CVA Regulatory Compliance & Audit Standards 3 — Questions and Answers
Question 1: A CVA is reviewing an organization's vendor due diligence process. Which regulatory framework is most directly relevant to third-party risk management for U.S. banks?
- OCC Bulletin 2013-29 on Third-Party Relationships (Correct answer)
- NIST SP 800-53 Revision 5
- COSO ERM Framework 2017
- ISO 9001:2015
Correct answer: OCC Bulletin 2013-29 on Third-Party Relationships
OCC Bulletin 2013-29 provides comprehensive guidance to national banks on managing risks associated with third-party relationships.
Question 2: Which of the following is the primary purpose of the 'reasonable procedures' standard under the FCRA Section 607(b)?
- To require consumer reporting agencies to share data with law enforcement
- To ensure consumer reporting agencies follow maximum possible accuracy in their reports (Correct answer)
- To mandate real-time updating of all consumer records
- To prohibit the use of credit scores in tenant screening
Correct answer: To ensure consumer reporting agencies follow maximum possible accuracy in their reports
FCRA Section 607(b) requires consumer reporting agencies to maintain reasonable procedures to ensure the maximum possible accuracy of the information in consumer reports.
Question 3: In the context of employment verification, E-Verify is operated by which federal agencies?
- Department of Labor and IRS
- Department of Homeland Security and Social Security Administration (Correct answer)
- Department of Justice and EEOC
- CBP and USCIS only
Correct answer: Department of Homeland Security and Social Security Administration
E-Verify is operated by the Department of Homeland Security (DHS) in partnership with the Social Security Administration (SSA).
Question 4: A CVA conducting an audit of a healthcare organization's credential verification process must ensure compliance with which accrediting body's standards for primary source verification?
- OSHA
- The Joint Commission (TJC) (Correct answer)
- FINRA
- FinCEN
Correct answer: The Joint Commission (TJC)
The Joint Commission requires healthcare organizations to conduct primary source verification of practitioner credentials as part of its accreditation standards.
Question 5: When a verification reveals a material discrepancy in an applicant's reported credentials, the CVA's primary obligation is to:
- Immediately report the discrepancy to law enforcement
- Document the finding objectively and report it to the requesting party per established protocols (Correct answer)
- Confront the applicant directly to obtain an explanation
- Disregard the discrepancy if the applicant is otherwise qualified
Correct answer: Document the finding objectively and report it to the requesting party per established protocols
A CVA must objectively document discrepancies and report findings to the requesting party following established protocols, without personally confronting applicants or making judgment calls beyond the scope of the verification.
Question 6: Under the Gramm-Leach-Bliley Act (GLBA), the Safeguards Rule requires financial institutions to:
- Disclose all consumer data to federal regulators on demand
- Develop, implement, and maintain a comprehensive information security program (Correct answer)
- Share customer financial data freely among affiliated companies
- Obtain written consent before opening any new customer account
Correct answer: Develop, implement, and maintain a comprehensive information security program
The GLBA Safeguards Rule requires covered financial institutions to implement a comprehensive written information security program to protect customer data.
Question 7: Which type of audit opinion indicates that financial statements present fairly in all material respects in accordance with GAAP?
- Adverse opinion
- Disclaimer of opinion
- Qualified opinion
- Unmodified (clean) opinion (Correct answer)
Correct answer: Unmodified (clean) opinion
An unmodified or 'clean' opinion is issued by an auditor when financial statements present fairly in all material respects in accordance with the applicable financial reporting framework.
A CVA is reviewing an organization's vendor due diligence process.
Which regulatory framework is most directly relevant to third-party risk management for U.S. banks?