Regulatory Frameworks & Standards Flashcards
7 cards from real RCMS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Regulatory Frameworks & Standards flashcards as text
Under the COSO Internal Control โ Integrated Framework, which component addresses the processes used to identify and assess risks to achieving objectives?
Answer: Risk Assessment
The Risk Assessment component of COSO involves identifying and analyzing relevant risks that may prevent achievement of organizational objectives.
Which EU regulation, effective 2023, requires large companies to conduct due diligence on human rights and environmental impacts across their supply chains?
Answer: Corporate Sustainability Due Diligence Directive
The Corporate Sustainability Due Diligence Directive (CS3D) mandates that large EU companies identify and address adverse human rights and environmental impacts in their value chains.
In U.S. financial regulation, Regulation O governs which type of transactions?
Answer: Loans to executive officers and directors of banks
Regulation O restricts credit extensions by member banks to their own executive officers, directors, principal shareholders, and their related interests.
A compliance officer is mapping controls to regulatory requirements. Which approach ensures that each regulation has at least one control addressing it?
Answer: Regulatory gap analysis
A regulatory gap analysis systematically compares existing controls against regulatory requirements to identify areas lacking adequate coverage.
The UK Bribery Act 2010 differs from the U.S. FCPA primarily because it:
Answer: Covers both public and private sector bribery
Unlike the FCPA, the UK Bribery Act covers bribery in both the public and private sectors and includes an offense of failing to prevent bribery.
Under the Payment Card Industry Data Security Standard (PCI DSS), what is the minimum length required for unique cryptographic keys?
Answer: 128 bits
PCI DSS requires a minimum key length of 128 bits for symmetric encryption algorithms to protect cardholder data.
Which provision of the Gramm-Leach-Bliley Act (GLBA) requires financial institutions to provide customers with privacy notices about information sharing practices?
Answer: Financial Privacy Rule
The GLBA Financial Privacy Rule requires financial institutions to provide clear notice to customers about their privacy practices and information-sharing policies.