← All CSCP Flashcard Decks

Compliance Programs & Risk Management Flashcards

7 cards from real CSCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Compliance Programs & Risk Management flashcards as text
  1. A compliance officer at a dually registered firm (broker-dealer and investment adviser) must be aware that which regulatory body has primary jurisdiction over the investment adviser side of the business?

    Answer: SEC or state securities regulators, depending on AUM

    Investment advisers are regulated by the SEC if they have $110 million or more in AUM (or meet other federal thresholds), or by state securities regulators below that threshold — not by FINRA, which regulates broker-dealers.

  2. Which of the following scenarios represents a 'compliance culture' failure rather than a procedural gap?

    Answer: Senior management actively discourages escalation of compliance concerns to avoid business disruption

    When senior management discourages escalation, the firm's tone-at-the-top undermines compliance culture — this is a culture failure, as opposed to a documentation or process deficiency.

  3. What is the primary purpose of a Suspicious Activity Report (SAR) filed by a broker-dealer?

    Answer: To alert FinCEN of transactions that may involve money laundering or other financial crimes

    SARs are filed with FinCEN (via the BSA E-Filing System) to report transactions that a broker-dealer knows, suspects, or has reason to suspect involve money laundering, tax evasion, or other financial crimes.

  4. In conducting a compliance risk assessment, which approach involves assigning numeric values to the probability and severity of risks to produce a ranked list?

    Answer: Quantitative risk assessment

    Quantitative risk assessment assigns numerical scores or monetary values to likelihood and impact, producing ranked risk scores, while qualitative assessment uses descriptive categories like 'high/medium/low.'

  5. Under FINRA Rule 3110, branch office inspections must be conducted at what minimum frequency for non-OSJ branch offices with one or more registered persons?

    Answer: Annually

    FINRA Rule 3110 requires firms to inspect non-OSJ branch offices with at least one registered person on an annual basis, while OSJs must also be inspected annually.

  6. A compliance officer is designing a new escalation policy for potential violations. Which feature is most critical to include to protect whistleblowers within the firm?

    Answer: Non-retaliation provisions for good-faith reporting of concerns

    Non-retaliation provisions are essential to encourage good-faith reporting and are required under laws like the Dodd-Frank Act, which prohibits retaliation against employees who report securities law violations.

  7. Which of the following is the most accurate description of a compliance program 'testing' function?

    Answer: Independently verifying that controls are operating as designed and detecting violations

    The compliance testing function independently evaluates whether controls are actually working as intended — it is distinct from training, policy drafting, or reviewing external exam reports.