Regulatory Framework & Compliance Flashcards
7 cards from real RIMS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Regulatory Framework & Compliance flashcards as text
The Foreign Corrupt Practices Act (FCPA) creates compliance obligations for risk managers primarily related to:
Answer: Bribery of foreign government officials and accurate record-keeping
The FCPA prohibits bribing foreign government officials to obtain business and requires companies to maintain accurate books and records.
Which regulatory framework governs the privacy and security of protected health information (PHI) most relevant to employer-sponsored health plans?
Answer: HIPAA Privacy and Security Rules
HIPAA's Privacy and Security Rules establish federal standards for protecting PHI held by health plans, healthcare providers, and their business associates.
Under the Terrorism Risk Insurance Act (TRIA), what is the insurer's obligation when offering commercial property and casualty policies?
Answer: Insurers must make terrorism coverage available and disclose the premium charge separately
TRIA requires insurers to make terrorism coverage available to commercial policyholders and to separately disclose the premium for that coverage.
Which compliance concept describes an organization's obligation to report known violations of law to the government, even absent a specific statutory requirement to do so?
Answer: Voluntary self-disclosure
Voluntary self-disclosure involves an organization proactively reporting violations to regulators, often in exchange for reduced penalties and cooperation credit.
A risk manager is reviewing a surplus lines placement for a unique risk. What is the PRIMARY regulatory requirement before placing coverage with an unlicensed (non-admitted) insurer?
Answer: Diligent search requirement demonstrating the risk cannot be placed in the admitted market
Most states require a diligent search of the admitted market demonstrating the coverage is unavailable before a surplus lines placement is permissible.
The Nonadmitted and Reinsurance Reform Act (NRRA) of 2010 primarily streamlined which regulatory process?
Answer: Surplus lines tax collection and regulatory jurisdiction for multi-state risks
NRRA established that only the home state of the insured has regulatory jurisdiction and tax authority over surplus lines transactions for multi-state risks.
Under the EU's General Data Protection Regulation (GDPR), what is the maximum fine for the most serious violations?
Answer: €20 million or 4% of global annual turnover, whichever is higher
GDPR's most serious violations carry penalties up to €20 million or 4% of total global annual turnover of the preceding year, whichever is higher.