Regulatory Compliance Audits Flashcards
7 cards from real CBA practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Regulatory Compliance Audits flashcards as text
A bank's compliance audit reveals that its flood insurance procedures do not include force-placing flood insurance within the required timeframe after a borrower's lapse in coverage. Under the Flood Disaster Protection Act, what is the required force-placement timeframe?
Answer: 45 days after sending notice of lapse
The Flood Disaster Protection Act requires lenders to force-place flood insurance if the borrower fails to obtain coverage within 45 days of the initial notice.
Which of the following is a key difference between a compliance risk assessment and a compliance audit?
Answer: A risk assessment identifies and prioritizes compliance risks, while an audit provides independent testing and verification of controls
Risk assessments identify and rank potential compliance exposures to guide audit focus, while audits independently test whether controls are operating effectively.
During a CRA compliance audit of a large bank, which performance test carries the greatest weight in the overall CRA rating?
Answer: The Lending test
For large banks, the Lending test carries the most weight in the overall CRA rating, reflecting that loans are the primary means by which banks help meet community credit needs.
An auditor reviewing a bank's vendor management program finds that a third-party processor handling credit card data has not been assessed for PCI DSS compliance. What is the primary compliance concern?
Answer: The bank retains responsibility for third-party PCI DSS compliance and could face card network penalties for the oversight
Card networks hold banks responsible for ensuring their service providers maintain PCI DSS compliance, and failure to assess vendor compliance exposes the bank to penalties.
Under the Truth in Savings Act (TISA) and Regulation DD, what disclosure is required when a bank offers a certificate of deposit with an early withdrawal penalty?
Answer: The amount or method of calculating the early withdrawal penalty must be disclosed at account opening
Regulation DD requires banks to disclose the amount of any early withdrawal penalty or the method used to calculate it as part of the initial account disclosures.
A compliance auditor is evaluating a bank's Unfair, Deceptive, or Abusive Acts or Practices (UDAAP) program. Which of the following scenarios most clearly constitutes an 'abusive' practice under Dodd-Frank?
Answer: A bank taking advantage of consumers' inability to understand a product's material risks
An abusive practice under Dodd-Frank includes taking unreasonable advantage of consumers' lack of understanding of the material risks or costs of a financial product.
When conducting a fair lending statistical analysis, an auditor compares loan approval rates between similarly qualified minority and non-minority applicants. This methodology is known as:
Answer: Disparate treatment analysis using matched-pair testing
Matched-pair testing (disparate treatment analysis) compares outcomes for applicants with substantially similar credit profiles across protected and non-protected classes.