Compliance Reporting & Documentation Flashcards
7 cards from real RCMS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Compliance Reporting & Documentation flashcards as text
What is the primary purpose of a document retention policy in the context of regulatory compliance?
Answer: To ensure records are preserved for required periods while establishing when they may be legally disposed of
A document retention policy ensures legally required records are preserved for appropriate periods to satisfy regulatory and legal obligations while also establishing lawful disposal schedules for records no longer required.
What is a 'litigation hold' (legal hold) in the context of compliance documentation management?
Answer: A directive to preserve all potentially relevant documents when litigation or regulatory investigation is reasonably anticipated
A litigation hold suspends normal document destruction schedules and requires preservation of all documents potentially relevant to reasonably anticipated or actual litigation or regulatory investigation.
Which SEC rule specifically governs electronic records retention requirements for registered investment advisers?
Answer: Rule 204-2 under the Investment Advisers Act of 1940
SEC Rule 204-2 under the Investment Advisers Act of 1940 specifies the types of records investment advisers must maintain, required formats, and applicable retention periods.
What is the recommended course of action when a compliance officer discovers that required records were inadvertently destroyed?
Answer: Promptly notify relevant regulators and thoroughly document the discovery and circumstances of the loss
Best practice and often regulatory obligation requires prompt voluntary disclosure to regulators and thorough documentation of the circumstances when required records are inadvertently destroyed.
When a compliance report submitted to a regulator contains material misstatements, what category of risk does this create?
Answer: Legal, regulatory, and potentially criminal risk in addition to reputational risk
Material misstatements in regulatory compliance reports can expose the organization and responsible individuals to legal liability, regulatory sanctions, civil penalties, and potentially criminal charges for fraud or false statements.
Under HIPAA, covered entities must maintain documentation of their privacy policies and procedures for how long?
Answer: 6 years from creation or last effective date, whichever is later
HIPAA's Privacy Rule requires covered entities to retain documentation of their privacy policies, procedures, and related records for 6 years from the date of creation or the date it was last in effect, whichever is later.
In compliance audit reporting, what is the primary distinction between a 'finding' and an 'observation'?
Answer: A finding represents a confirmed violation of a specific requirement; an observation is a lesser concern or improvement suggestion that does not constitute a clear violation
In compliance reporting, a 'finding' denotes a confirmed violation of a specific rule or requirement, while an 'observation' is a lower-severity note about a potential improvement area or minor concern that falls short of a clear violation.