RCMS Risk Assessment & Internal Controls 5 β Questions and Answers
Question 1: A compliance officer is asked to evaluate a new product line that may involve BSA/AML obligations not currently covered by existing controls. What is the FIRST step in this process?
- File a Suspicious Activity Report with FinCEN
- Conduct a risk assessment specific to the new product's BSA/AML exposure (Correct answer)
- Immediately halt the product launch pending external legal review
- Update the existing control matrix to add BSA/AML fields
Correct answer: Conduct a risk assessment specific to the new product's BSA/AML exposure
Before designing or updating controls, a targeted risk assessment must identify the specific BSA/AML risks introduced by the new product line.
Question 2: Which control activity is specifically designed to verify that transactions are accurately captured and completely processed without loss or duplication?
- Physical access controls
- Reconciliation controls (Correct answer)
- Authorization controls
- Disclosure controls
Correct answer: Reconciliation controls
Reconciliation controls compare two independent sources of data to confirm that all transactions are recorded completely and accurately.
Question 3: An organization rates a compliance risk as 'accepted' despite it exceeding its stated risk tolerance. Which governance failure does this indicate?
- Inadequate risk identification methodology
- Misalignment between risk appetite policy and actual risk decisions (Correct answer)
- Failure to implement detective controls
- Ineffective use of Key Risk Indicators
Correct answer: Misalignment between risk appetite policy and actual risk decisions
Accepting a risk that exceeds stated tolerance without formal exception approval indicates a breakdown between the organization's documented policy and actual management behavior.
Question 4: Which scenario BEST illustrates an inherent risk that has been partially mitigated to produce a residual risk?
- A company avoids entering a high-risk market, eliminating exposure entirely
- A bank identifies high fraud potential in wire transfers and installs transaction limits, reducing but not eliminating exposure (Correct answer)
- An insurer pays a claim after a fraud event occurs
- An auditor confirms no material weaknesses exist in the financial close process
Correct answer: A bank identifies high fraud potential in wire transfers and installs transaction limits, reducing but not eliminating exposure
Installing transaction limits reduces the inherent fraud risk in wire transfers but does not eliminate it, leaving a residual risk the bank must still manage.
Question 5: A compliance testing program reveals that 15% of loan files are missing required disclosures. Which type of risk does this finding primarily represent?
- Strategic risk
- Operational and compliance risk (Correct answer)
- Market risk
- Liquidity risk
Correct answer: Operational and compliance risk
Missing required disclosures in loan files represent a failure in operational processes and create direct compliance risk under consumer protection regulations.
Question 6: A company conducts a control self-assessment (CSA). Which statement BEST describes the primary purpose of this exercise?
- To replace the annual external audit and reduce audit fees
- To enable business units to evaluate the design and effectiveness of their own controls (Correct answer)
- To identify suspected fraud for referral to law enforcement
- To satisfy external regulatory examination requirements
Correct answer: To enable business units to evaluate the design and effectiveness of their own controls
CSAs empower process owners to assess whether their controls are properly designed and operating effectively, fostering accountability at the operational level.
Question 7: Which element distinguishes a material weakness from a significant deficiency in the context of internal control over financial reporting?
- A material weakness is identified by external auditors; a significant deficiency is identified internally
- A material weakness creates reasonable possibility of material misstatement; a significant deficiency is less severe (Correct answer)
- A material weakness applies only to public companies; a significant deficiency applies to all entities
- A material weakness requires immediate regulatory disclosure; a significant deficiency requires no disclosure
Correct answer: A material weakness creates reasonable possibility of material misstatement; a significant deficiency is less severe
A material weakness is a deficiency, or combination of deficiencies, where there is a reasonable possibility that a material misstatement will not be prevented or detected, making it more severe than a significant deficiency.
A compliance officer is asked to evaluate a new product line that may involve BSA/AML obligations not currently covered by existing controls.
What is the FIRST step in this process?