CRO Regulatory Compliance & Corporate Policies 3 — Questions and Answers
Question 1: Which regulation requires U.S. public companies to maintain adequate internal controls over financial reporting and have management assess them annually?
- Sarbanes-Oxley Act Section 404 (Correct answer)
- Gramm-Leach-Bliley Act
- Bank Secrecy Act
- Fair Credit Reporting Act
Correct answer: Sarbanes-Oxley Act Section 404
SOX Section 404 mandates that management assess and report on the effectiveness of internal controls over financial reporting annually.
Question 2: An institution's written policies conflict with current regulatory guidance issued after policy creation. What is the CRO's priority action?
- Update policies to align with current regulatory guidance and notify affected staff (Correct answer)
- Continue operating under existing policies until the next scheduled review
- Request a regulatory exemption to maintain existing policies
- Only update policies if a regulator formally orders the change
Correct answer: Update policies to align with current regulatory guidance and notify affected staff
Regulatory guidance supersedes outdated internal policies; the CRO must update policies promptly and communicate changes to impacted personnel.
Question 3: Under the Bank Secrecy Act, a Suspicious Activity Report (SAR) must generally be filed within how many days of detecting a suspicious transaction?
- 30 calendar days (Correct answer)
- 10 business days
- 60 calendar days
- 90 business days
Correct answer: 30 calendar days
FinCEN requires SARs to be filed within 30 calendar days of the date the suspicious activity was initially detected.
Question 4: Which concept describes the risk that arises when a company's actions violate laws, regulations, or ethical standards, potentially damaging its reputation?
- Compliance risk (Correct answer)
- Credit risk
- Liquidity risk
- Settlement risk
Correct answer: Compliance risk
Compliance risk is the risk of legal or regulatory sanctions, material financial loss, or reputational harm from failure to comply with laws or standards.
Question 5: The Foreign Corrupt Practices Act (FCPA) prohibits U.S. companies from doing what?
- Bribing foreign government officials to obtain or retain business (Correct answer)
- Engaging in insider trading on foreign stock exchanges
- Importing goods produced with forced labor
- Operating in countries under U.S. trade sanctions
Correct answer: Bribing foreign government officials to obtain or retain business
The FCPA prohibits U.S. persons and businesses from bribing foreign officials for business advantage.
Question 6: A CRO is designing a compliance testing program. Which approach provides the most objective assessment of control effectiveness?
- Independent testing by compliance or internal audit, separate from the control owners (Correct answer)
- Self-assessment surveys completed by the business unit managing the controls
- External benchmarking against peer institutions only
- Automated monitoring without human review overlay
Correct answer: Independent testing by compliance or internal audit, separate from the control owners
Independent testing by parties separate from control owners provides the most objective and unbiased assessment of whether controls are operating effectively.
Question 7: Under U.S. consumer protection regulations, the 'UDAAP' standard prohibits which types of acts or practices?
- Unfair, deceptive, or abusive acts or practices (Correct answer)
- Unauthorized disclosure of account privacy data
- Unsolicited direct advertising and automated phone practices
- Underwriting discrimination against protected classes
Correct answer: Unfair, deceptive, or abusive acts or practices
UDAAP stands for Unfair, Deceptive, or Abusive Acts or Practices and is enforced by the CFPB against financial institutions.
Which regulation requires U.S. public companies to maintain adequate internal controls over financial reporting and have management assess them annually?