 7: A compliance report identifies a 'material weakness.' According to internal control frameworks, what does this term mean?
- A minor deficiency that requires no escalation
- A significant deficiency that has a reasonable possibility of resulting in a material misstatement (Correct answer)
- A control that is strong but underutilized
- An issue limited to IT systems only
Correct answer: A significant deficiency that has a reasonable possibility of resulting in a material misstatement
A material weakness is a deficiency, or combination of deficiencies, in internal control such that there is a reasonable possibility of a material misstatement in financial statements.
A compliance officer discovers that a key control has been failing silently for 60 days with no alert generated.
What does this scenario most likely indicate?