OM Regulatory Compliance 3 — Questions and Answers
Question 1: Which compliance framework is specifically designed to help organizations that process payment card data protect cardholder information?
- ISO 27001
- NIST CSF
- PCI DSS (Correct answer)
- SOC 2
Correct answer: PCI DSS
The Payment Card Industry Data Security Standard (PCI DSS) is specifically designed to protect cardholder data for organizations that process, store, or transmit payment card information.
Question 2: Under the Fair Labor Standards Act (FLSA), which category of workers is exempt from overtime pay requirements?
- All salaried employees regardless of duties
- Part-time employees working fewer than 30 hours per week
- Executives, administrative, and professional employees meeting salary and duties tests (Correct answer)
- Employees who voluntarily waive their overtime rights in writing
Correct answer: Executives, administrative, and professional employees meeting salary and duties tests
The FLSA exempts executive, administrative, and professional employees who meet both the salary basis test and specific duties tests from overtime requirements.
Question 3: A company's compliance program includes a confidential reporting hotline. According to best practices and SOX requirements, who should the hotline reports ultimately reach?
- The Chief Compliance Officer only
- The CEO and executive leadership team
- The Audit Committee of the Board of Directors (Correct answer)
- The organization's external auditors
Correct answer: The Audit Committee of the Board of Directors
SOX requires that audit committees establish procedures for receiving and handling complaints about accounting and internal controls, making them the appropriate recipients of hotline reports.
Question 4: The False Claims Act's 'qui tam' provision allows:
- Regulators to impose treble damages on repeat offenders
- Private citizens to file lawsuits on behalf of the government and share in recoveries (Correct answer)
- Companies to voluntarily disclose fraud in exchange for reduced penalties
- Whistleblowers to remain anonymous during all phases of litigation
Correct answer: Private citizens to file lawsuits on behalf of the government and share in recoveries
The False Claims Act's qui tam provision allows private citizens (relators) to sue on the government's behalf and receive 15-30% of recovered funds.
Question 5: An organization operating internationally must comply with the EU General Data Protection Regulation (GDPR). Which principle requires that personal data be collected only for specified, explicit, and legitimate purposes?
- Data minimization
- Purpose limitation (Correct answer)
- Storage limitation
- Integrity and confidentiality
Correct answer: Purpose limitation
GDPR's purpose limitation principle requires that personal data be collected for specified, explicit, and legitimate purposes and not processed in incompatible ways.
Question 6: Which document formally describes an organization's commitment to ethical conduct and serves as the foundation of its compliance program?
- Standard Operating Procedures manual
- Code of Conduct or Code of Ethics (Correct answer)
- Annual compliance audit report
- Regulatory correspondence file
Correct answer: Code of Conduct or Code of Ethics
A Code of Conduct or Code of Ethics is the foundational document that articulates an organization's values, ethical standards, and commitment to compliance.
Question 7: Under the Equal Employment Opportunity (EEO) laws enforced by the EEOC, what is the statute of limitations for filing a charge of discrimination with a federal agency in a 'deferral state'?
- 90 days from the discriminatory act
- 180 days from the discriminatory act
- 300 days from the discriminatory act (Correct answer)
- 2 years from the discriminatory act
Correct answer: 300 days from the discriminatory act
In states with their own fair employment agencies (deferral states), employees have 300 days to file a discrimination charge with the EEOC.
Which compliance framework is specifically designed to help organizations that process payment card data protect cardholder information?