CRA Regulatory Compliance & Ethical Standards 3 — Questions and Answers
Question 1: Which U.S. regulation prohibits banking entities from engaging in proprietary trading and restricts their investments in hedge funds and private equity funds?
- Glass-Steagall Act
- Volcker Rule (Dodd-Frank Section 619) (Correct answer)
- Bank Holding Company Act
- Community Reinvestment Act
Correct answer: Volcker Rule (Dodd-Frank Section 619)
The Volcker Rule, codified in Section 619 of Dodd-Frank, restricts banks from proprietary trading and limits investments in covered funds.
Question 2: An organization's code of ethics should be reviewed and updated at a minimum:
- Every five years or when major regulatory changes occur
- Annually or when significant business or regulatory changes occur (Correct answer)
- Only after a compliance violation is discovered
- Upon request by the board's audit committee
Correct answer: Annually or when significant business or regulatory changes occur
Best practice requires annual review of the code of ethics to ensure alignment with current regulations, business activities, and stakeholder expectations.
Question 3: Under COSO's Integrated Framework, 'tone at the top' is most directly associated with which component?
- Risk Assessment
- Control Activities
- Control Environment (Correct answer)
- Monitoring Activities
Correct answer: Control Environment
The Control Environment component encompasses leadership's commitment to integrity and ethical values, collectively referred to as 'tone at the top.'
Question 4: The FFIEC's guidance on IT risk management primarily addresses which type of institution?
- Insurance companies regulated by state commissions
- Federal and state-chartered financial institutions (Correct answer)
- Publicly traded technology companies
- Non-bank fintech startups only
Correct answer: Federal and state-chartered financial institutions
The Federal Financial Institutions Examination Council (FFIEC) issues guidance applicable to federally supervised banks, thrifts, and credit unions.
Question 5: A risk architect is asked to sign off on a model that has not been independently validated. The MOST appropriate response is to:
- Sign off conditionally with a caveat in the documentation
- Refuse to sign off and escalate the lack of validation to senior management (Correct answer)
- Request the model developer to self-validate
- Delay sign-off until the next scheduled review cycle
Correct answer: Refuse to sign off and escalate the lack of validation to senior management
Model risk management standards require independent validation; signing off without it would violate ethical and professional obligations and should be escalated.
Question 6: Which standard specifically governs anti-bribery and anti-corruption practices on an international basis?
- ISO 31000
- ISO 37001 (Correct answer)
- SOC 2 Type II
- NIST CSF
Correct answer: ISO 37001
ISO 37001 is the international standard that specifies requirements and provides guidance for establishing anti-bribery management systems.
Question 7: The 'three lines of defense' model assigns compliance monitoring as a primary responsibility of:
- The first line (business units)
- The second line (risk and compliance functions) (Correct answer)
- The third line (internal audit)
- The board of directors
Correct answer: The second line (risk and compliance functions)
In the three lines of defense model, the second line—comprising risk management and compliance functions—is responsible for oversight, monitoring, and advisory roles.
Which U.S. regulation prohibits banking entities from engaging in proprietary trading and restricts their investments in hedge funds and private equity funds?