RCMS Compliance Monitoring & Testing 5 — Questions and Answers
Question 1: A compliance monitoring plan should be updated MOST frequently in response to:
- Changes in the compliance department's organizational chart
- New or amended regulations, significant business changes, or emerging risk areas (Correct answer)
- The annual budget cycle of the organization
- The personal preferences of the Chief Compliance Officer
Correct answer: New or amended regulations, significant business changes, or emerging risk areas
The monitoring plan must remain aligned with the current regulatory environment and business risk profile, requiring updates as those change.
Question 2: What is the MAIN difference between compliance monitoring and compliance auditing?
- Monitoring is conducted by the third line of defense; auditing by the second line
- Monitoring is an ongoing, risk-based management activity; auditing is a periodic, independent assessment (Correct answer)
- Monitoring focuses only on financial controls; auditing covers all controls
- Monitoring is optional for smaller organizations; auditing is always required
Correct answer: Monitoring is an ongoing, risk-based management activity; auditing is a periodic, independent assessment
Monitoring is a continuous, second-line management activity while auditing is a periodic, independent third-line assessment of overall control effectiveness.
Question 3: A compliance officer notices a significant spike in customer complaints related to a specific product. Under a risk-based approach, this SHOULD trigger:
- An immediate suspension of the product until the cause is identified
- An escalation of monitoring intensity and a targeted compliance review of that product (Correct answer)
- Referral of the complaints directly to legal counsel only
- No immediate action unless a regulator raises the issue
Correct answer: An escalation of monitoring intensity and a targeted compliance review of that product
Elevated complaints are a KRI signaling potential compliance risk and should trigger increased monitoring and a targeted review.
Question 4: Which element is MOST critical to include in a corrective action plan (CAP) resulting from a monitoring finding?
- A description of the finding, root cause, specific remediation steps, responsible owner, and target completion date (Correct answer)
- A list of all regulations that could potentially relate to the finding
- The names of employees who caused the compliance gap
- A comparison to industry benchmarks for similar findings
Correct answer: A description of the finding, root cause, specific remediation steps, responsible owner, and target completion date
An effective CAP requires clear identification of the problem, its root cause, specific steps to fix it, accountability, and a timeline.
Question 5: When designing a compliance test for a consumer lending disclosure requirement, the tester should FIRST:
- Select a random sample of loan files from the past year
- Identify the specific regulatory requirements and map them to testable control attributes (Correct answer)
- Interview customer service staff about their disclosure practices
- Review prior audit findings related to lending disclosures
Correct answer: Identify the specific regulatory requirements and map them to testable control attributes
Test design must begin with a clear understanding of the specific regulatory requirements before defining what to test and how to test it.
Question 6: Under the COSO framework, which component MOST directly supports ongoing compliance monitoring activities?
- Control Environment
- Risk Assessment
- Monitoring Activities (Correct answer)
- Information and Communication
Correct answer: Monitoring Activities
The COSO 'Monitoring Activities' component specifically covers ongoing evaluations and separate evaluations used to assess whether internal controls are present and functioning.
Question 7: A compliance officer receives a request from a business line manager to delay reporting a monitoring finding to senior management until the business unit can self-remediate. The MOST appropriate response is to:
- Agree, as self-remediation demonstrates the business unit's commitment to compliance
- Decline and follow the established escalation and reporting protocols regardless of remediation status (Correct answer)
- Agree only if the finding is rated as low severity
- Refer the decision to the legal department
Correct answer: Decline and follow the established escalation and reporting protocols regardless of remediation status
Compliance reporting protocols exist to ensure timely transparency to senior management and must not be circumvented even when remediation is underway.
A compliance monitoring plan should be updated MOST frequently in response to: