Regulatory Compliance & Audit Standards Flashcards
7 cards from real CVA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Regulatory Compliance & Audit Standards flashcards as text
A CVA is reviewing an organization's vendor due diligence process. Which regulatory framework is most directly relevant to third-party risk management for U.S. banks?
Answer: OCC Bulletin 2013-29 on Third-Party Relationships
OCC Bulletin 2013-29 provides comprehensive guidance to national banks on managing risks associated with third-party relationships.
Which of the following is the primary purpose of the 'reasonable procedures' standard under the FCRA Section 607(b)?
Answer: To ensure consumer reporting agencies follow maximum possible accuracy in their reports
FCRA Section 607(b) requires consumer reporting agencies to maintain reasonable procedures to ensure the maximum possible accuracy of the information in consumer reports.
In the context of employment verification, E-Verify is operated by which federal agencies?
Answer: Department of Homeland Security and Social Security Administration
E-Verify is operated by the Department of Homeland Security (DHS) in partnership with the Social Security Administration (SSA).
A CVA conducting an audit of a healthcare organization's credential verification process must ensure compliance with which accrediting body's standards for primary source verification?
Answer: The Joint Commission (TJC)
The Joint Commission requires healthcare organizations to conduct primary source verification of practitioner credentials as part of its accreditation standards.
When a verification reveals a material discrepancy in an applicant's reported credentials, the CVA's primary obligation is to:
Answer: Document the finding objectively and report it to the requesting party per established protocols
A CVA must objectively document discrepancies and report findings to the requesting party following established protocols, without personally confronting applicants or making judgment calls beyond the scope of the verification.
Under the Gramm-Leach-Bliley Act (GLBA), the Safeguards Rule requires financial institutions to:
Answer: Develop, implement, and maintain a comprehensive information security program
The GLBA Safeguards Rule requires covered financial institutions to implement a comprehensive written information security program to protect customer data.
Which type of audit opinion indicates that financial statements present fairly in all material respects in accordance with GAAP?
Answer: Unmodified (clean) opinion
An unmodified or 'clean' opinion is issued by an auditor when financial statements present fairly in all material respects in accordance with the applicable financial reporting framework.