Mixed Deck — All RCMS Topics Flashcards
100 cards from real RCMS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All RCMS Topics flashcards as text
What is the primary purpose of a board-level audit committee in a publicly traded US company?
Answer: Overseeing financial reporting and internal controls
The audit committee oversees the integrity of financial reporting, internal audit function, and relationship with external auditors.
Which metric BEST indicates whether compliance training is changing employee behavior?
Answer: Post-training incident rates compared to pre-training baselines
Comparing incident rates before and after training directly measures behavioral change, which is the ultimate goal of compliance training.
A compliance officer receives a subpoena request from a foreign government for records of a U.S. sanctions investigation. What is the primary concern?
Answer: Risk of violating anti-boycott regulations under the EAR
Responding to foreign government requests to boycott certain countries or persons can violate U.S. anti-boycott regulations enforced by BIS under the EAR.
Which of the following BEST describes 'values-based' compliance as opposed to 'rules-based' compliance?
Answer: Values-based compliance fosters internalized ethical principles that guide behavior even in situations not covered by explicit rules
Values-based compliance builds a culture where employees make ethical decisions based on internalized principles, filling gaps that rules-based approaches cannot anticipate.
Which element of a risk appetite statement specifies the maximum level of risk the organization is willing to take to achieve its strategic objectives?
Answer: Risk tolerance
Risk tolerance defines the acceptable variation in outcomes relative to objectives, representing the boundary the organization is willing to operate within.
Which of the following is an example of trade-based money laundering (TBML)?
Answer: Over-invoicing goods to transfer value across borders under the guise of legitimate trade
TBML exploits international trade transactions, such as over- or under-invoicing, to move value across borders illicitly.
What is the timeframe within which a financial institution must file a SAR after initially detecting a suspicious transaction?
Answer: 30 calendar days, extendable to 60 if no suspect is identified
SARs must be filed within 30 calendar days of detection, with a 60-day extension allowed when no suspect has been identified.
Under the DOJ's updated Corporate Compliance Program Evaluation guidance, prosecutors assess whether a compliance program is 'adequately resourced.' What does this primarily examine?
Answer: Staffing levels, expertise, and funding relative to the company's risk profile
DOJ evaluates whether compliance functions have sufficient personnel, expertise, and budget to address the organization's specific risk profile and operational complexity.
What is the significance of a code of ethics in governance?
Answer: To set behavior standards.
A code of ethics is a formal document that outlines the ethical principles and expected standards of conduct for all employees and stakeholders within an organization. Its significance in governance lies in providing a clear framework for ethical decision-making and behavior. This code helps to cultivate a culture of integrity, ensuring that actions align with the company's values and legal obligations, thereby mitigating risks and promoting responsible operations.
Which of the following is an example of 'tone at the middle' in a compliance program?
Answer: A regional manager consistently enforcing compliance policies and coaching employees on ethical decisions
Tone at the middle refers to managers reinforcing ethical standards in daily operations, bridging the gap between executive messaging and frontline behavior.
What does the term 'corporate social responsibility' (CSR) primarily refer to in a governance context?
Answer: Voluntary initiatives to create positive social and environmental impact beyond legal requirements
CSR encompasses voluntary corporate actions that address social, environmental, and ethical concerns beyond minimum legal compliance.
What is the recommended course of action when a compliance officer discovers that required records were inadvertently destroyed?
Answer: Promptly notify relevant regulators and thoroughly document the discovery and circumstances of the loss
Best practice and often regulatory obligation requires prompt voluntary disclosure to regulators and thorough documentation of the circumstances when required records are inadvertently destroyed.
Which EU regulation, effective 2023, requires large companies to conduct due diligence on human rights and environmental impacts across their supply chains?
Answer: Corporate Sustainability Due Diligence Directive
The Corporate Sustainability Due Diligence Directive (CS3D) mandates that large EU companies identify and address adverse human rights and environmental impacts in their value chains.
A company's compliance monitoring program identifies a control failure in its export controls process. What is the CORRECT sequence of actions?
Answer: Assess impact and potential violation, remediate, document, and report to authorities if required
Proper handling requires first assessing the scope and potential regulatory violation, then remediating, documenting thoroughly, and making mandatory disclosures if the assessment warrants.
When designing scenario-based compliance training, what is the MOST important characteristic of effective scenarios?
Answer: They should reflect realistic workplace situations employees are likely to encounter
Scenarios grounded in realistic, relatable situations increase engagement and help employees recognize and respond to compliance issues in their actual work context.
Under a continuous monitoring model, compliance alerts are MOST commonly triggered by:
Answer: Automated system rules that flag transactions exceeding defined thresholds
Continuous monitoring relies on automated rules and system controls to generate real-time alerts when activity exceeds defined parameters.
How should RCMS professionals handle confidential information related to third-party compliance management?
Answer: Follow established protocols for data protection, access control, and disclosure in accordance with applicable regulations
Confidential information must be handled according to established protocols, regulatory requirements, and professional ethics standards, including proper access control and disclosure procedures.
Which of the following best describes a 'debarred' party on the State Department's AECA Debarred List?
Answer: A person prohibited from participating in defense articles exports under ITAR
The AECA Debarred List identifies parties prohibited from receiving defense articles or defense services controlled under ITAR due to AECA violations.
Which SEC rule specifically governs electronic records retention requirements for registered investment advisers?
Answer: Rule 204-2 under the Investment Advisers Act of 1940
SEC Rule 204-2 under the Investment Advisers Act of 1940 specifies the types of records investment advisers must maintain, required formats, and applicable retention periods.
A compliance officer is remediating a data privacy violation. Which control would MOST directly prevent recurrence of unauthorized data access?
Answer: Implementing role-based access controls and periodic access reviews
Role-based access controls directly restrict who can access sensitive data, addressing the technical root cause of unauthorized access.