General Regulatory Compliance Basics 5 — Questions and Answers
Question 1: What is 'anti-bribery compliance' designed to prevent?
- Employees accepting unauthorized discounts from vendors
- Offering or accepting anything of value to improperly influence a business or government decision (Correct answer)
- Unauthorized use of company property
- Price-fixing agreements with competitors
Correct answer: Offering or accepting anything of value to improperly influence a business or government decision
Anti-bribery compliance programs are designed to prevent the offering, promising, giving, or accepting of bribes to gain an improper business advantage.
Question 2: Which document outlines a company's expectations for employee behavior and ethical conduct?
- An employee benefits handbook
- A code of conduct or code of ethics (Correct answer)
- A standard operating procedure manual
- A collective bargaining agreement
Correct answer: A code of conduct or code of ethics
A code of conduct or code of ethics formally articulates the values, principles, and behavioral standards the organization expects from all employees.
Question 3: What is 'third-party risk management' in compliance?
- Managing risks from natural disasters and accidents
- Identifying, assessing, and mitigating risks arising from relationships with vendors, partners, and suppliers (Correct answer)
- Evaluating risks faced by customers purchasing your products
- Analyzing competitor business practices
Correct answer: Identifying, assessing, and mitigating risks arising from relationships with vendors, partners, and suppliers
Third-party risk management involves evaluating and monitoring external parties to ensure they do not create legal, financial, or reputational risks for your organization.
Question 4: Under the Health Insurance Portability and Accountability Act (HIPAA), which information is considered Protected Health Information (PHI)?
- General health statistics published in medical journals
- Any individually identifiable health information held or transmitted by a covered entity (Correct answer)
- Anonymized patient data used for medical research
- Health information shared publicly by patients themselves on social media
Correct answer: Any individually identifiable health information held or transmitted by a covered entity
PHI under HIPAA is any individually identifiable health information that relates to a person's past, present, or future physical or mental health condition, treatment, or payment for care.
Question 5: What is the significance of 'materiality' in compliance and financial reporting?
- It refers to the physical materials used in manufacturing
- Information is material if its omission or misstatement could influence the decisions of a reasonable user (Correct answer)
- It describes the durability of compliance documentation
- It determines which employees must complete compliance training
Correct answer: Information is material if its omission or misstatement could influence the decisions of a reasonable user
Materiality is a threshold concept that determines whether information is significant enough that failing to disclose it would mislead stakeholders making decisions.
Question 6: Which of the following is an example of a 'preventive control' in a compliance program?
- Conducting a post-incident investigation after a data breach
- Issuing disciplinary action following a policy violation
- Requiring dual authorization for large financial transactions before they are processed (Correct answer)
- Preparing a report analyzing past compliance failures
Correct answer: Requiring dual authorization for large financial transactions before they are processed
Preventive controls are designed to deter or stop compliance violations before they occur, such as requiring two approvals to reduce the risk of unauthorized transactions.
Question 7: What is 'record retention' in the context of regulatory compliance?
- The process of hiring and retaining compliance staff
- The practice of keeping business records for specified periods as required by law or regulation (Correct answer)
- Storing only digital copies of important documents
- Destroying records annually to protect sensitive information
Correct answer: The practice of keeping business records for specified periods as required by law or regulation
Record retention refers to the policies and procedures that govern how long an organization must keep certain documents to meet legal, regulatory, or business requirements.
What is 'anti-bribery compliance' designed to prevent?