Compliance Programs & Risk Management Flashcards
7 cards from real CSCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Compliance Programs & Risk Management flashcards as text
A compliance officer at a dually registered firm (broker-dealer and investment adviser) must be aware that which regulatory body has primary jurisdiction over the investment adviser side of the business?
Answer: SEC or state securities regulators, depending on AUM
Investment advisers are regulated by the SEC if they have $110 million or more in AUM (or meet other federal thresholds), or by state securities regulators below that threshold — not by FINRA, which regulates broker-dealers.
Which of the following scenarios represents a 'compliance culture' failure rather than a procedural gap?
Answer: Senior management actively discourages escalation of compliance concerns to avoid business disruption
When senior management discourages escalation, the firm's tone-at-the-top undermines compliance culture — this is a culture failure, as opposed to a documentation or process deficiency.
What is the primary purpose of a Suspicious Activity Report (SAR) filed by a broker-dealer?
Answer: To alert FinCEN of transactions that may involve money laundering or other financial crimes
SARs are filed with FinCEN (via the BSA E-Filing System) to report transactions that a broker-dealer knows, suspects, or has reason to suspect involve money laundering, tax evasion, or other financial crimes.
In conducting a compliance risk assessment, which approach involves assigning numeric values to the probability and severity of risks to produce a ranked list?
Answer: Quantitative risk assessment
Quantitative risk assessment assigns numerical scores or monetary values to likelihood and impact, producing ranked risk scores, while qualitative assessment uses descriptive categories like 'high/medium/low.'
Under FINRA Rule 3110, branch office inspections must be conducted at what minimum frequency for non-OSJ branch offices with one or more registered persons?
Answer: Annually
FINRA Rule 3110 requires firms to inspect non-OSJ branch offices with at least one registered person on an annual basis, while OSJs must also be inspected annually.
A compliance officer is designing a new escalation policy for potential violations. Which feature is most critical to include to protect whistleblowers within the firm?
Answer: Non-retaliation provisions for good-faith reporting of concerns
Non-retaliation provisions are essential to encourage good-faith reporting and are required under laws like the Dodd-Frank Act, which prohibits retaliation against employees who report securities law violations.
Which of the following is the most accurate description of a compliance program 'testing' function?
Answer: Independently verifying that controls are operating as designed and detecting violations
The compliance testing function independently evaluates whether controls are actually working as intended — it is distinct from training, policy drafting, or reviewing external exam reports.