CSCP Compliance Programs & Risk Management 5 — Questions and Answers
Question 1: A compliance officer at a dually registered firm (broker-dealer and investment adviser) must be aware that which regulatory body has primary jurisdiction over the investment adviser side of the business?
- FINRA
- SEC or state securities regulators, depending on AUM (Correct answer)
- OCC
- FDIC
Correct answer: SEC or state securities regulators, depending on AUM
Investment advisers are regulated by the SEC if they have $110 million or more in AUM (or meet other federal thresholds), or by state securities regulators below that threshold — not by FINRA, which regulates broker-dealers.
Question 2: Which of the following scenarios represents a 'compliance culture' failure rather than a procedural gap?
- A firm's WSPs do not address a newly effective FINRA rule
- Senior management actively discourages escalation of compliance concerns to avoid business disruption (Correct answer)
- A registered representative's continuing education is 30 days overdue due to a system error
- A branch office lacks an updated copy of the firm's code of ethics
Correct answer: Senior management actively discourages escalation of compliance concerns to avoid business disruption
When senior management discourages escalation, the firm's tone-at-the-top undermines compliance culture — this is a culture failure, as opposed to a documentation or process deficiency.
Question 3: What is the primary purpose of a Suspicious Activity Report (SAR) filed by a broker-dealer?
- To notify the SEC of potential insider trading activity
- To alert FinCEN of transactions that may involve money laundering or other financial crimes (Correct answer)
- To report customer complaints about unsuitable recommendations to FINRA
- To disclose conflicts of interest to the broker-dealer's board
Correct answer: To alert FinCEN of transactions that may involve money laundering or other financial crimes
SARs are filed with FinCEN (via the BSA E-Filing System) to report transactions that a broker-dealer knows, suspects, or has reason to suspect involve money laundering, tax evasion, or other financial crimes.
Question 4: In conducting a compliance risk assessment, which approach involves assigning numeric values to the probability and severity of risks to produce a ranked list?
- Qualitative risk assessment
- Quantitative risk assessment (Correct answer)
- Scenario analysis
- Control self-assessment
Correct answer: Quantitative risk assessment
Quantitative risk assessment assigns numerical scores or monetary values to likelihood and impact, producing ranked risk scores, while qualitative assessment uses descriptive categories like 'high/medium/low.'
Question 5: Under FINRA Rule 3110, branch office inspections must be conducted at what minimum frequency for non-OSJ branch offices with one or more registered persons?
- Monthly
- Quarterly
- Annually (Correct answer)
- Every three years
Correct answer: Annually
FINRA Rule 3110 requires firms to inspect non-OSJ branch offices with at least one registered person on an annual basis, while OSJs must also be inspected annually.
Question 6: A compliance officer is designing a new escalation policy for potential violations. Which feature is most critical to include to protect whistleblowers within the firm?
- Mandatory reporting timelines of 48 hours for all issues
- Non-retaliation provisions for good-faith reporting of concerns (Correct answer)
- Requirement that all reports go through the direct supervisor first
- Limitation of reporting channels to the CCO only
Correct answer: Non-retaliation provisions for good-faith reporting of concerns
Non-retaliation provisions are essential to encourage good-faith reporting and are required under laws like the Dodd-Frank Act, which prohibits retaliation against employees who report securities law violations.
Question 7: Which of the following is the most accurate description of a compliance program 'testing' function?
- Reviewing regulatory examination reports from past years
- Independently verifying that controls are operating as designed and detecting violations (Correct answer)
- Training staff on updated policies and procedures
- Drafting new written supervisory procedures in response to rule changes
Correct answer: Independently verifying that controls are operating as designed and detecting violations
The compliance testing function independently evaluates whether controls are actually working as intended — it is distinct from training, policy drafting, or reviewing external exam reports.
A compliance officer at a dually registered firm (broker-dealer and investment adviser) must be aware that which regulatory body has primary jurisdiction over the investment adviser side of the business?