Regulatory Compliance Basics Flashcards
7 cards from real General practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Regulatory Compliance Basics flashcards as text
What is 'anti-bribery compliance' designed to prevent?
Answer: Offering or accepting anything of value to improperly influence a business or government decision
Anti-bribery compliance programs are designed to prevent the offering, promising, giving, or accepting of bribes to gain an improper business advantage.
Which document outlines a company's expectations for employee behavior and ethical conduct?
Answer: A code of conduct or code of ethics
A code of conduct or code of ethics formally articulates the values, principles, and behavioral standards the organization expects from all employees.
What is 'third-party risk management' in compliance?
Answer: Identifying, assessing, and mitigating risks arising from relationships with vendors, partners, and suppliers
Third-party risk management involves evaluating and monitoring external parties to ensure they do not create legal, financial, or reputational risks for your organization.
Under the Health Insurance Portability and Accountability Act (HIPAA), which information is considered Protected Health Information (PHI)?
Answer: Any individually identifiable health information held or transmitted by a covered entity
PHI under HIPAA is any individually identifiable health information that relates to a person's past, present, or future physical or mental health condition, treatment, or payment for care.
What is the significance of 'materiality' in compliance and financial reporting?
Answer: Information is material if its omission or misstatement could influence the decisions of a reasonable user
Materiality is a threshold concept that determines whether information is significant enough that failing to disclose it would mislead stakeholders making decisions.
Which of the following is an example of a 'preventive control' in a compliance program?
Answer: Requiring dual authorization for large financial transactions before they are processed
Preventive controls are designed to deter or stop compliance violations before they occur, such as requiring two approvals to reduce the risk of unauthorized transactions.
What is 'record retention' in the context of regulatory compliance?
Answer: The practice of keeping business records for specified periods as required by law or regulation
Record retention refers to the policies and procedures that govern how long an organization must keep certain documents to meet legal, regulatory, or business requirements.