Registered Compliance Management Specialist (RCMS) Certification — Questions and Answers
Question 1: Which privilege most commonly protects communications between legal counsel and employees during an internal compliance investigation?
- Fifth Amendment privilege
- Attorney-client privilege (Correct answer)
- Common interest privilege
- Work product doctrine
Correct answer: Attorney-client privilege
Attorney-client privilege protects confidential communications between an attorney and the client when legal advice is sought.
Question 2: A company's compliance program should include a financial fraud risk assessment that is performed at minimum:
- Only during external audits
- Whenever an employee is terminated
- Once at program inception
- Periodically and when significant organizational changes occur (Correct answer)
Correct answer: Periodically and when significant organizational changes occur
Fraud risk assessments should be conducted periodically and updated whenever significant changes occur, such as mergers, new products, or leadership changes.
Question 3: When a compliance officer conducts a whistleblower investigation, what principle requires keeping the reporter's identity confidential?
- The Fifth Amendment right against self-incrimination
- Confidentiality obligation to protect the reporter from retaliation (Correct answer)
- Attorney-client privilege between the company and its counsel
- The reporter's right to public disclosure
Correct answer: Confidentiality obligation to protect the reporter from retaliation
Compliance officers have an ethical and often legal obligation to protect a reporter's identity to prevent retaliation and encourage future reporting.
Question 4: Which of the following is a PRIMARY output of a compliance monitoring cycle?
- An updated list of applicable regulations
- A revised regulatory examination schedule
- A monitoring report summarizing findings, risk ratings, and remediation recommendations (Correct answer)
- A revised annual compliance budget
Correct answer: A monitoring report summarizing findings, risk ratings, and remediation recommendations
The primary deliverable of a monitoring cycle is the monitoring report, which communicates findings and drives corrective action.
Question 5: How should RCMS professionals handle confidential information related to regulatory change management?
- Share freely with all colleagues for transparency
- Delete all records after project completion
- Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations (Correct answer)
- Store information without any security measures
Correct answer: Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations
Confidential information must be handled according to established protocols, regulatory requirements, and professional ethics standards, including proper access control and disclosure procedures.
Question 6: Which is a key compliance standard in finance?
- GDPR.
- SOX. (Correct answer)
- OSHA.
- ISO 9001.
Correct answer: SOX.
The Sarbanes-Oxley Act (SOX) is a key compliance standard specifically in finance, particularly for public companies in the U.S. It mandates strict requirements for financial reporting, corporate governance, and internal controls to prevent fraud and ensure transparency. SOX directly impacts how financial institutions and publicly traded companies manage their financial operations and disclosures.
Question 7: Under the Foreign Corrupt Practices Act (FCPA), which type of payment to a foreign official is explicitly prohibited?
- Charitable donations to approved nonprofits
- Payments to obtain or retain business (Correct answer)
- Nominal gifts within company policy
- Legitimate travel expenses for facility tours
Correct answer: Payments to obtain or retain business
The FCPA prohibits bribery of foreign government officials to obtain or retain business, with limited exceptions for facilitating payments.
Question 8: When a compliance report submitted to a regulator contains material misstatements, what category of risk does this create?
- Only reputational risk with no formal legal consequences
- Minimal risk if the misstatement is corrected and resubmitted within 90 days
- Legal, regulatory, and potentially criminal risk in addition to reputational risk (Correct answer)
- Only the risk of a failed examination or audit finding
Correct answer: Legal, regulatory, and potentially criminal risk in addition to reputational risk
Material misstatements in regulatory compliance reports can expose the organization and responsible individuals to legal liability, regulatory sanctions, civil penalties, and potentially criminal charges for fraud or false statements.
Question 9: What does the 'fraud triangle' model identify as the three elements necessary for occupational fraud to occur?
- Motive, method, and means
- Risk, reward, and capability
- Pressure, opportunity, and rationalization (Correct answer)
- Intent, access, and concealment
Correct answer: Pressure, opportunity, and rationalization
The fraud triangle, developed by Donald Cressey, identifies pressure, opportunity, and rationalization as the three conditions that enable fraud.
Question 10: Which of the following BEST describes a 'compliance gap' in regulatory change management?
- Missing documentation in a regulatory filing
- The time lag between a regulation's publication and its effective date
- A disagreement between internal legal and compliance teams on rule interpretation
- The difference between what a new regulation requires and the organization's current state (Correct answer)
Correct answer: The difference between what a new regulation requires and the organization's current state
A compliance gap is the measurable difference between where the organization currently operates and what the new regulatory requirement mandates.
Question 11: The ACFE's Fraud Prevention Check-Up recommends that organizations with effective anti-fraud programs experience fraud losses that are approximately what percentage lower than those without such programs?
- 50 percent lower (Correct answer)
- 75 percent lower
- 25 percent lower
- 10 percent lower
Correct answer: 50 percent lower
ACFE research consistently finds that organizations with proactive anti-fraud controls suffer losses roughly 50% lower than those without them.
Question 12: Which of the following is the best example of a detective control in a fraud prevention framework?
- Surprise audits of petty cash funds (Correct answer)
- Providing annual fraud awareness training
- Requiring dual authorization for wire transfers
- Implementing a vendor onboarding checklist
Correct answer: Surprise audits of petty cash funds
Surprise audits are detective controls because they identify fraud after it has occurred, rather than preventing it from happening.
Question 13: When interviewing a subject of a compliance investigation (as opposed to a witness), what must the investigator typically provide?
- A written guarantee of confidentiality for the subject's statements
- An Upjohn warning clarifying that the company's attorney represents the company, not the individual (Correct answer)
- Miranda warnings identical to law enforcement
- Immunity from disciplinary action in exchange for cooperation
Correct answer: An Upjohn warning clarifying that the company's attorney represents the company, not the individual
An Upjohn warning informs the interview subject that the attorney represents the organization, not the individual, and that the company controls the privilege.
Question 14: What is the MAIN difference between compliance monitoring and compliance auditing?
- Monitoring focuses only on financial controls; auditing covers all controls
- Monitoring is an ongoing, risk-based management activity; auditing is a periodic, independent assessment (Correct answer)
- Monitoring is conducted by the third line of defense; auditing by the second line
- Monitoring is optional for smaller organizations; auditing is always required
Correct answer: Monitoring is an ongoing, risk-based management activity; auditing is a periodic, independent assessment
Monitoring is a continuous, second-line management activity while auditing is a periodic, independent third-line assessment of overall control effectiveness.
Question 15: A compliance officer must assess whether a new product falls under CFPB jurisdiction. Which factor is most determinative?
- Whether the product is offered in interstate commerce
- The size of the financial institution offering the product
- Whether the institution is federally or state chartered
- Whether the product is a 'consumer financial product or service' as defined by Dodd-Frank (Correct answer)
Correct answer: Whether the product is a 'consumer financial product or service' as defined by Dodd-Frank
The CFPB's jurisdiction turns on whether the product or service qualifies as a 'consumer financial product or service' under Title X of Dodd-Frank.
Question 16: Under the Dodd-Frank Act, whistleblowers who report securities violations to the SEC may receive monetary awards of what percentage of sanctions collected?
- 1 to 5 percent
- 5 to 10 percent
- 50 to 75 percent
- 10 to 30 percent (Correct answer)
Correct answer: 10 to 30 percent
Dodd-Frank authorizes the SEC to award whistleblowers between 10% and 30% of sanctions over $1 million collected from enforcement actions.
Question 17: An organization wants to assess concentration risk in its vendor portfolio. What does concentration risk refer to in this context?
- Over-reliance on a single vendor or vendor type for critical functions (Correct answer)
- High employee turnover concentrated in one vendor's account team
- Concentration of low-risk vendors requiring minimal oversight
- The vendor's geographic concentration in one country
Correct answer: Over-reliance on a single vendor or vendor type for critical functions
Concentration risk occurs when an organization relies too heavily on one vendor or a small group of vendors, creating a single point of failure for critical operations.
Question 18: A compliance officer is mapping controls to regulatory requirements. Which approach ensures that each regulation has at least one control addressing it?
- Compliance risk scoring
- Three lines of defense review
- Regulatory gap analysis (Correct answer)
- Control self-assessment
Correct answer: Regulatory gap analysis
A regulatory gap analysis systematically compares existing controls against regulatory requirements to identify areas lacking adequate coverage.
Question 19: Which approach BEST supports a culture of compliance throughout an organization?
- Focusing compliance culture efforts exclusively on high-risk departments
- Consistent 'tone from the top' with visible leadership commitment and reinforced behaviors (Correct answer)
- Limiting compliance messaging to the annual all-hands meeting
- Publishing compliance statistics on the intranet without management commentary
Correct answer: Consistent 'tone from the top' with visible leadership commitment and reinforced behaviors
Visible, consistent leadership commitment ('tone at the top') is the most powerful driver of an ethical culture because employees model the behaviors they observe in leadership.
Question 20: Which factor is MOST critical when selecting a third-party vendor for a compliance technology platform?
- Number of years the vendor has been in business
- Platform's ability to integrate with existing systems and scale with the organization (Correct answer)
- Vendor's headquarters location
- Lowest initial purchase price
Correct answer: Platform's ability to integrate with existing systems and scale with the organization
Integration capability and scalability ensure the platform will work within existing workflows and grow with the organization's needs without requiring costly replacements.
Question 21: Which of the following best describes an 'open door' reporting policy in a compliance program?
- Employees may report concerns to any level of management without fear of reprisal (Correct answer)
- All reports must be made in writing and signed
- Reports must be submitted only to direct supervisors
- Concerns are escalated exclusively to external auditors
Correct answer: Employees may report concerns to any level of management without fear of reprisal
An open door policy allows employees to bypass normal reporting chains to raise compliance concerns with any manager or compliance officer without retaliation.
Question 22: A regulated entity receives conflicting guidance from two different federal regulators claiming jurisdiction. This situation is best characterized as:
- Jurisdictional overlap (Correct answer)
- Regulatory capture
- Regulatory arbitrage
- Preemption conflict
Correct answer: Jurisdictional overlap
Jurisdictional overlap occurs when multiple regulators claim authority over the same entity or conduct, creating compliance ambiguity.
Question 23: Which of the following remediation activities is considered a 'preventive control' enhancement?
- Conducting a forensic review of past transactions
- Adding mandatory dual-approval for wire transfers above a defined threshold (Correct answer)
- Performing a gap analysis of historical compliance failures
- Reviewing existing investigation files for closed matters
Correct answer: Adding mandatory dual-approval for wire transfers above a defined threshold
Requiring dual approval prevents a single individual from completing a high-risk transaction without oversight, stopping violations before they occur.
Question 24: What is the most effective way to measure success in data privacy & protection compliance within RCMS professional practice?
- Compare only with industry averages without considering context
- Rely solely on supervisor opinion
- Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives (Correct answer)
- Count only the number of activities completed
Correct answer: Use a combination of quantitative metrics, qualitative assessments, and stakeholder feedback aligned with defined objectives
Effective measurement combines multiple data sources — quantitative metrics, qualitative assessments, and stakeholder feedback — all aligned with clearly defined objectives for a comprehensive evaluation.
Question 25: Which of the following BEST describes 'triage' in the context of compliance investigations?
- Conducting simultaneous interviews with all witnesses
- Rapidly assessing incoming reports to prioritize and allocate investigative resources (Correct answer)
- Delegating all investigations to external counsel
- Documenting all findings in the compliance management system
Correct answer: Rapidly assessing incoming reports to prioritize and allocate investigative resources
Triage involves quickly evaluating reports to determine severity, credibility, and urgency so resources are allocated to the highest-priority matters first.
Question 26: What is the primary purpose of a document retention policy in the context of regulatory compliance?
- To restrict employee access to sensitive compliance documents
- To reduce storage costs by systematically deleting old records as quickly as possible
- To ensure records are preserved for required periods while establishing when they may be legally disposed of (Correct answer)
- To automate the generation and filing of periodic regulatory reports
Correct answer: To ensure records are preserved for required periods while establishing when they may be legally disposed of
A document retention policy ensures legally required records are preserved for appropriate periods to satisfy regulatory and legal obligations while also establishing lawful disposal schedules for records no longer required.
Question 27: Which of the following best describes a key competency required for anti-money laundering & kyc in RCMS practice?
- The ability to work independently without any oversight
- Strong analytical skills combined with effective communication and ethical judgment (Correct answer)
- Reliance on a single methodology for all situations
- Memorization of all relevant regulations without understanding context
Correct answer: Strong analytical skills combined with effective communication and ethical judgment
RCMS professionals working in anti-money laundering & kyc need analytical skills to assess situations, communication skills to convey findings, and ethical judgment to make sound decisions.
Question 28: Which best practice ensures a whistleblower hotline remains effective and trustworthy over time?
- Routing all hotline reports exclusively to the CEO
- Regularly publishing aggregate statistics on reports received and actions taken (Correct answer)
- Requiring all reports to include the reporter's name and department
- Limiting hotline access to senior management only
Correct answer: Regularly publishing aggregate statistics on reports received and actions taken
Publishing aggregate statistics demonstrates that reports are acted upon and builds employee trust in the reporting system.
Question 29: Which provision of the Gramm-Leach-Bliley Act (GLBA) requires financial institutions to provide customers with privacy notices about information sharing practices?
- Financial Privacy Rule (Correct answer)
- Pretexting provisions
- Interagency Guidelines
- Safeguards Rule
Correct answer: Financial Privacy Rule
The GLBA Financial Privacy Rule requires financial institutions to provide clear notice to customers about their privacy practices and information-sharing policies.
Question 30: Which factor is LEAST important when prioritizing remediation actions after a compliance investigation?
- Severity of the violation
- Likelihood of recurrence
- Regulatory reporting deadlines
- The seniority of the employee who caused the violation (Correct answer)
Correct answer: The seniority of the employee who caused the violation
Employee seniority should not determine remediation priority; severity, recurrence risk, and deadlines are the substantive drivers.
Question 31: A compliance team is remediating an anti-money laundering (AML) failure. Which action would most directly strengthen the company's suspicious activity monitoring?
- Increasing the number of compliance officers without changing detection tools
- Reducing the scope of customer due diligence to speed up onboarding
- Enhancing transaction monitoring rules and alert thresholds based on identified gaps (Correct answer)
- Eliminating legacy accounts that triggered the initial alerts
Correct answer: Enhancing transaction monitoring rules and alert thresholds based on identified gaps
Refining transaction monitoring rules targets the specific detection failure that allowed suspicious activity to go unnoticed.
Registered Compliance Management Specialist (RCMS) Certification
The RCMS certification validates expertise in compliance program management, anti-money laundering, financial crimes prevention, and regulatory frameworks. It is designed for compliance professionals responsible for designing, implementing, and overseeing organizational compliance programs.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds