Regulatory Frameworks & Compliance Flashcards
7 cards from real Certified Internal Auditor practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Regulatory Frameworks & Compliance flashcards as text
A company subject to HIPAA discovers that a business associate transmitted protected health information without authorization. Who bears primary regulatory responsibility?
Answer: Both the covered entity and the business associate
Under the HIPAA Omnibus Rule, both covered entities and their business associates can be held directly liable for HIPAA violations.
Which of the following best describes the purpose of a compliance risk assessment?
Answer: To identify and prioritize areas where regulatory violations are most likely
A compliance risk assessment systematically identifies, evaluates, and prioritizes the organization's exposure to regulatory and legal violations.
Under the Dodd-Frank Act, which agency was created to oversee consumer financial protection?
Answer: CFPB
The Consumer Financial Protection Bureau (CFPB) was established by Dodd-Frank to regulate consumer financial products and enforce consumer protection laws.
An internal auditor is evaluating a compliance training program. Which metric is most useful for assessing training effectiveness?
Answer: Pre- and post-training knowledge assessment scores
Pre- and post-training assessments measure actual knowledge gained, making them the most direct indicator of training effectiveness.
The three lines of defense model assigns compliance monitoring as a primary responsibility of which line?
Answer: Second line (compliance and risk functions)
The second line of defense includes compliance and risk management functions responsible for establishing policies and monitoring adherence.
Which anti-money laundering requirement mandates that financial institutions verify the identity of beneficial owners of legal entity customers?
Answer: Customer Due Diligence (CDD) Rule
FinCEN's Customer Due Diligence Rule requires financial institutions to identify and verify beneficial owners (≥25% ownership) of legal entity customers.
When assessing regulatory compliance, an internal auditor should give the highest priority to regulations that:
Answer: Carry the most significant penalties for non-compliance
A risk-based approach prioritizes regulations with the most severe consequences (fines, criminal penalties, license revocation) for non-compliance.