CORES Regulatory Compliance & Industry Standards 2 — Questions and Answers
Question 1: Under Basel III, what is the minimum Common Equity Tier 1 (CET1) capital ratio required for banks?
- 4.5% (Correct answer)
- 6.0%
- 8.0%
- 10.5%
Correct answer: 4.5%
Basel III sets the minimum CET1 capital ratio at 4.5% of risk-weighted assets.
Question 2: Which U.S. regulation requires financial institutions to maintain written information security programs to protect customer financial data?
- Sarbanes-Oxley Act
- Gramm-Leach-Bliley Act (GLBA) (Correct answer)
- Dodd-Frank Act
- Bank Secrecy Act
Correct answer: Gramm-Leach-Bliley Act (GLBA)
The GLBA Safeguards Rule mandates written information security programs for customer financial information.
Question 3: The Volcker Rule, implemented under Dodd-Frank, primarily restricts banks from engaging in which activity?
- Accepting demand deposits
- Proprietary trading and certain fund investments (Correct answer)
- Issuing subordinated debt
- Cross-border currency transactions
Correct answer: Proprietary trading and certain fund investments
The Volcker Rule prohibits banks from proprietary trading and from owning or sponsoring hedge funds or private equity funds.
Question 4: Under the COSO Enterprise Risk Management framework updated in 2017, which component focuses on the tone, culture, and oversight of an organization?
- Risk Assessment
- Governance & Culture (Correct answer)
- Control Activities
- Information & Communication
Correct answer: Governance & Culture
Governance & Culture is the first COSO ERM component, establishing the foundation for all risk management activities.
Question 5: Which regulatory body oversees the enforcement of the Bank Secrecy Act (BSA) for depository institutions in the United States?
- SEC
- CFTC
- FinCEN (Correct answer)
- FDIC
Correct answer: FinCEN
FinCEN (Financial Crimes Enforcement Network) is the primary BSA regulator and administrator.
Question 6: An operational risk compliance officer discovers that a business unit has been mis-categorizing loss events to avoid regulatory reporting thresholds. This is BEST addressed first by:
- Terminating the responsible employees immediately
- Escalating to the board audit committee and notifying regulators as required (Correct answer)
- Quietly correcting the records without disclosure
- Issuing a warning letter to the business unit manager
Correct answer: Escalating to the board audit committee and notifying regulators as required
Regulatory reporting violations require escalation to appropriate governance bodies and potential regulator notification per compliance obligations.
Question 7: The Payment Card Industry Data Security Standard (PCI DSS) applies primarily to organizations that:
- Process payroll for more than 500 employees
- Store, process, or transmit cardholder data (Correct answer)
- Operate cross-border wire transfer services
- Issue government-backed payment instruments
Correct answer: Store, process, or transmit cardholder data
PCI DSS requirements apply to any entity that stores, processes, or transmits cardholder data regardless of size.
Under Basel III, what is the minimum Common Equity Tier 1 (CET1) capital ratio required for banks?