CRO Regulatory Compliance & Corporate Policies 2 — Questions and Answers
Question 1: Under the Dodd-Frank Act, which entity is responsible for overseeing systemic risk in the U.S. financial system?
- Financial Stability Oversight Council (FSOC) (Correct answer)
- Office of the Comptroller of the Currency (OCC)
- Consumer Financial Protection Bureau (CFPB)
- Federal Deposit Insurance Corporation (FDIC)
Correct answer: Financial Stability Oversight Council (FSOC)
FSOC was created by Dodd-Frank to identify and respond to systemic risks threatening U.S. financial stability.
Question 2: A company's compliance policy requires annual AML training. An employee misses the deadline by one week due to a medical leave. What is the most appropriate CRO response?
- Apply a policy exception with documented justification and a remediation deadline (Correct answer)
- Terminate the employee for non-compliance
- Waive the requirement permanently due to medical circumstances
- Report the employee to the regulator immediately
Correct answer: Apply a policy exception with documented justification and a remediation deadline
Policy exceptions with documentation and remediation timelines are standard practice for isolated, justified compliance gaps.
Question 3: Which Basel III pillar specifically addresses market discipline through public disclosure requirements?
- Pillar 3 (Correct answer)
- Pillar 1
- Pillar 2
- Pillar 4
Correct answer: Pillar 3
Pillar 3 of Basel III requires banks to publicly disclose risk exposure and capital adequacy information to enable market discipline.
Question 4: When a CRO discovers that a business unit has been circumventing a key internal control, what should be the FIRST action?
- Escalate to senior management and the audit committee (Correct answer)
- Publicly disclose the breach immediately
- Discipline the business unit head without further investigation
- Modify the control to match current practice
Correct answer: Escalate to senior management and the audit committee
Circumvention of key controls is a governance failure requiring immediate escalation to senior management and the audit committee before other actions.
Question 5: The Volcker Rule under Dodd-Frank primarily restricts which activity for banking entities?
- Proprietary trading and certain hedge fund/PE fund sponsorship (Correct answer)
- Mortgage lending to subprime borrowers
- Cross-border currency transactions
- Consumer deposit insurance coverage
Correct answer: Proprietary trading and certain hedge fund/PE fund sponsorship
The Volcker Rule prohibits banking entities from engaging in proprietary trading and limits their relationships with hedge funds and private equity funds.
Question 6: Under GDPR, what is the maximum fine for the most serious violations?
- €20 million or 4% of annual global turnover, whichever is higher (Correct answer)
- €10 million or 2% of annual global turnover, whichever is higher
- $50 million flat penalty regardless of revenue
- €5 million or 1% of EU revenue, whichever is lower
Correct answer: €20 million or 4% of annual global turnover, whichever is higher
GDPR's highest tier of fines reaches €20 million or 4% of total worldwide annual turnover, whichever is greater.
Question 7: A 'three lines of defense' model assigns compliance functions primarily to which line?
- Second line (risk management and compliance functions) (Correct answer)
- First line (business operations)
- Third line (internal audit)
- Fourth line (external regulators)
Correct answer: Second line (risk management and compliance functions)
In the three lines of defense model, the second line comprises risk management and compliance functions that oversee and challenge the first line.
Under the Dodd-Frank Act, which entity is responsible for overseeing systemic risk in the U.S. financial system?