CCT Regulatory Frameworks & Compliance Standards 2 — Questions and Answers
Question 1: Which federal agency enforces the Bank Secrecy Act (BSA) and oversees anti-money laundering compliance for financial institutions?
- Securities and Exchange Commission (SEC)
- Financial Crimes Enforcement Network (FinCEN) (Correct answer)
- Federal Reserve Board (FRB)
- Office of the Comptroller of the Currency (OCC)
Correct answer: Financial Crimes Enforcement Network (FinCEN)
FinCEN, a bureau of the U.S. Treasury Department, administers and enforces the Bank Secrecy Act and AML regulations.
Question 2: Under the Sarbanes-Oxley Act, which section requires management to assess and report on the effectiveness of internal controls over financial reporting?
- Section 302
- Section 404 (Correct answer)
- Section 806
- Section 1107
Correct answer: Section 404
SOX Section 404 mandates that management assess internal controls over financial reporting and that external auditors attest to that assessment.
Question 3: The EU General Data Protection Regulation (GDPR) applies to U.S. companies under which circumstance?
- Only if the company has a physical office in an EU country
- When processing personal data of EU residents regardless of company location (Correct answer)
- Only when the company earns more than €10 million in EU revenue
- When the company employs EU citizens
Correct answer: When processing personal data of EU residents regardless of company location
GDPR has extraterritorial reach and applies to any organization processing personal data of EU residents, regardless of where the company is located.
Question 4: Which compliance framework specifically addresses payment card data security and is maintained by a council of major card brands?
- ISO 27001
- NIST Cybersecurity Framework
- PCI DSS (Correct answer)
- SOC 2
Correct answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) is maintained by the PCI Security Standards Council and governs protection of cardholder data.
Question 5: A company subject to HIPAA must provide patients access to their Protected Health Information (PHI) within how many days of a request?
- 15 days
- 30 days (Correct answer)
- 45 days
- 60 days
Correct answer: 30 days
HIPAA's Privacy Rule requires covered entities to provide individuals access to their PHI within 30 days of a request, with a possible 30-day extension.
Question 6: The Foreign Corrupt Practices Act (FCPA) prohibits which type of conduct by U.S. companies and their agents?
- Insider trading on foreign stock exchanges
- Bribing foreign government officials to obtain business (Correct answer)
- Importing goods from sanctioned countries
- Employing foreign nationals without work authorization
Correct answer: Bribing foreign government officials to obtain business
The FCPA prohibits U.S. persons and businesses from bribing foreign government officials to obtain or retain business.
Question 7: Which regulatory principle requires that compliance programs be proportional to the actual risks faced by an organization?
- Prescriptive compliance
- Risk-based approach (Correct answer)
- Zero-tolerance standard
- Strict liability framework
Correct answer: Risk-based approach
A risk-based approach tailors compliance resources and controls to the level and nature of risks the organization actually faces.
Which federal agency enforces the Bank Secrecy Act (BSA) and oversees anti-money laundering compliance for financial institutions?