← All RCC Flashcard Decks

Mixed Deck — All RCC Topics Flashcards

100 cards from real RCC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All RCC Topics flashcards as text
  1. What element is essential for an effective compliance training program?

    Answer: Tailor content to job-specific roles

    For a compliance training program to be truly effective, its content must be relevant and applicable to the specific roles and responsibilities of the employees being trained. Tailoring content ensures that employees understand how compliance applies directly to their daily tasks and decision-making. This makes the training more impactful, increasing adherence and reducing the risk of non-compliance.

  2. In a Suspicious Activity Report (SAR) filed under the Bank Secrecy Act, what is the 'safe harbor' provision?

    Answer: Filers cannot be held civilly or criminally liable for filing a SAR in good faith

    The BSA safe harbor protects financial institutions and their employees from liability when they file a SAR in good faith, even if the suspicion turns out to be unfounded.

  3. During an interview in a compliance investigation, the subject employee requests to have a union representative present. Under the NLRA, this right is known as:

    Answer: Weingarten rights

    Weingarten rights, established by the Supreme Court, give unionized employees the right to union representation during investigatory interviews that could result in discipline.

  4. An organization that retains personal data longer than necessary for its stated purpose is most likely violating which privacy principle?

    Answer: Storage limitation

    The storage limitation principle requires that personal data be kept for no longer than necessary for the purpose it was collected, after which it should be deleted or anonymized.

  5. What is a red flag for unethical behavior in an organization?

    Answer: Employee fear of reporting misconduct

    Employee fear of reporting misconduct is a significant red flag for an unhealthy ethical culture within an organization. This fear indicates a lack of trust in leadership, a potential for retaliation, or a belief that reports will not be taken seriously, allowing unethical behavior to persist unchecked. A healthy ethical environment encourages open communication and protects those who speak up.

  6. What is the MAIN compliance function of a company's code of conduct?

    Answer: To establish the ethical standards and behavioral expectations for everyone in the organization

    A code of conduct articulates the organization's values, ethical standards, and expected behaviors, serving as the foundational compliance document that guides employee decision-making.

  7. Which standard provides a widely recognized framework for internal audit quality assurance in the US?

    Answer: The IIA International Standards for the Professional Practice of Internal Auditing

    The Institute of Internal Auditors (IIA) publishes the International Standards for the Professional Practice of Internal Auditing, which govern audit quality, independence, and methodology.

  8. Which phase of the vendor lifecycle is MOST often overlooked in compliance programs?

    Answer: Offboarding and data return or destruction

    Vendor offboarding — ensuring data is returned or securely destroyed and access is terminated — is frequently neglected despite being a key privacy and security compliance requirement.

  9. A compliance officer learns that the company's sales incentive plan may be driving improper conduct. What action is most appropriate?

    Answer: Escalate to leadership and recommend redesigning the incentive structure

    Root-cause remediation requires escalating to leadership to address the underlying incentive design, not just monitoring symptoms or issuing reminders.

  10. What is a 'board compliance committee' MOST commonly responsible for?

    Answer: Overseeing the compliance program, reviewing significant compliance risks, and reporting to the full board

    A board-level compliance committee provides dedicated governance oversight of the compliance program, receives reports from the chief compliance officer, and escalates material compliance risks to the full board.

  11. An organization stores cardholder data and processes credit card transactions. Which standard governs its data security compliance obligations?

    Answer: PCI DSS (Payment Card Industry Data Security Standard)

    PCI DSS is the mandated security standard for any organization that stores, processes, or transmits cardholder data, requiring specific technical and operational controls.

  12. Proxy statements (Form DEF 14A) are filed with the SEC PRIMARILY to:

    Answer: Disclose information shareholders need to vote on corporate matters including director elections and executive compensation

    Proxy statements provide shareholders with the information needed to vote on matters such as director elections, say-on-pay votes, and other shareholder proposals at annual meetings.

  13. The process of evaluating a potential vendor's compliance posture BEFORE engagement is known as:

    Answer: Due diligence

    Due diligence involves assessing a vendor's legal, financial, operational, and compliance history prior to entering into a contractual relationship.

  14. In a multi-jurisdictional organization, how should compliance policies address conflicts between U.S. federal law and local international law?

    Answer: Document the conflict and apply whichever law governs with a clear rationale

    When laws conflict, organizations must document the conflict, determine which law applies with proper legal analysis, and apply that law consistently with a clear rationale.

  15. What is 'pseudonymization' in a data privacy compliance context?

    Answer: Replacing direct identifiers with artificial identifiers so data cannot be attributed to a specific individual without additional information

    Pseudonymization replaces identifying information with a pseudonym, reducing privacy risk while still allowing data to be re-identified when combined with separately stored key information.

  16. Which ethical principle is most important when handling confidential reports?

    Answer: Confidentiality

    Confidentiality is paramount when handling sensitive reports, especially those involving ethical misconduct. Upholding confidentiality protects the privacy of individuals involved, encourages future reporting by building trust, and prevents potential retaliation against the reporter or premature judgment of the accused. It ensures a fair and unbiased investigation process.

  17. Which scenario BEST illustrates a 'detective' compliance control?

    Answer: Running a monthly report that flags transactions above a dollar threshold

    Detective controls identify non-compliant events after they have occurred, such as exception reports that flag unusual transactions for review.

  18. An organization's 'risk tolerance' differs from 'risk appetite' in that risk tolerance refers to:

    Answer: The acceptable variation around risk appetite objectives

    Risk tolerance defines the acceptable deviation from risk appetite, providing operational boundaries around the broader strategic risk appetite statement.

  19. Under SOX Section 302, which executives must personally certify the effectiveness of disclosure controls and procedures?

    Answer: Chief Executive Officer and Chief Financial Officer

    SOX Section 302 requires the CEO and CFO to personally certify the adequacy of disclosure controls and that financial statements fairly present the company's financial condition.

  20. HIPAA's Security Rule applies specifically to:

    Answer: Electronic protected health information (ePHI) held by covered entities and their business associates

    The HIPAA Security Rule establishes national standards for protecting ePHI that is created, received, used, or maintained by covered entities and business associates.