CCT Compliance Monitoring & Reporting 4 — Questions and Answers
Question 1: A compliance officer preparing a board report should PRIMARILY focus on which type of information?
- Detailed transaction-level data from the past month
- Trending risk indicators, material exceptions, and corrective action status (Correct answer)
- A comprehensive list of all employees who completed training
- Technical descriptions of each monitoring tool used
Correct answer: Trending risk indicators, material exceptions, and corrective action status
Board reports should provide decision-relevant information such as risk trends, significant exceptions, and status of remediation rather than granular operational data.
Question 2: What does 'three lines of defense' mean in the context of compliance monitoring?
- Three separate legal entities each with their own compliance team
- Operational management, compliance/risk functions, and internal audit serving distinct oversight roles (Correct answer)
- Three annual audits conducted at different times of year
- Three regulators that each have oversight of the same institution
Correct answer: Operational management, compliance/risk functions, and internal audit serving distinct oversight roles
The three lines of defense model assigns ownership of controls to operational management (1st), oversight to compliance and risk functions (2nd), and independent assurance to internal audit (3rd).
Question 3: A compliance monitoring review finds that exception reports are generated but never reviewed. This represents which type of control failure?
- Design deficiency only
- Operating effectiveness failure (Correct answer)
- Preventive control absence
- Regulatory reporting gap
Correct answer: Operating effectiveness failure
When a control exists but is not actually performed as designed (reports generated but not reviewed), it is an operating effectiveness failure rather than a design issue.
Question 4: Which of the following is the BEST example of a preventive compliance control?
- Monthly reconciliation of account balances
- System-enforced transaction limits that block unauthorized amounts (Correct answer)
- Quarterly internal audit of loan files
- Annual review of the compliance program by external counsel
Correct answer: System-enforced transaction limits that block unauthorized amounts
Preventive controls stop violations before they occur; system-enforced limits block non-compliant transactions in real-time rather than detecting them after the fact.
Question 5: An organization is required to report its compliance program effectiveness to a federal regulator annually. Which document would MOST comprehensively satisfy this requirement?
- Employee training completion spreadsheet
- Comprehensive compliance management system (CMS) assessment report (Correct answer)
- IT security vulnerability scan
- Marketing expense report
Correct answer: Comprehensive compliance management system (CMS) assessment report
A CMS assessment report documents the organization's policies, training, monitoring, and corrective action processes, providing regulators with a full picture of program effectiveness.
Question 6: A 'gap analysis' in compliance monitoring compares which two elements?
- Budget versus actual spending on compliance activities
- Current state of controls versus required state under applicable regulations (Correct answer)
- Number of employees versus number of compliance officers
- Past audit findings versus current audit findings
Correct answer: Current state of controls versus required state under applicable regulations
A compliance gap analysis assesses where an organization currently stands against what regulations or standards require, identifying areas needing remediation.
Question 7: Under the Sarbanes-Oxley Act (SOX) Section 302, corporate executives must certify which of the following in quarterly and annual filings?
- That no employees have violated company policy during the period
- That they have reviewed the report and that internal controls are effective (Correct answer)
- That all customers have been notified of any material changes
- That the company's stock price accurately reflects its true value
Correct answer: That they have reviewed the report and that internal controls are effective
SOX Section 302 requires CEOs and CFOs to personally certify that they have reviewed SEC filings and that internal controls over financial reporting are effective.
A compliance officer preparing a board report should PRIMARILY focus on which type of information?