RCC Compliance Program Development and Implementation 3 — Questions and Answers
Question 1: What is the primary purpose of conducting a compliance program gap analysis?
- To identify discrepancies between current practices and regulatory requirements (Correct answer)
- To calculate the budget needed for compliance activities
- To evaluate employee satisfaction with compliance policies
- To compare the organization's program against competitors
Correct answer: To identify discrepancies between current practices and regulatory requirements
A gap analysis systematically compares existing practices against applicable requirements to identify deficiencies that must be remediated.
Question 2: In a multi-jurisdictional organization, how should compliance policies address conflicts between U.S. federal law and local international law?
- Always apply the most restrictive standard regardless of jurisdiction
- Apply local law in each jurisdiction and ignore U.S. requirements abroad
- Document the conflict and apply whichever law governs with a clear rationale (Correct answer)
- Defer all decisions to the legal department without compliance involvement
Correct answer: Document the conflict and apply whichever law governs with a clear rationale
When laws conflict, organizations must document the conflict, determine which law applies with proper legal analysis, and apply that law consistently with a clear rationale.
Question 3: Which metric is most useful for measuring the effectiveness of a compliance hotline?
- Total number of calls received per quarter
- Ratio of substantiated to unsubstantiated reports and average resolution time (Correct answer)
- Cost per call handled by the hotline vendor
- Employee awareness that the hotline exists
Correct answer: Ratio of substantiated to unsubstantiated reports and average resolution time
Substantiation rates and resolution times reveal whether the hotline is capturing genuine issues and resolving them promptly, making them the most meaningful effectiveness metrics.
Question 4: A compliance officer wants to implement a third-party risk management program. What is the correct first step?
- Contract all third parties to sign a code of conduct
- Inventory and categorize all third-party relationships by risk level (Correct answer)
- Conduct on-site audits of all vendors immediately
- Terminate relationships with any foreign-based suppliers
Correct answer: Inventory and categorize all third-party relationships by risk level
Inventorying and categorizing third parties by risk level is the essential first step because it allows proportionate due diligence resources to be allocated appropriately.
Question 5: Under the FCPA, which condition would NOT constitute a defense to a bribery charge?
- The payment was required by written local law
- The payment was a reasonable bona fide business expense
- The payment was customary in the local industry
- The payment was below a materiality threshold (Correct answer)
Correct answer: The payment was below a materiality threshold
There is no materiality threshold under the FCPA; even small payments made with corrupt intent can constitute violations, making amount an invalid defense.
Question 6: What distinguishes a compliance program that is 'on paper' from one that is 'effective' per the DOJ's 2023 guidance?
- The number of policies published on the intranet
- Whether the program is adequately resourced and actually implemented in practice (Correct answer)
- The length and detail of the code of conduct
- Whether the program has been certified by an external auditor
Correct answer: Whether the program is adequately resourced and actually implemented in practice
DOJ guidance emphasizes that effectiveness depends on whether the program has sufficient resources, authority, and is genuinely applied — not merely whether documents exist.
Question 7: Which type of internal audit sampling provides the strongest evidence when testing controls in a high-risk compliance area?
- Judgmental sampling based on auditor intuition
- Statistical random sampling with a defined confidence level (Correct answer)
- Convenience sampling of readily accessible records
- Sequential sampling of the first transactions in a period
Correct answer: Statistical random sampling with a defined confidence level
Statistical random sampling with a defined confidence level provides defensible, mathematically valid results and allows meaningful conclusions about the entire population.
What is the primary purpose of conducting a compliance program gap analysis?