RIMS Regulatory Compliance & Ethical Standards 2 — Questions and Answers
Question 1: Under the Sarbanes-Oxley Act (SOX), which section specifically requires CEOs and CFOs to certify the accuracy of financial reports?
- Section 302 (Correct answer)
- Section 404
- Section 906
- Section 101
Correct answer: Section 302
SOX Section 302 requires CEOs and CFOs to personally certify the accuracy and completeness of financial disclosures in periodic reports.
Question 2: A risk manager discovers that a vendor is offering gifts above the company's stated policy limit. The MOST ethical course of action is to:
- Accept the gift since it is from an approved vendor
- Decline the gift and report it to compliance (Correct answer)
- Accept the gift but disclose it later in an annual report
- Return half the gift to stay within policy limits
Correct answer: Decline the gift and report it to compliance
Ethical standards require declining gifts that exceed policy thresholds and reporting the incident to compliance to maintain integrity.
Question 3: Which federal law primarily governs the privacy of health information and directly impacts how risk managers handle employee benefits data?
- ERISA
- HIPAA (Correct answer)
- FCRA
- ADA
Correct answer: HIPAA
HIPAA (Health Insurance Portability and Accountability Act) sets national standards for protecting individually identifiable health information.
Question 4: The concept of 'conflict of interest' in risk management ethics MOST directly refers to:
- Disagreements between departments on risk tolerance
- A situation where personal interests could improperly influence professional decisions (Correct answer)
- Competing bids from multiple insurers
- Regulatory disagreements between state and federal authorities
Correct answer: A situation where personal interests could improperly influence professional decisions
A conflict of interest occurs when a professional's personal interests could compromise their objectivity or loyalty to their organization.
Question 5: Under RIMS ethical guidelines, confidential information obtained during the course of risk management work should be:
- Shared freely with industry peers to advance best practices
- Used only to benefit the risk manager's career
- Protected and disclosed only when authorized or legally required (Correct answer)
- Published anonymously to warn others in the industry
Correct answer: Protected and disclosed only when authorized or legally required
RIMS ethics require that confidential information be safeguarded and disclosed only with proper authorization or as required by law.
Question 6: The Foreign Corrupt Practices Act (FCPA) prohibits U.S. companies from:
- Competing with foreign companies in domestic markets
- Paying bribes to foreign government officials to obtain business (Correct answer)
- Importing goods from countries under trade sanctions
- Hiring foreign nationals without proper documentation
Correct answer: Paying bribes to foreign government officials to obtain business
The FCPA makes it unlawful for U.S. persons and entities to bribe foreign government officials to obtain or retain business.
Question 7: When a risk manager suspects that a colleague is submitting fraudulent insurance claims, the BEST ethical action is to:
- Confront the colleague directly and demand they stop
- Ignore it to avoid workplace conflict
- Report the suspicion through the appropriate internal compliance or ethics channel (Correct answer)
- Inform the insurer directly without notifying internal management
Correct answer: Report the suspicion through the appropriate internal compliance or ethics channel
Suspected fraud should be reported through established internal compliance or ethics channels to ensure proper investigation.
Under the Sarbanes-Oxley Act (SOX), which section specifically requires CEOs and CFOs to certify the accuracy of financial reports?