CGRC Compliance Programs 5 — Questions and Answers
Question 1: What is the primary purpose of conducting a third-party compliance due diligence review before entering a business relationship?
- To negotiate better contract terms
- To identify and mitigate compliance risks the third party may introduce (Correct answer)
- To comply with import/export documentation requirements
- To satisfy investor relations requirements
Correct answer: To identify and mitigate compliance risks the third party may introduce
Third-party due diligence identifies compliance risks — such as FCPA violations, sanctions exposure, or data privacy risks — that could be introduced into the organization through the business relationship.
Question 2: Under the Foreign Corrupt Practices Act (FCPA), which defense allows a company to avoid liability for payments made to foreign officials?
- The business necessity defense
- Facilitating payments for routine governmental actions (limited exception) (Correct answer)
- The whistleblower defense
- The good faith reliance defense
Correct answer: Facilitating payments for routine governmental actions (limited exception)
The FCPA contains a narrow exception for facilitating payments made to expedite or secure the performance of routine, non-discretionary governmental actions.
Question 3: A compliance program's 'speak up' culture is BEST reinforced by which organizational practice?
- Requiring mandatory annual ethics certifications
- Leadership visibly acting on reports and protecting reporters from retaliation (Correct answer)
- Installing anonymous suggestion boxes
- Publishing disciplinary actions in company newsletters
Correct answer: Leadership visibly acting on reports and protecting reporters from retaliation
When leadership demonstrably acts on compliance reports and protects reporters from retaliation, employees gain confidence that speaking up is safe and worthwhile.
Question 4: Which element of a compliance program specifically addresses ensuring that disciplinary measures are applied consistently?
- The compliance risk assessment process
- The enforcement and discipline component (Correct answer)
- The compliance communications plan
- The regulatory horizon scanning process
Correct answer: The enforcement and discipline component
The enforcement and discipline component ensures that violations are consistently identified, investigated, and sanctioned, which deters future misconduct.
Question 5: An organization's compliance program review reveals that its policies have not been updated in three years despite several regulatory changes. This MOST directly indicates a failure in which program element?
- Training and communication
- Regulatory change management and policy maintenance (Correct answer)
- Internal reporting mechanisms
- Leadership commitment
Correct answer: Regulatory change management and policy maintenance
Regulatory change management ensures that policies and procedures are updated when laws or regulations change; failure to update reflects a breakdown in this process.
Question 6: Which of the following scenarios BEST illustrates 'willful blindness' in the context of compliance?
- An executive who was not present during a compliance briefing
- A manager who deliberately avoids learning about subordinates' questionable conduct (Correct answer)
- An employee who misunderstands a complex regulatory requirement
- A compliance officer who misses a regulatory deadline
Correct answer: A manager who deliberately avoids learning about subordinates' questionable conduct
Willful blindness occurs when a person deliberately avoids acquiring knowledge of facts that would make them aware of a legal violation, which courts treat similarly to actual knowledge.
Question 7: What is the recommended frequency for reviewing and updating a compliance program's risk assessment?
- Once every five years or when required by regulators
- At least annually and when significant business or regulatory changes occur (Correct answer)
- Only when a compliance violation has been identified
- Every quarter regardless of business changes
Correct answer: At least annually and when significant business or regulatory changes occur
Best practice calls for annual risk assessment reviews at minimum, with additional reviews triggered by significant regulatory, operational, or business model changes.
What is the primary purpose of conducting a third-party compliance due diligence review before entering a business relationship?