Mixed Deck — All RCC Topics Flashcards
100 cards from real RCC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All RCC Topics flashcards as text
What element is essential for an effective compliance training program?
Answer: Tailor content to job-specific roles
For a compliance training program to be truly effective, its content must be relevant and applicable to the specific roles and responsibilities of the employees being trained. Tailoring content ensures that employees understand how compliance applies directly to their daily tasks and decision-making. This makes the training more impactful, increasing adherence and reducing the risk of non-compliance.
In a Suspicious Activity Report (SAR) filed under the Bank Secrecy Act, what is the 'safe harbor' provision?
Answer: Filers cannot be held civilly or criminally liable for filing a SAR in good faith
The BSA safe harbor protects financial institutions and their employees from liability when they file a SAR in good faith, even if the suspicion turns out to be unfounded.
During an interview in a compliance investigation, the subject employee requests to have a union representative present. Under the NLRA, this right is known as:
Answer: Weingarten rights
Weingarten rights, established by the Supreme Court, give unionized employees the right to union representation during investigatory interviews that could result in discipline.
An organization that retains personal data longer than necessary for its stated purpose is most likely violating which privacy principle?
Answer: Storage limitation
The storage limitation principle requires that personal data be kept for no longer than necessary for the purpose it was collected, after which it should be deleted or anonymized.
What is a red flag for unethical behavior in an organization?
Answer: Employee fear of reporting misconduct
Employee fear of reporting misconduct is a significant red flag for an unhealthy ethical culture within an organization. This fear indicates a lack of trust in leadership, a potential for retaliation, or a belief that reports will not be taken seriously, allowing unethical behavior to persist unchecked. A healthy ethical environment encourages open communication and protects those who speak up.
What is the MAIN compliance function of a company's code of conduct?
Answer: To establish the ethical standards and behavioral expectations for everyone in the organization
A code of conduct articulates the organization's values, ethical standards, and expected behaviors, serving as the foundational compliance document that guides employee decision-making.
Which standard provides a widely recognized framework for internal audit quality assurance in the US?
Answer: The IIA International Standards for the Professional Practice of Internal Auditing
The Institute of Internal Auditors (IIA) publishes the International Standards for the Professional Practice of Internal Auditing, which govern audit quality, independence, and methodology.
Which phase of the vendor lifecycle is MOST often overlooked in compliance programs?
Answer: Offboarding and data return or destruction
Vendor offboarding — ensuring data is returned or securely destroyed and access is terminated — is frequently neglected despite being a key privacy and security compliance requirement.
A compliance officer learns that the company's sales incentive plan may be driving improper conduct. What action is most appropriate?
Answer: Escalate to leadership and recommend redesigning the incentive structure
Root-cause remediation requires escalating to leadership to address the underlying incentive design, not just monitoring symptoms or issuing reminders.
What is a 'board compliance committee' MOST commonly responsible for?
Answer: Overseeing the compliance program, reviewing significant compliance risks, and reporting to the full board
A board-level compliance committee provides dedicated governance oversight of the compliance program, receives reports from the chief compliance officer, and escalates material compliance risks to the full board.
An organization stores cardholder data and processes credit card transactions. Which standard governs its data security compliance obligations?
Answer: PCI DSS (Payment Card Industry Data Security Standard)
PCI DSS is the mandated security standard for any organization that stores, processes, or transmits cardholder data, requiring specific technical and operational controls.
Proxy statements (Form DEF 14A) are filed with the SEC PRIMARILY to:
Answer: Disclose information shareholders need to vote on corporate matters including director elections and executive compensation
Proxy statements provide shareholders with the information needed to vote on matters such as director elections, say-on-pay votes, and other shareholder proposals at annual meetings.
The process of evaluating a potential vendor's compliance posture BEFORE engagement is known as:
Answer: Due diligence
Due diligence involves assessing a vendor's legal, financial, operational, and compliance history prior to entering into a contractual relationship.
In a multi-jurisdictional organization, how should compliance policies address conflicts between U.S. federal law and local international law?
Answer: Document the conflict and apply whichever law governs with a clear rationale
When laws conflict, organizations must document the conflict, determine which law applies with proper legal analysis, and apply that law consistently with a clear rationale.
What is 'pseudonymization' in a data privacy compliance context?
Answer: Replacing direct identifiers with artificial identifiers so data cannot be attributed to a specific individual without additional information
Pseudonymization replaces identifying information with a pseudonym, reducing privacy risk while still allowing data to be re-identified when combined with separately stored key information.
Which ethical principle is most important when handling confidential reports?
Answer: Confidentiality
Confidentiality is paramount when handling sensitive reports, especially those involving ethical misconduct. Upholding confidentiality protects the privacy of individuals involved, encourages future reporting by building trust, and prevents potential retaliation against the reporter or premature judgment of the accused. It ensures a fair and unbiased investigation process.
Which scenario BEST illustrates a 'detective' compliance control?
Answer: Running a monthly report that flags transactions above a dollar threshold
Detective controls identify non-compliant events after they have occurred, such as exception reports that flag unusual transactions for review.
An organization's 'risk tolerance' differs from 'risk appetite' in that risk tolerance refers to:
Answer: The acceptable variation around risk appetite objectives
Risk tolerance defines the acceptable deviation from risk appetite, providing operational boundaries around the broader strategic risk appetite statement.
Under SOX Section 302, which executives must personally certify the effectiveness of disclosure controls and procedures?
Answer: Chief Executive Officer and Chief Financial Officer
SOX Section 302 requires the CEO and CFO to personally certify the adequacy of disclosure controls and that financial statements fairly present the company's financial condition.
HIPAA's Security Rule applies specifically to:
Answer: Electronic protected health information (ePHI) held by covered entities and their business associates
The HIPAA Security Rule establishes national standards for protecting ePHI that is created, received, used, or maintained by covered entities and business associates.