Regulatory Compliance Auditing Flashcards
7 cards from real CBA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Regulatory Compliance Auditing flashcards as text
Under the Truth in Savings Act (Regulation DD), when must a bank notify customers of changes to account terms that are adverse to the consumer?
Answer: At least 30 days before the effective date
Regulation DD requires banks to provide at least 30 days' advance notice before implementing changes to account terms that are adverse to the consumer.
A compliance auditor is evaluating a bank's third-party vendor risk management program. According to OCC guidance, who bears ultimate responsibility for ensuring vendor compliance with applicable laws?
Answer: The bank's board of directors and senior management
OCC guidance makes clear that the bank's board of directors and senior management retain ultimate responsibility for activities conducted by third-party vendors on the bank's behalf.
Which provision of the Volcker Rule most directly impacts a bank compliance auditor's review of trading activities?
Answer: Restrictions on proprietary trading and certain fund investments
The Volcker Rule prohibits banks from engaging in proprietary trading for their own account and restricts ownership interests in hedge funds and private equity funds.
An auditor reviewing mortgage loan files finds that the bank consistently failed to provide the Loan Estimate within 3 business days of receiving a loan application. Which regulation is violated?
Answer: Regulation Z (TRID)
Under TRID (TILA-RESPA Integrated Disclosure rules, Regulation Z), lenders must deliver the Loan Estimate within 3 business days of receiving a completed loan application.
What is the key difference between a 'compliance risk assessment' and a 'compliance audit' in a bank's compliance framework?
Answer: A risk assessment identifies and prioritizes potential compliance risks; an audit tests whether controls are operating effectively
A compliance risk assessment identifies and prioritizes risks before they occur, while a compliance audit evaluates whether existing controls are functioning effectively to mitigate those risks.
A bank's internal audit team discovers that the compliance department has not updated its BSA/AML policies since a major regulatory change 18 months ago. Which corrective action is MOST appropriate?
Answer: Issue a management letter requiring immediate policy updates and re-training
The appropriate corrective action is to issue a management letter or finding requiring the compliance department to update policies promptly and conduct staff retraining to address the gap.
Under the Gramm-Leach-Bliley Act (GLBA), what must a financial institution provide to consumers regarding their privacy policies?
Answer: An initial privacy notice at account opening and annual notices thereafter
GLBA's Privacy Rule requires financial institutions to provide consumers with an initial privacy notice at account opening and then annually thereafter as long as the relationship continues.