Regulatory Compliance & Ethical Standards Flashcards
7 cards from real CRA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Regulatory Compliance & Ethical Standards flashcards as text
Which U.S. regulation prohibits banking entities from engaging in proprietary trading and restricts their investments in hedge funds and private equity funds?
Answer: Volcker Rule (Dodd-Frank Section 619)
The Volcker Rule, codified in Section 619 of Dodd-Frank, restricts banks from proprietary trading and limits investments in covered funds.
An organization's code of ethics should be reviewed and updated at a minimum:
Answer: Annually or when significant business or regulatory changes occur
Best practice requires annual review of the code of ethics to ensure alignment with current regulations, business activities, and stakeholder expectations.
Under COSO's Integrated Framework, 'tone at the top' is most directly associated with which component?
Answer: Control Environment
The Control Environment component encompasses leadership's commitment to integrity and ethical values, collectively referred to as 'tone at the top.'
The FFIEC's guidance on IT risk management primarily addresses which type of institution?
Answer: Federal and state-chartered financial institutions
The Federal Financial Institutions Examination Council (FFIEC) issues guidance applicable to federally supervised banks, thrifts, and credit unions.
A risk architect is asked to sign off on a model that has not been independently validated. The MOST appropriate response is to:
Answer: Refuse to sign off and escalate the lack of validation to senior management
Model risk management standards require independent validation; signing off without it would violate ethical and professional obligations and should be escalated.
Which standard specifically governs anti-bribery and anti-corruption practices on an international basis?
Answer: ISO 37001
ISO 37001 is the international standard that specifies requirements and provides guidance for establishing anti-bribery management systems.
The 'three lines of defense' model assigns compliance monitoring as a primary responsibility of:
Answer: The second line (risk and compliance functions)
In the three lines of defense model, the second line—comprising risk management and compliance functions—is responsible for oversight, monitoring, and advisory roles.