Internal Controls & Compliance Flashcards
7 cards from real CBA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Internal Controls & Compliance flashcards as text
What is the MOST significant limitation of relying solely on preventive controls in a bank's internal control framework?
Answer: They cannot detect errors or fraud that circumvent or override the prevention mechanism
Preventive controls reduce the likelihood of errors or fraud occurring, but detective controls are also needed to identify issues that bypass preventive measures.
Under the Bank Secrecy Act, a Currency Transaction Report (CTR) must be filed for cash transactions exceeding:
Answer: $10,000 in a single day
CTRs must be filed with FinCEN for each cash transaction (deposit, withdrawal, or exchange) exceeding $10,000 conducted by or on behalf of the same person in a single business day.
An auditor discovers that loan officers are encouraged to help customers 'structure' their loan applications to meet underwriting criteria. This practice MOST likely violates:
Answer: Regulation B and safe and sound lending standards
Coaching applicants to misrepresent their financial information constitutes application fraud and violates Regulation B's prohibition on discriminatory or deceptive credit practices.
In the context of model risk management (SR 11-7), what is the primary purpose of model validation?
Answer: To independently verify that models are conceptually sound and performing as intended
Model validation, per SR 11-7, provides independent assessment of model conceptual soundness, performance, and ongoing monitoring to identify weaknesses.
Which of the following scenarios represents 'structuring' under the Bank Secrecy Act?
Answer: A customer making multiple cash deposits of $9,000 each to avoid CTR filing requirements
Structuring is the illegal practice of breaking up transactions into smaller amounts specifically to evade the $10,000 CTR reporting threshold.
A bank's internal audit function discovers that management has implemented a compensating control to address a control weakness. The auditor should:
Answer: Evaluate whether the compensating control is effective enough to adequately mitigate the residual risk
Auditors must assess whether compensating controls actually reduce risk to an acceptable level before adjusting finding severity or closing the issue.
Which of the following BEST describes the concept of 'risk appetite' in a bank's compliance framework?
Answer: The amount and type of compliance risk the bank is willing to accept in pursuit of its objectives
Risk appetite defines the level and types of risk the bank's board is willing to tolerate, guiding decision-making and compliance risk management strategies.