CGRC Compliance Programs 4 — Questions and Answers
Question 1: A company operates in 12 countries with varying local laws. What is the BEST approach to compliance program design?
- Apply the strictest single standard globally
- Use a core global framework with local adaptations for jurisdiction-specific requirements (Correct answer)
- Create entirely separate programs for each country
- Follow only the laws of the country of incorporation
Correct answer: Use a core global framework with local adaptations for jurisdiction-specific requirements
A core global framework with local adaptations balances consistency and efficiency with the need to meet jurisdiction-specific legal requirements.
Question 2: Which document typically serves as the ethical and behavioral foundation of a compliance program?
- The compliance risk assessment
- The code of conduct (Correct answer)
- The internal audit charter
- The regulatory inventory
Correct answer: The code of conduct
The code of conduct articulates the organization's values and expected behaviors, serving as the ethical foundation upon which all other compliance policies are built.
Question 3: What is the key difference between compliance monitoring and compliance auditing?
- Monitoring is done by regulators; auditing is done internally
- Monitoring is ongoing and continuous; auditing is periodic and formal (Correct answer)
- Monitoring focuses on financial data; auditing covers all areas
- Monitoring is preventive; auditing is corrective
Correct answer: Monitoring is ongoing and continuous; auditing is periodic and formal
Compliance monitoring is a continuous, ongoing activity that checks day-to-day compliance, while auditing is a periodic, formal, and systematic evaluation.
Question 4: An employee uses a compliance hotline to report alleged misconduct but later claims retaliation. Under the Dodd-Frank Act, which agency has enforcement authority over such retaliation claims for securities violations?
- Department of Justice
- Securities and Exchange Commission (Correct answer)
- Equal Employment Opportunity Commission
- Department of Labor
Correct answer: Securities and Exchange Commission
The SEC has enforcement authority over retaliation claims under the Dodd-Frank whistleblower protection provisions for securities-related violations.
Question 5: Which compliance program element is specifically designed to detect violations that have already occurred?
- Pre-employment screening
- Compliance monitoring and auditing (Correct answer)
- Employee training programs
- Policy dissemination
Correct answer: Compliance monitoring and auditing
Monitoring and auditing are detective controls designed to identify compliance violations after they occur, enabling corrective action.
Question 6: A healthcare organization must comply with both HIPAA and state privacy laws that are more stringent than HIPAA. What is the correct approach?
- Comply only with HIPAA as federal law preempts state law
- Comply with the more stringent state law requirements (Correct answer)
- Apply whichever law was enacted more recently
- Request a federal waiver from the state requirements
Correct answer: Comply with the more stringent state law requirements
HIPAA sets a floor, not a ceiling; state laws that are more protective of patient privacy than HIPAA are not preempted and must be followed.
Question 7: Which of the following is considered a 'leading indicator' of compliance program effectiveness?
- Number of regulatory enforcement actions received
- Percentage of high-risk employees completing targeted training (Correct answer)
- Total fines paid in the prior year
- Number of incidents reported to regulators
Correct answer: Percentage of high-risk employees completing targeted training
Leading indicators like targeted training completion rates measure preventive actions taken before problems occur, unlike lagging indicators that measure outcomes after violations.
A company operates in 12 countries with varying local laws.
What is the BEST approach to compliance program design?