CRA Regulatory and Compliance Standards 3 — Questions and Answers
Question 1: Under the Sarbanes-Oxley Act, which section requires management to assess and report on the effectiveness of internal controls over financial reporting (ICFR)?
- Section 302
- Section 404 (Correct answer)
- Section 409
- Section 802
Correct answer: Section 404
SOX Section 404 mandates that management assess ICFR effectiveness annually, and requires external auditors to attest to that assessment.
Question 2: Which regulatory body oversees the enforcement of the Foreign Corrupt Practices Act (FCPA) for securities-related violations?
- Department of Justice (DOJ)
- Federal Trade Commission (FTC)
- Securities and Exchange Commission (SEC) (Correct answer)
- Office of Foreign Assets Control (OFAC)
Correct answer: Securities and Exchange Commission (SEC)
The SEC enforces FCPA's anti-bribery and accounting provisions for issuers of securities, while the DOJ handles criminal enforcement.
Question 3: The FFIEC Cybersecurity Assessment Tool (CAT) maps to which NIST framework as its primary reference?
- NIST SP 800-53
- NIST Cybersecurity Framework (CSF) (Correct answer)
- NIST SP 800-171
- NIST SP 800-37
Correct answer: NIST Cybersecurity Framework (CSF)
The FFIEC CAT aligns its maturity domains and assessment categories directly to the five core functions of the NIST Cybersecurity Framework.
Question 4: Under HIPAA, what is the maximum civil monetary penalty per violation category for organizations that demonstrate willful neglect and fail to correct the violation?
- $10,000
- $50,000
- $100,000
- $1,900,000 (Correct answer)
Correct answer: $1,900,000
HIPAA's highest penalty tier—willful neglect not corrected—carries a maximum of $1.9 million per violation category per year (adjusted for inflation).
Question 5: Which international standard provides a framework for establishing, implementing, and maintaining an Information Security Management System (ISMS)?
- ISO 9001
- ISO 22301
- ISO 27001 (Correct answer)
- ISO 31000
Correct answer: ISO 27001
ISO/IEC 27001 specifies requirements for an ISMS and is the globally recognized certification standard for information security management.
Question 6: The COSO Enterprise Risk Management (ERM) framework was updated in 2017 to strengthen alignment with which strategic priority?
- Operational efficiency metrics
- Strategy and performance (Correct answer)
- IT governance controls
- Internal audit independence
Correct answer: Strategy and performance
The 2017 COSO ERM update explicitly integrates risk management with strategy-setting and performance measurement across the enterprise.
Question 7: A firm subject to the EU's Markets in Financial Instruments Directive II (MiFID II) must record and retain telephone conversations and electronic communications related to client orders for how long?
- 1 year
- 3 years
- 5 years (Correct answer)
- 7 years
Correct answer: 5 years
MiFID II requires investment firms to retain recordings of client-order communications for a minimum of 5 years (up to 7 years if requested by a competent authority).
Under the Sarbanes-Oxley Act, which section requires management to assess and report on the effectiveness of internal controls over financial reporting (ICFR)?