OM Regulatory Compliance 2 — Questions and Answers
Question 1: Under the Sarbanes-Oxley Act (SOX), which section requires CEOs and CFOs to personally certify the accuracy of financial reports?
- Section 302 (Correct answer)
- Section 404
- Section 806
- Section 1107
Correct answer: Section 302
SOX Section 302 mandates that CEOs and CFOs personally certify the accuracy and completeness of financial reports filed with the SEC.
Question 2: An organization discovers a data breach affecting 600 individuals in California. Under CCPA, what is the maximum civil penalty per intentional violation?
- $2,500
- $7,500 (Correct answer)
- $15,000
- $25,000
Correct answer: $7,500
The CCPA imposes civil penalties of up to $7,500 per intentional violation and $2,500 per unintentional violation.
Question 3: Which federal agency enforces the Foreign Corrupt Practices Act (FCPA) related to accounting provisions?
- Department of Justice (DOJ)
- Securities and Exchange Commission (SEC) (Correct answer)
- Federal Trade Commission (FTC)
- Office of Foreign Assets Control (OFAC)
Correct answer: Securities and Exchange Commission (SEC)
The SEC enforces the FCPA's accounting and internal controls provisions, while the DOJ handles the anti-bribery provisions.
Question 4: A compliance officer is implementing a risk-based compliance program. Which approach BEST prioritizes regulatory risk management resources?
- Applying equal resources to all compliance areas regardless of risk level
- Focusing all resources on the highest-volume transactions
- Allocating resources proportionally based on likelihood and impact of violations (Correct answer)
- Prioritizing only areas that were previously cited in regulatory audits
Correct answer: Allocating resources proportionally based on likelihood and impact of violations
A risk-based compliance program allocates resources proportionally to the likelihood and potential impact of compliance failures, maximizing efficiency.
Question 5: Which of the following is a key requirement of the HIPAA Security Rule for organizations handling electronic Protected Health Information (ePHI)?
- Annual patient notification of all data access events
- Implementation of administrative, physical, and technical safeguards (Correct answer)
- Mandatory encryption of all paper records
- Real-time government reporting of all ePHI transactions
Correct answer: Implementation of administrative, physical, and technical safeguards
The HIPAA Security Rule requires covered entities to implement administrative, physical, and technical safeguards to protect ePHI.
Question 6: Under OSHA's General Duty Clause, employers are required to:
- Provide workers' compensation insurance to all employees
- Furnish a workplace free from recognized hazards likely to cause death or serious harm (Correct answer)
- Conduct quarterly safety audits certified by a third party
- Report all workplace injuries regardless of severity within 24 hours
Correct answer: Furnish a workplace free from recognized hazards likely to cause death or serious harm
OSHA's General Duty Clause (Section 5(a)(1)) requires employers to provide a workplace free from recognized hazards that could cause death or serious physical harm.
Question 7: An organization subject to the Americans with Disabilities Act (ADA) must provide reasonable accommodations unless doing so would cause:
- Any increase in operational costs
- Undue hardship on the organization (Correct answer)
- Displacement of another employee's duties
- Changes to essential job functions
Correct answer: Undue hardship on the organization
Under the ADA, employers must provide reasonable accommodations unless they would impose an undue hardship, considering factors like cost and operational impact.
Under the Sarbanes-Oxley Act (SOX), which section requires CEOs and CFOs to personally certify the accuracy of financial reports?