Regulatory Compliance Certification (RCC) โ Questions and Answers
Question 1: A compliance officer wants to reach employees who do not work at desks. Which training delivery method is MOST appropriate?
- Mobile-friendly microlearning modules accessible on any device (Correct answer)
- Live classroom sessions at headquarters only
- Printed policy manuals
- Email-only communications
Correct answer: Mobile-friendly microlearning modules accessible on any device
Mobile-friendly microlearning accommodates deskless and field workers by allowing them to access brief, focused compliance content on smartphones or tablets.
Question 2: Which element distinguishes a 'per se' antitrust violation from a 'rule of reason' analysis under the Sherman Act?
- Rule of reason violations carry criminal penalties; per se violations only civil
- Per se analysis applies only to vertical restraints
- Per se violations require proof of market power; rule of reason does not
- Per se violations are automatically illegal without need to assess competitive effects (Correct answer)
Correct answer: Per se violations are automatically illegal without need to assess competitive effects
Per se violations (e.g., price-fixing, bid-rigging) are conclusively presumed illegal without weighing pro- vs. anti-competitive effects.
Question 3: A vendor compliance scorecard is MOST useful for:
- Comparing vendor salary structures
- Tracking vendor performance against defined compliance metrics over time (Correct answer)
- Satisfying annual shareholder reports
- Replacing contractual obligations with informal agreements
Correct answer: Tracking vendor performance against defined compliance metrics over time
A vendor scorecard provides a structured, metrics-based view of how well a vendor is meeting compliance expectations, enabling data-driven decisions about the relationship.
Question 4: Which element of a vendor contract MOST directly supports compliance with data privacy regulations like CCPA or HIPAA?
- A payment terms clause
- A force majeure clause
- An exclusivity provision
- Data processing agreements and data security requirements (Correct answer)
Correct answer: Data processing agreements and data security requirements
Data processing agreements define how a vendor may collect, use, store, and protect personal data, which is a contractual requirement under many privacy regulations.
Question 5: Which approach best ensures that compliance training is effective rather than merely completed?
- Testing comprehension and tracking behavioral outcomes (Correct answer)
- Using the same training module annually
- Delegating training design to HR
- Requiring electronic acknowledgment of attendance
Correct answer: Testing comprehension and tracking behavioral outcomes
Measuring comprehension through testing and tracking changes in behavior ensures training produces actual compliance improvements, not just completion records.
Question 6: A 'compliance newsletter' distributed to employees PRIMARILY serves to:
- Satisfy annual SEC disclosure requirements
- Provide legal opinions on regulatory matters
- Reinforce awareness of compliance topics, recent changes, and success stories (Correct answer)
- Replace mandatory training requirements
Correct answer: Reinforce awareness of compliance topics, recent changes, and success stories
A compliance newsletter keeps the workforce engaged with compliance topics between formal training sessions and can highlight recent enforcement trends, policy updates, and positive compliance behaviors.
Question 7: A compliance program review reveals that the compliance officer reports to the General Counsel. What is the primary structural concern?
- The reporting line may compromise independence if legal matters conflict with compliance obligations (Correct answer)
- The compliance officer may lack sufficient legal training
- This structure violates SEC regulations for public companies
- General Counsels are not qualified to evaluate compliance work
Correct answer: The reporting line may compromise independence if legal matters conflict with compliance obligations
When compliance reports to legal, there is a risk that attorney-client privilege considerations or legal strategy may influence compliance decisions, compromising independence.
Question 8: Which affirmative defense is explicitly available under the FCPA anti-bribery provisions?
- The company self-reported the violation within 30 days of discovery
- The payment was a reasonable and bona fide business expenditure directly related to promoting products or services (Correct answer)
- The payment was below a materiality threshold of $5,000
- The foreign official voluntarily solicited the payment
Correct answer: The payment was a reasonable and bona fide business expenditure directly related to promoting products or services
The FCPA provides an affirmative defense for reasonable and bona fide promotional expenditures, provided they are lawful under the written laws of the foreign country.
Question 9: What are 'facilitating payments' (also called grease payments) under the FCPA?
- Large bribes paid to senior government ministers to win contracts
- Commission payments made to third-party sales agents
- Small payments to low-level officials to expedite routine, non-discretionary government actions (Correct answer)
- Charitable donations made to government-linked foundations
Correct answer: Small payments to low-level officials to expedite routine, non-discretionary government actions
Facilitating payments are small payments to minor officials to speed up routine government actions (e.g., processing permits), and the FCPA contains a narrow exception for them, though many other laws do not.
Question 10: In an anti-corruption compliance program, what is the primary purpose of conducting third-party due diligence?
- To satisfy annual reporting requirements to the SEC
- To identify competitors who may be engaging in bribery
- To assess the corruption risk posed by agents, distributors, and other intermediaries acting on the company's behalf (Correct answer)
- To verify that suppliers hold appropriate ISO quality certifications
Correct answer: To assess the corruption risk posed by agents, distributors, and other intermediaries acting on the company's behalf
Third-party due diligence is critical because the FCPA and similar laws hold companies liable for bribes paid through intermediaries who act on their behalf, making risk assessment of such parties essential.
Question 11: Which of the following BEST describes a 'continuous monitoring' approach to compliance?
- Requiring weekly employee self-certifications
- Hiring additional compliance staff to observe operations
- Using automated tools to flag exceptions in real time (Correct answer)
- Scheduling annual compliance reviews
Correct answer: Using automated tools to flag exceptions in real time
Continuous monitoring leverages technology to automatically detect and alert compliance personnel to anomalies or policy violations as they occur.
Question 12: Which technique involves systematically reviewing a representative portion of transactions to assess compliance?
- Observation
- Sampling (Correct answer)
- Inquiry
- Benchmarking
Correct answer: Sampling
Sampling involves selecting a representative subset of transactions or records to draw conclusions about the entire population.
Question 13: Which risk-tiering approach is BEST practice when managing a large vendor portfolio?
- Require all vendors to achieve ISO 27001 certification
- Only monitor vendors that have previously caused incidents
- Classify vendors by risk level and allocate monitoring resources proportionally (Correct answer)
- Apply identical oversight to all vendors regardless of risk
Correct answer: Classify vendors by risk level and allocate monitoring resources proportionally
Risk-tiering directs the most intensive oversight to high-risk or critical vendors, allowing compliance resources to be allocated efficiently across a large portfolio.
Question 14: What does the term 'successor liability' mean in the context of FCPA enforcement during mergers and acquisitions?
- FCPA liability is extinguished upon completion of a merger
- Executives of the acquired company are personally indemnified against FCPA claims
- The selling company retains all FCPA liability post-transaction
- The acquiring company assumes the liability for the target company's pre-acquisition FCPA violations (Correct answer)
Correct answer: The acquiring company assumes the liability for the target company's pre-acquisition FCPA violations
Successor liability means that a company acquiring another entity may inherit FCPA liability for the target's pre-acquisition corrupt conduct, making pre-deal due diligence essential.
Question 15: Why is third-party compliance management critical for organizations subject to regulatory oversight?
- Organizations can be held liable for compliance failures caused by their vendors (Correct answer)
- Third parties are always more compliant than internal departments
- Vendor audits are required by GAAP
- Regulators only audit vendors, not the organization itself
Correct answer: Organizations can be held liable for compliance failures caused by their vendors
Regulators hold organizations accountable for the compliance behavior of third parties acting on their behalf, making vendor oversight a core compliance obligation.
Question 16: A compliance officer discovers that a regional manager approved an undisclosed cash payment to a local permit officer to accelerate a construction license. The most appropriate immediate next step is to:
- Preserve all relevant documents, conduct a privileged internal investigation, and consult with legal counsel about disclosure obligations (Correct answer)
- Issue a company-wide memo prohibiting all future cash payments
- Reimburse the permit officer to avoid further entanglement
- Terminate the regional manager and close the matter internally
Correct answer: Preserve all relevant documents, conduct a privileged internal investigation, and consult with legal counsel about disclosure obligations
Upon discovering a potential FCPA violation, companies should preserve evidence, conduct a privileged investigation, and assess potential voluntary disclosure obligations with counsel before taking further action.
Question 17: Speak-up culture in an organization is BEST supported by:
- Limiting reporting channels to direct managers only
- A zero-tolerance policy with severe penalties for all violations
- Publishing the identities of all whistleblowers
- Ensuring employees know how to report concerns and feel protected from retaliation (Correct answer)
Correct answer: Ensuring employees know how to report concerns and feel protected from retaliation
A speak-up culture flourishes when employees trust that reporting channels are accessible, confidential, and protected from retaliation, encouraging early reporting of potential issues.
Question 18: What does 'tone at the top' mean in the context of a compliance culture?
- The volume of communications sent by HR
- The number of compliance training hours completed by executives
- The quality of the organization's compliance policies
- The ethical standards and commitment to compliance demonstrated by senior leadership (Correct answer)
Correct answer: The ethical standards and commitment to compliance demonstrated by senior leadership
Tone at the top refers to the values, behaviors, and compliance commitments modeled by senior executives, which set the cultural standard for the entire organization.
Question 19: During ongoing vendor monitoring, which indicator would MOST concern a compliance officer?
- The vendor changed its billing software
- The vendor launched a new product line
- The vendor received a regulatory enforcement action from its primary regulator (Correct answer)
- The vendor increased its staff headcount by 10%
Correct answer: The vendor received a regulatory enforcement action from its primary regulator
A regulatory enforcement action against a vendor signals potential systemic compliance or control failures that could directly affect the organization relying on that vendor.
Question 20: A 'root cause analysis' in compliance monitoring is BEST described as:
- A process for ranking compliance risks by severity
- A benchmark comparison against industry peers
- An investigation into the underlying reason a compliance failure occurred (Correct answer)
- A financial calculation methodology
Correct answer: An investigation into the underlying reason a compliance failure occurred
Root cause analysis seeks to identify the fundamental reason a violation or control failure occurred so that corrective actions address the source rather than just the symptom.
Question 21: What is the focus of the General Data Protection Regulation (GDPR)?
- Personal data protection (Correct answer)
- Financial auditing
- Trade regulation
- Cybersecurity enforcement
Correct answer: Personal data protection
The General Data Protection Regulation (GDPR) is a comprehensive data privacy law from the European Union. Its main objective is to protect the personal data and privacy of EU citizens and residents. It sets strict rules for how organizations collect, process, and store personal information, giving individuals greater control over their data.
Question 22: Which of the following best describes an effective anti-corruption 'speak up' culture?
- A policy requiring employees to report all concerns directly to their immediate supervisor
- A culture where employees fear reporting violations because of past retaliation incidents
- A system where only senior managers are authorized to receive and review compliance reports
- An environment where employees feel safe reporting concerns without fear of retaliation, supported by multiple confidential reporting channels and a non-retaliation policy that is actively enforced (Correct answer)
Correct answer: An environment where employees feel safe reporting concerns without fear of retaliation, supported by multiple confidential reporting channels and a non-retaliation policy that is actively enforced
An effective speak-up culture combines psychological safety, multiple accessible reporting channels, a strong non-retaliation policy, and visible evidence that reports are taken seriously and acted upon.
Question 23: Which federal statute imposes civil and criminal liability on any person who knowingly presents a false claim for payment to the federal government?
- The Anti-Kickback Statute
- The False Claims Act (Correct answer)
- The Program Fraud Civil Remedies Act
- The Sarbanes-Oxley Act
Correct answer: The False Claims Act
The False Claims Act (31 U.S.C. ยงยง 3729โ3733) imposes treble damages and per-claim penalties for knowingly submitting false claims to federal agencies.
Question 24: What distinguishes a compliance review from a compliance audit?
- Reviews are always conducted by external parties
- Reviews are typically less formal and scope-limited compared to full audits (Correct answer)
- Reviews are required by law; audits are optional
- Audits do not produce written reports
Correct answer: Reviews are typically less formal and scope-limited compared to full audits
Compliance reviews tend to be narrower in scope and less formal than audits, often focusing on a specific process or control rather than a comprehensive examination.
Question 25: An employee is terminated shortly after filing a workers' compensation claim and suspects retaliation. Which federal law primarily protects employees from retaliation for filing such claims?
- The Employee Retirement Income Security Act (ERISA)
- The Fair Labor Standards Act (FLSA)
- The Occupational Safety and Health Act (OSHA)
- State workers' compensation statutes and general anti-retaliation principles (Correct answer)
Correct answer: State workers' compensation statutes and general anti-retaliation principles
Workers' compensation retaliation is primarily governed by state law, though OSHA and other federal statutes may apply depending on the circumstances.
Question 26: Which standard provides a widely recognized framework for internal audit quality assurance in the US?
- The IIA International Standards for the Professional Practice of Internal Auditing (Correct answer)
- COSO ERM
- ISO 9001
- NIST CSF
Correct answer: The IIA International Standards for the Professional Practice of Internal Auditing
The Institute of Internal Auditors (IIA) publishes the International Standards for the Professional Practice of Internal Auditing, which govern audit quality, independence, and methodology.
Question 27: Which training approach BEST promotes ethical decision-making skills rather than mere rule-following?
- Scenario-based training using realistic ethical dilemmas (Correct answer)
- Compliance testing focused on policy definitions
- Memorization of the entire regulatory code
- Annual policy distribution with employee signatures
Correct answer: Scenario-based training using realistic ethical dilemmas
Scenario-based training develops judgment by presenting realistic situations where employees must apply compliance principles, rather than simply memorize rules.
Question 28: Which regulation requires public companies to establish internal controls for financial reporting?
- FCPA
- GDPR
- SOX (Correct answer)
- HIPAA
Correct answer: SOX
The Sarbanes-Oxley Act of 2002 (SOX) is a federal law that mandated reforms to enhance corporate responsibility and improve financial disclosures. A key provision, particularly Section 404, requires public companies to establish and maintain internal controls over financial reporting. Management and external auditors must then report on the effectiveness of these controls to ensure accuracy and prevent fraud.
Question 29: When setting a monitoring frequency for a compliance control, the MOST important factor is:
- The preferences of department managers
- The level of inherent risk associated with the process being monitored (Correct answer)
- The availability of the compliance officer
- The cost of the monitoring activity
Correct answer: The level of inherent risk associated with the process being monitored
Higher-risk processes should be monitored more frequently; monitoring frequency should be calibrated to the inherent risk of the activity to ensure timely detection of issues.
Question 30: An internal auditor discovers that employees have been bypassing a required approval step because it slows their workflow. This is an example of:
- Inherent risk
- Risk transfer
- Risk avoidance
- Control override (Correct answer)
Correct answer: Control override
Control override occurs when individuals circumvent established controls, undermining their effectiveness regardless of how well the control was designed.
Question 31: Under the California Consumer Privacy Act (CCPA), consumers have the right to:
- Sue businesses for any data collection without prior notice
- Prohibit businesses from collecting any data
- Know what personal information is collected about them and request its deletion (Correct answer)
- Delete all records held by a business at any time regardless of law
Correct answer: Know what personal information is collected about them and request its deletion
The CCPA grants California consumers rights to know about, access, delete, and opt out of the sale of their personal information, with some exceptions.
Question 32: Which regulatory guidance document addresses vendor management obligations for US financial institutions?
- OSHA 29 CFR 1910
- SEC Regulation FD
- OCC Bulletin 2013-29 on Third-Party Relationships (Correct answer)
- EPA Clean Air Act regulations
Correct answer: OCC Bulletin 2013-29 on Third-Party Relationships
OCC Bulletin 2013-29 provides comprehensive guidance for national banks and federal savings associations on managing risks associated with third-party relationships.
Regulatory Compliance Certification (RCC)
The RCC certification validates professional competency in corporate compliance programs, covering regulatory frameworks, anti-corruption practices, compliance auditing, third-party risk management, and training culture.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong โ answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds