CCT Compliance Monitoring & Reporting 3 — Questions and Answers
Question 1: A company's compliance dashboard shows 100% policy attestation completion but regulators still find widespread violations. What is the MOST likely explanation?
- Employees completed attestations without reading or understanding the policies (Correct answer)
- The compliance dashboard software has a technical error
- Regulators are applying incorrect standards
- Policy attestations are not a required compliance activity
Correct answer: Employees completed attestations without reading or understanding the policies
High attestation rates can be misleading if employees sign off without genuinely understanding policies, a phenomenon known as 'checkbox compliance.'
Question 2: Which regulatory body requires broker-dealers to file Form BD and maintain specific books and records under SEC Rule 17a-3?
- FDIC
- OCC
- FINRA/SEC (Correct answer)
- CFPB
Correct answer: FINRA/SEC
The SEC and FINRA regulate broker-dealers, requiring them to maintain books and records under SEC Rule 17a-3 and file registration forms including Form BD.
Question 3: In compliance monitoring, what is a 'key risk indicator' (KRI)?
- A metric that measures the cost of compliance activities
- A forward-looking metric that signals increasing exposure to a specific risk (Correct answer)
- A historical report of past compliance failures
- A list of all identified risks in the risk register
Correct answer: A forward-looking metric that signals increasing exposure to a specific risk
KRIs are forward-looking metrics that provide early warning signals when risk exposure is increasing, enabling proactive management.
Question 4: A compliance officer must escalate a potential FCPA violation discovered during monitoring. To whom should this be escalated FIRST according to best practice?
- The employee's direct supervisor
- Legal counsel and senior management or the board (Correct answer)
- The local media
- An external competitor
Correct answer: Legal counsel and senior management or the board
FCPA violations carry serious criminal and civil penalties, so they should be escalated immediately to legal counsel and senior management or the board for proper handling.
Question 5: What is the purpose of a 'testing calendar' in a compliance monitoring program?
- To schedule employee vacations around audit periods
- To ensure all controls are tested at defined intervals across the year (Correct answer)
- To track the dates of external regulatory examinations only
- To plan compliance training session dates
Correct answer: To ensure all controls are tested at defined intervals across the year
A testing calendar schedules when each control will be tested, ensuring consistent coverage and preventing gaps where controls go untested for extended periods.
Question 6: Under GDPR, if a personal data breach is likely to result in a risk to individuals' rights, within what timeframe must a controller notify the supervisory authority?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach that poses a risk to individuals.
Question 7: Which approach to compliance monitoring involves selecting a random sample of transactions to test, regardless of risk level?
- Risk-based sampling
- Statistical random sampling (Correct answer)
- Judgmental sampling
- Stratified sampling
Correct answer: Statistical random sampling
Statistical random sampling selects transactions randomly without regard to risk, giving every transaction an equal probability of selection.
A company's compliance dashboard shows 100% policy attestation completion but regulators still find widespread violations.
What is the MOST likely explanation?