CORES Regulatory Compliance & Industry Standards 3 — Questions and Answers
Question 1: Under the Dodd-Frank Act, the Consumer Financial Protection Bureau (CFPB) has supervisory authority over which type of institution?
- Only federally chartered credit unions
- Non-bank financial companies and large banks with assets over $10 billion (Correct answer)
- Community banks with assets under $1 billion only
- Foreign bank branches operating in the U.S.
Correct answer: Non-bank financial companies and large banks with assets over $10 billion
The CFPB supervises non-bank financial companies and depository institutions with assets exceeding $10 billion.
Question 2: ISO 31000:2018 defines risk as:
- The probability of a loss event exceeding a threshold
- The effect of uncertainty on objectives (Correct answer)
- A negative deviation from expected outcomes
- A threat to organizational assets
Correct answer: The effect of uncertainty on objectives
ISO 31000:2018 defines risk as 'the effect of uncertainty on objectives,' encompassing both positive and negative impacts.
Question 3: A bank's compliance program identifies that its third-party vendor lacks adequate AML controls. Under OCC guidance, the bank's PRIMARY obligation is to:
- Terminate the vendor contract immediately
- Conduct enhanced due diligence and require the vendor to remediate deficiencies (Correct answer)
- Report the vendor to FinCEN
- Absorb the vendor's AML responsibilities directly
Correct answer: Conduct enhanced due diligence and require the vendor to remediate deficiencies
OCC guidance on third-party risk requires banks to conduct enhanced due diligence and ensure vendors meet equivalent compliance standards.
Question 4: Which Basel Committee publication introduced the standardized approach for measuring operational risk capital under Basel III reforms (Basel IV)?
- Basel II Pillar 1 guidelines
- The Standardized Measurement Approach (SMA) finalization document (Correct answer)
- Basel I credit risk framework
- BCBS 239 on risk data aggregation
Correct answer: The Standardized Measurement Approach (SMA) finalization document
The Basel Committee finalized the Standardized Measurement Approach (SMA) in 2017 to replace internal models for operational risk capital.
Question 5: Under Regulation E, what is the maximum liability for a consumer who reports an unauthorized electronic funds transfer within 2 business days of learning of the loss?
- $500
- $50 (Correct answer)
- $0
- $1,000
Correct answer: $50
Regulation E caps consumer liability at $50 for unauthorized EFTs reported within 2 business days of discovery.
Question 6: The Three Lines of Defense model assigns which primary role to Internal Audit?
- Owning and managing risk on a day-to-day basis
- Designing and implementing risk controls
- Providing independent assurance to the board and senior management (Correct answer)
- Setting the organization's risk appetite
Correct answer: Providing independent assurance to the board and senior management
Internal Audit (third line) provides independent, objective assurance that controls designed and operated by the first and second lines are effective.
Question 7: The Sarbanes-Oxley Act Section 302 requires which of the following?
- External auditors to attest to internal control effectiveness over financial reporting
- CEO and CFO to personally certify the accuracy of financial statements (Correct answer)
- Banks to maintain capital buffers for operational risk
- Audit committees to include at least one financial expert
Correct answer: CEO and CFO to personally certify the accuracy of financial statements
SOX Section 302 requires the CEO and CFO to personally certify the accuracy and completeness of financial reports filed with the SEC.
Under the Dodd-Frank Act, the Consumer Financial Protection Bureau (CFPB) has supervisory authority over which type of institution?