← All Certified Internal Auditor Flashcard Decks

Regulatory Frameworks & Compliance Flashcards

7 cards from real Certified Internal Auditor practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Regulatory Frameworks & Compliance flashcards as text
  1. Under the Sarbanes-Oxley Act, which section requires management to assess and report on the effectiveness of internal controls over financial reporting?

    Answer: Section 404

    Section 404 of SOX requires management to assess internal control over financial reporting and requires the external auditor to attest to that assessment.

  2. The COSO Internal Control–Integrated Framework identifies how many components of internal control?

    Answer: Five

    COSO's framework includes five components: Control Environment, Risk Assessment, Control Activities, Information & Communication, and Monitoring Activities.

  3. Which regulatory body enforces compliance with the Bank Secrecy Act (BSA) requirements for financial institutions in the US?

    Answer: FinCEN

    The Financial Crimes Enforcement Network (FinCEN) is the primary bureau administering and enforcing BSA compliance requirements.

  4. An internal auditor discovers that a company's compliance program lacks a formal process for employees to report violations anonymously. Which framework element is most deficient?

    Answer: Whistleblower Mechanisms

    An anonymous reporting mechanism (whistleblower hotline) is a fundamental element of an effective compliance program under DOJ/OIG guidance.

  5. Under GDPR, what is the maximum timeframe within which a data breach must be reported to the supervisory authority?

    Answer: 72 hours

    GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach.

  6. The Foreign Corrupt Practices Act (FCPA) prohibits US companies from bribing which category of individuals?

    Answer: Foreign government officials

    The FCPA's anti-bribery provisions prohibit payments to foreign government officials to obtain or retain business.

  7. Which framework provides guidance specifically for enterprise risk management and is considered an extension of the COSO Internal Control framework?

    Answer: COSO ERM

    COSO ERM (Enterprise Risk Management–Integrating with Strategy and Performance, 2017) extends COSO's internal control framework to address risk at an enterprise level.