Regulatory and Compliance Standards Flashcards
7 cards from real CRA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Regulatory and Compliance Standards flashcards as text
Under the Sarbanes-Oxley Act, which section requires management to assess and report on the effectiveness of internal controls over financial reporting (ICFR)?
Answer: Section 404
SOX Section 404 mandates that management assess ICFR effectiveness annually, and requires external auditors to attest to that assessment.
Which regulatory body oversees the enforcement of the Foreign Corrupt Practices Act (FCPA) for securities-related violations?
Answer: Securities and Exchange Commission (SEC)
The SEC enforces FCPA's anti-bribery and accounting provisions for issuers of securities, while the DOJ handles criminal enforcement.
The FFIEC Cybersecurity Assessment Tool (CAT) maps to which NIST framework as its primary reference?
Answer: NIST Cybersecurity Framework (CSF)
The FFIEC CAT aligns its maturity domains and assessment categories directly to the five core functions of the NIST Cybersecurity Framework.
Under HIPAA, what is the maximum civil monetary penalty per violation category for organizations that demonstrate willful neglect and fail to correct the violation?
Answer: $1,900,000
HIPAA's highest penalty tier—willful neglect not corrected—carries a maximum of $1.9 million per violation category per year (adjusted for inflation).
Which international standard provides a framework for establishing, implementing, and maintaining an Information Security Management System (ISMS)?
Answer: ISO 27001
ISO/IEC 27001 specifies requirements for an ISMS and is the globally recognized certification standard for information security management.
The COSO Enterprise Risk Management (ERM) framework was updated in 2017 to strengthen alignment with which strategic priority?
Answer: Strategy and performance
The 2017 COSO ERM update explicitly integrates risk management with strategy-setting and performance measurement across the enterprise.
A firm subject to the EU's Markets in Financial Instruments Directive II (MiFID II) must record and retain telephone conversations and electronic communications related to client orders for how long?
Answer: 5 years
MiFID II requires investment firms to retain recordings of client-order communications for a minimum of 5 years (up to 7 years if requested by a competent authority).