Certified Internal Auditor Regulatory Frameworks & Compliance 3 — Questions and Answers
Question 1: A company subject to HIPAA discovers that a business associate transmitted protected health information without authorization. Who bears primary regulatory responsibility?
- The business associate only
- The covered entity only
- Both the covered entity and the business associate (Correct answer)
- The US Department of Labor
Correct answer: Both the covered entity and the business associate
Under the HIPAA Omnibus Rule, both covered entities and their business associates can be held directly liable for HIPAA violations.
Question 2: Which of the following best describes the purpose of a compliance risk assessment?
- To rank employees by their compliance knowledge
- To identify and prioritize areas where regulatory violations are most likely (Correct answer)
- To replace internal audit's annual risk assessment
- To satisfy external auditor requirements
Correct answer: To identify and prioritize areas where regulatory violations are most likely
A compliance risk assessment systematically identifies, evaluates, and prioritizes the organization's exposure to regulatory and legal violations.
Question 3: Under the Dodd-Frank Act, which agency was created to oversee consumer financial protection?
- FDIC
- OCC
- CFPB (Correct answer)
- CFTC
Correct answer: CFPB
The Consumer Financial Protection Bureau (CFPB) was established by Dodd-Frank to regulate consumer financial products and enforce consumer protection laws.
Question 4: An internal auditor is evaluating a compliance training program. Which metric is most useful for assessing training effectiveness?
- Number of training hours completed
- Employee satisfaction scores
- Pre- and post-training knowledge assessment scores (Correct answer)
- Number of employees enrolled
Correct answer: Pre- and post-training knowledge assessment scores
Pre- and post-training assessments measure actual knowledge gained, making them the most direct indicator of training effectiveness.
Question 5: The three lines of defense model assigns compliance monitoring as a primary responsibility of which line?
- First line (operational management)
- Second line (compliance and risk functions) (Correct answer)
- Third line (internal audit)
- External audit
Correct answer: Second line (compliance and risk functions)
The second line of defense includes compliance and risk management functions responsible for establishing policies and monitoring adherence.
Question 6: Which anti-money laundering requirement mandates that financial institutions verify the identity of beneficial owners of legal entity customers?
- Customer Due Diligence (CDD) Rule (Correct answer)
- Suspicious Activity Report (SAR) Rule
- Currency Transaction Report (CTR) Rule
- OFAC Screening Rule
Correct answer: Customer Due Diligence (CDD) Rule
FinCEN's Customer Due Diligence Rule requires financial institutions to identify and verify beneficial owners (≥25% ownership) of legal entity customers.
Question 7: When assessing regulatory compliance, an internal auditor should give the highest priority to regulations that:
- Were most recently enacted
- Carry the most significant penalties for non-compliance (Correct answer)
- Apply to the most employees
- Are most frequently tested by regulators
Correct answer: Carry the most significant penalties for non-compliance
A risk-based approach prioritizes regulations with the most severe consequences (fines, criminal penalties, license revocation) for non-compliance.
A company subject to HIPAA discovers that a business associate transmitted protected health information without authorization.
Who bears primary regulatory responsibility?