← All CRA Flashcard Decks

Regulatory and Compliance Standards Flashcards

7 cards from real CRA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Regulatory and Compliance Standards flashcards as text
  1. Under the Office of Foreign Assets Control (OFAC) regulations, which legal standard holds a company strictly liable for sanctions violations even if it had no knowledge of the prohibited transaction?

    Answer: Strict liability

    OFAC applies strict liability for civil violations, meaning companies can be penalized regardless of intent or knowledge of the sanctioned transaction.

  2. Which section of the Dodd-Frank Act created the Financial Stability Oversight Council (FSOC) to identify and respond to systemic risks to U.S. financial stability?

    Answer: Title I

    Title I of the Dodd-Frank Act established FSOC and authorized it to designate nonbank financial companies as systemically important financial institutions (SIFIs).

  3. Which risk assessment methodology, commonly used in compliance programs, evaluates risks based on the product of likelihood and impact to produce a residual risk score?

    Answer: Risk matrix (heat map)

    A risk matrix multiplies likelihood by impact scores to plot residual risks on a heat map, enabling prioritization of compliance controls.

  4. The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requires financial institutions to implement a comprehensive information security program. Which federal regulator enforces this rule for non-banking financial companies?

    Answer: FTC

    The FTC enforces the GLBA Safeguards Rule for financial institutions not subject to the authority of a federal banking regulator, such as mortgage brokers and auto dealers.

  5. A Certified Risk Architect reviewing model risk under SR 11-7 guidance would classify a model as high risk based primarily on which factor?

    Answer: The materiality and breadth of decisions the model influences

    SR 11-7 defines model risk tiers primarily by the scope and materiality of business decisions driven by model outputs, not technical characteristics.

  6. Under the EU's Digital Operational Resilience Act (DORA), financial entities must report major ICT-related incidents to competent authorities within what initial timeframe?

    Answer: 24 hours

    DORA requires an initial notification to competent authorities within 24 hours of classifying an incident as major, followed by an intermediate report within 72 hours.

  7. Which component of the three lines of defense model is responsible for providing independent assurance over the effectiveness of risk management and internal controls?

    Answer: Internal audit (third line)

    The third line—internal audit—provides independent, objective assurance to the board and senior management on the effectiveness of governance, risk, and control processes.