RCC Legal and Regulatory Frameworks 1 — Questions and Answers
Question 1: Which regulation requires public companies to establish internal controls for financial reporting?
- HIPAA
- FCPA
- GDPR
- SOX (Correct answer)
Correct answer: SOX
The Sarbanes-Oxley Act of 2002 (SOX) is a federal law that mandated reforms to enhance corporate responsibility and improve financial disclosures. A key provision, particularly Section 404, requires public companies to establish and maintain internal controls over financial reporting. Management and external auditors must then report on the effectiveness of these controls to ensure accuracy and prevent fraud.
Question 2: What is the primary purpose of the Foreign Corrupt Practices Act (FCPA)?
- Prevent tax evasion
- Promote fair trade practices
- Prohibit bribery of foreign officials (Correct answer)
- Regulate internal hiring
Correct answer: Prohibit bribery of foreign officials
The Foreign Corrupt Practices Act (FCPA) was enacted to combat corruption in international business. Its primary purpose is to prohibit U.S. companies and individuals from bribing foreign government officials to obtain or retain business. This ensures fair competition and upholds ethical business practices globally, preventing illicit advantages.
Question 3: Which of the following is a key function of the Securities and Exchange Commission (SEC)?
- Enforce criminal law
- Issue patents
- Regulate financial disclosures by public companies (Correct answer)
- Manage labor disputes
Correct answer: Regulate financial disclosures by public companies
The Securities and Exchange Commission (SEC) is an independent federal agency tasked with protecting investors and maintaining fair and orderly securities markets. A key function is to regulate financial disclosures by public companies, requiring them to provide transparent and accurate information. This transparency helps investors make informed decisions and prevents fraudulent activities in the market.
Question 4: What is the focus of the General Data Protection Regulation (GDPR)?
- Cybersecurity enforcement
- Financial auditing
- Personal data protection (Correct answer)
- Trade regulation
Correct answer: Personal data protection
The General Data Protection Regulation (GDPR) is a comprehensive data privacy law from the European Union. Its main objective is to protect the personal data and privacy of EU citizens and residents. It sets strict rules for how organizations collect, process, and store personal information, giving individuals greater control over their data.
Question 5: What is a common penalty for non-compliance with regulatory laws?
- Award of a bonus
- Reduction in taxes
- Government subsidy
- Fines and legal action (Correct answer)
Correct answer: Fines and legal action
Non-compliance with regulatory laws can lead to significant penalties for individuals and organizations. The most common consequences include substantial fines imposed by regulatory bodies, which can vary based on the severity of the violation. Additionally, non-compliance can result in legal action, including civil lawsuits, criminal charges, and severe reputational damage.
Question 6: Which U.S. law is primarily focused on protecting patient medical information?
- SOX
- FCPA
- HIPAA (Correct answer)
- GDPR
Correct answer: HIPAA
The Health Insurance Portability and Accountability Act (HIPAA) is a U.S. federal law specifically designed to protect sensitive patient health information. It establishes national standards for healthcare providers, health plans, and other entities regarding the privacy and security of medical records. HIPAA ensures that patient data is handled confidentially and securely, preventing unauthorized disclosure.
Which regulation requires public companies to establish internal controls for financial reporting?