CRA Regulatory Compliance & Corporate Governance 3 — Questions and Answers
Question 1: The Bank Secrecy Act (BSA) requires financial institutions to file a Suspicious Activity Report (SAR) within how many calendar days of detecting a suspicious transaction?
- 15 days
- 30 days (Correct answer)
- 45 days
- 60 days
Correct answer: 30 days
Under BSA regulations, financial institutions must file a SAR within 30 calendar days of the initial detection of the suspicious activity.
Question 2: Which element of the COSO ERM 2017 framework reflects an organization's alignment of risk appetite with strategy?
- Governance and Culture
- Strategy and Objective-Setting (Correct answer)
- Review and Revision
- Information, Communication, and Reporting
Correct answer: Strategy and Objective-Setting
Strategy and Objective-Setting is the COSO ERM component where risk appetite is integrated into the strategic planning process.
Question 3: Under GDPR, a personal data breach must be reported to the relevant supervisory authority within:
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach, where feasible.
Question 4: A 'tone at the top' in corporate governance primarily refers to:
- The volume of compliance policies issued by the legal department
- The ethical culture and commitment to compliance demonstrated by senior leadership (Correct answer)
- The severity of penalties for policy violations
- The number of training sessions conducted annually
Correct answer: The ethical culture and commitment to compliance demonstrated by senior leadership
Tone at the top reflects senior leadership's visible commitment to ethical conduct and compliance, which shapes overall organizational culture.
Question 5: Which regulation requires U.S. broker-dealers and investment advisers to maintain adequate anti-money laundering programs?
- Regulation FD
- The USA PATRIOT Act (Correct answer)
- Investment Advisers Act of 1940
- Regulation Best Interest
Correct answer: The USA PATRIOT Act
The USA PATRIOT Act expanded BSA requirements to broker-dealers and other financial institutions, mandating AML program implementation.
Question 6: In a risk governance context, 'risk appetite' differs from 'risk tolerance' in that risk appetite is:
- The maximum risk that can be absorbed before insolvency
- The board-level statement of how much risk is acceptable in pursuit of objectives (Correct answer)
- The specific quantitative limit applied to individual risk exposures
- The residual risk after controls are applied
Correct answer: The board-level statement of how much risk is acceptable in pursuit of objectives
Risk appetite is a high-level, strategic statement set by the board, while risk tolerance represents the more specific acceptable deviation around objectives.
Question 7: Which governance document typically outlines the responsibilities, authority, and composition of the board of directors?
- Code of Conduct
- Corporate Charter (Articles of Incorporation)
- Board Charter (or Terms of Reference) (Correct answer)
- Compliance Manual
Correct answer: Board Charter (or Terms of Reference)
A Board Charter or Terms of Reference specifically defines the board's mandate, committee structure, roles, and operating procedures.
The Bank Secrecy Act (BSA) requires financial institutions to file a Suspicious Activity Report (SAR) within how many calendar days of detecting a suspicious transaction?