RCMS Compliance Monitoring & Testing 3 — Questions and Answers
Question 1: Under a continuous monitoring model, compliance alerts are MOST commonly triggered by:
- Scheduled calendar reminders set by the compliance team
- Automated system rules that flag transactions exceeding defined thresholds (Correct answer)
- Annual risk assessments conducted by senior management
- Periodic manual reviews of printed transaction reports
Correct answer: Automated system rules that flag transactions exceeding defined thresholds
Continuous monitoring relies on automated rules and system controls to generate real-time alerts when activity exceeds defined parameters.
Question 2: A compliance officer is reviewing a monitoring report that shows 5% of sampled files had missing required disclosures. What should be the first step?
- Immediately report the finding to regulators
- Determine whether the error rate represents a systemic issue or isolated incidents (Correct answer)
- Close all affected accounts pending a full review
- Require 100% testing of all files going forward
Correct answer: Determine whether the error rate represents a systemic issue or isolated incidents
Before escalating, the compliance officer must determine whether the error is isolated or indicative of a broader systemic failure.
Question 3: Which of the following is an example of a KEY RISK INDICATOR (KRI) used in compliance monitoring?
- The number of policies approved by the board this year
- The percentage of customer complaints related to a specific product line (Correct answer)
- The total dollar amount of revenue generated by a business unit
- The number of new employees hired in a compliance role
Correct answer: The percentage of customer complaints related to a specific product line
KRIs are forward-looking metrics that signal rising compliance risk, such as elevated complaint rates tied to specific products.
Question 4: What is the primary purpose of a compliance monitoring universe?
- To list all employees who have compliance responsibilities
- To catalog all regulations that apply to the organization
- To identify all business activities, products, and processes subject to compliance monitoring (Correct answer)
- To document all prior regulatory examinations and their outcomes
Correct answer: To identify all business activities, products, and processes subject to compliance monitoring
The monitoring universe defines the full scope of activities and areas eligible for compliance monitoring and testing.
Question 5: In compliance testing, 'attribute sampling' is BEST used to:
- Estimate the total dollar value of errors in a population
- Determine the rate at which a specific characteristic (e.g., missing signature) occurs in a population (Correct answer)
- Rank items by risk before selecting a sample
- Identify the largest transactions in a population
Correct answer: Determine the rate at which a specific characteristic (e.g., missing signature) occurs in a population
Attribute sampling is used to estimate the frequency of a specific attribute or error condition within a population.
Question 6: A compliance monitoring finding is classified as 'high severity' when:
- It involves a minor administrative error with no customer impact
- It represents a potential violation with significant regulatory, financial, or reputational consequences (Correct answer)
- It was discovered during an unscheduled review rather than a planned test
- It affects fewer than 10% of sampled transactions
Correct answer: It represents a potential violation with significant regulatory, financial, or reputational consequences
Severity is driven by the potential impact of the finding on regulatory standing, finances, and reputation, not by discovery method or sample rate.
Question 7: Which of the following BEST describes the role of the 'second line of defense' in a compliance monitoring context?
- Executing business transactions and owning day-to-day operational controls
- Conducting independent audits and reporting to the audit committee
- Overseeing, testing, and monitoring the first line's compliance with policies and regulations (Correct answer)
- Engaging with regulators on behalf of the organization
Correct answer: Overseeing, testing, and monitoring the first line's compliance with policies and regulations
The second line (compliance function) provides oversight, monitoring, and testing of the first line's control activities.
Under a continuous monitoring model, compliance alerts are MOST commonly triggered by: