CORES Regulatory Compliance & Industry Standards 5 β Questions and Answers
Question 1: Under the OCC's Heightened Standards for large banks (12 CFR Part 30, Appendix D), front-line units are PRIMARILY responsible for:
- Setting the bank's risk appetite and tolerance limits
- Owning and managing risks within their business activities (Correct answer)
- Providing independent oversight of risk management practices
- Approving all new product risk assessments
Correct answer: Owning and managing risks within their business activities
Under OCC Heightened Standards, front-line units own and manage the risks inherent in their business activities as the first line of defense.
Question 2: Which of the following is NOT a required element of a Suspicious Activity Report (SAR) filing under FinCEN regulations?
- Description of the suspicious activity
- Identity of the subject when known
- The filing institution's assessment of criminal intent (Correct answer)
- Dollar amount involved in the transaction
Correct answer: The filing institution's assessment of criminal intent
SAR filers are not required toβand generally should notβopine on criminal intent; they report facts and why the activity is suspicious.
Question 3: An operational risk manager is reviewing a new product approval process. Which regulatory guidance BEST supports requiring a formal risk assessment before product launch?
- OCC Bulletin 2013-29 on Third-Party Risk Management
- OCC Bulletin 2017-43 on New, Modified, or Expanded Bank Products and Services (Correct answer)
- FDIC Financial Institution Letter 2021-27 on Crypto Assets
- Federal Reserve SR 12-17 on Incentive Compensation
Correct answer: OCC Bulletin 2017-43 on New, Modified, or Expanded Bank Products and Services
OCC Bulletin 2017-43 specifically addresses risk management expectations for new, modified, or expanded bank products and services.
Question 4: The 'comply or explain' principle found in many corporate governance codes requires that companies:
- Comply with all provisions or face automatic regulatory penalties
- Either follow the code's provisions or publicly disclose and explain any departures (Correct answer)
- Submit annual attestations to regulators confirming full compliance
- Apply all governance requirements regardless of company size
Correct answer: Either follow the code's provisions or publicly disclose and explain any departures
Under 'comply or explain,' companies that deviate from governance code provisions must publicly explain their rationale, providing market transparency.
Question 5: A bank receives a matter requiring attention (MRA) from its primary regulator citing weaknesses in its operational risk framework. The MOST appropriate immediate response is to:
- Contest the MRA finding formally before taking any corrective action
- Develop a detailed remediation plan with milestones and present it to the regulator (Correct answer)
- Transfer the responsible compliance officer to another department
- Implement temporary controls and defer a formal response until the next exam cycle
Correct answer: Develop a detailed remediation plan with milestones and present it to the regulator
MRAs require a timely, substantive remediation plan with defined milestones submitted to the regulator demonstrating the bank's commitment to corrective action.
Question 6: Which component of the Basel II/III framework addresses market discipline through public disclosure requirements?
- Pillar 1 β Minimum Capital Requirements
- Pillar 2 β Supervisory Review Process
- Pillar 3 β Market Discipline (Correct answer)
- Pillar 4 β Leverage Ratio
Correct answer: Pillar 3 β Market Discipline
Basel Pillar 3 requires banks to publicly disclose risk, capital, and governance information to enable market participants to assess institutional soundness.
Question 7: The USA PATRIOT Act Section 326 'Customer Identification Program' (CIP) rule requires financial institutions to verify customer identity at account opening using which minimum information elements?
- Name, date of birth, address, and identification number (Correct answer)
- Name, employment status, income, and credit score
- Name, address, phone number, and email
- Name, Social Security number, and biometric data
Correct answer: Name, date of birth, address, and identification number
CIP rules require collection and verification of name, date of birth, address, and an identification number (e.g., SSN for U.S. persons) for individual customers.
Under the OCC's Heightened Standards for large banks (12 CFR Part 30, Appendix D), front-line units are PRIMARILY responsible for: