โ† All CSCP Flashcard Decks

Internal Controls & Auditing Flashcards

7 cards from real CSCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Internal Controls & Auditing flashcards as text
  1. In the context of a securities firm's internal controls, 'compensating controls' are best described as:

    Answer: Alternative controls that mitigate risk when primary controls cannot be implemented

    Compensating controls are alternative measures that reduce risk to an acceptable level when the preferred primary control is not feasible due to operational or cost constraints.

  2. Which of the following would be considered a 'control deficiency' in a broker-dealer's trade surveillance program?

    Answer: Alert review is performed by the same trader who executed the flagged transactions

    Having a trader review alerts for their own transactions creates a conflict of interest and eliminates the independence required for effective surveillance, constituting a control deficiency.

  3. An auditor testing a securities firm's order management controls would most likely use 're-performance' as an audit technique when:

    Answer: Independently executing the same control procedure to verify it produces the same results

    Re-performance involves the auditor independently executing a control procedure to determine whether it produces the same result as when performed by company personnel.

  4. FINRA's Annual Compliance Meeting requirement under Rule 3110 requires that each registered representative attend a compliance meeting or receive compliance information:

    Answer: Annually

    FINRA Rule 3110 requires that each registered representative participate in an annual compliance meeting to ensure ongoing awareness of regulatory requirements and firm policies.

  5. A securities firm's internal audit charter should NOT include which of the following elements?

    Answer: Specific audit findings from the most recent examination cycle

    The internal audit charter establishes the function's authority, independence, and scope, but specific audit findings belong in individual audit reports, not the charter itself.

  6. In a risk control self-assessment (RCSA) conducted at a broker-dealer, business line managers are asked to:

    Answer: Identify and evaluate risks and controls within their own business areas

    An RCSA is a process where business line managers identify key risks in their area and assess the adequacy of controls designed to mitigate those risks.

  7. During a gap assessment of a broker-dealer's AML controls, the auditor finds that the firm does not have a designated AML Compliance Officer. Under FinCEN regulations, this represents:

    Answer: A mandatory regulatory requirement violation that must be remediated immediately

    FinCEN regulations require all broker-dealers to designate an AML Compliance Officer as part of their mandatory written AML program; this is not optional regardless of firm size.