CCM CCM Compliance Program Management 5 — Questions and Answers
Question 1: Which element is essential when drafting a compliance program charter?
- A list of all current regulatory fines
- Clear delineation of the compliance function's authority, independence, and reporting lines (Correct answer)
- The personal contact information of all regulators
- A history of industry-wide violations
Correct answer: Clear delineation of the compliance function's authority, independence, and reporting lines
A compliance charter must define the scope of authority, independence from business units, and reporting structure to give the function credibility and effectiveness.
Question 2: A company is expanding into a new high-risk international market. What compliance action should be taken first?
- Launch the business operations immediately to capture market share
- Conduct a jurisdictional compliance risk assessment before market entry (Correct answer)
- Copy the existing domestic compliance program verbatim
- Wait for a regulatory inquiry before developing local controls
Correct answer: Conduct a jurisdictional compliance risk assessment before market entry
Assessing the specific legal, regulatory, and cultural compliance risks of the new jurisdiction before entry allows tailored controls to be built in from the start.
Question 3: Which statement best describes the role of internal audit in relation to the compliance function?
- Internal audit and compliance are the same function with different titles
- Internal audit provides independent assurance over the effectiveness of compliance controls (Correct answer)
- Internal audit sets compliance policy for the organization
- Internal audit reports directly to the Chief Compliance Officer
Correct answer: Internal audit provides independent assurance over the effectiveness of compliance controls
Internal audit independently tests whether compliance controls are designed and operating effectively, providing an objective third line of defense.
Question 4: An organization's compliance hotline receives very few reports over a 12-month period. What is the most likely interpretation?
- The organization is fully compliant with all regulations
- Employees may fear retaliation or distrust the system, not necessarily that no issues exist (Correct answer)
- The compliance program is highly effective
- The hotline technology is working perfectly
Correct answer: Employees may fear retaliation or distrust the system, not necessarily that no issues exist
Low reporting volume often signals cultural or trust barriers rather than an absence of compliance concerns, and should prompt investigation into the reporting environment.
Question 5: Which practice best ensures that a compliance program remains current as regulations change?
- Reviewing the program only after a regulatory fine is issued
- Establishing a regulatory change management process with continuous horizon scanning (Correct answer)
- Delegating regulatory tracking entirely to outside counsel
- Updating policies once every five years on a fixed schedule
Correct answer: Establishing a regulatory change management process with continuous horizon scanning
A formal regulatory change management process with proactive horizon scanning ensures the program adapts continuously to new and amended requirements.
Question 6: When delivering compliance training to senior management, which approach is most effective?
- Use the same generic e-learning module provided to all staff
- Tailor content to their specific risk exposures, decision-making authority, and accountability obligations (Correct answer)
- Focus exclusively on general ethics concepts
- Limit training to a one-page written summary
Correct answer: Tailor content to their specific risk exposures, decision-making authority, and accountability obligations
Senior leaders face distinct compliance risks tied to their authority and accountability, so training must address their specific roles, decisions, and governance responsibilities.
Question 7: What is the primary purpose of a compliance program's disciplinary policy?
- To publicly shame employees who violate rules
- To reinforce accountability by consistently applying proportionate consequences for compliance violations (Correct answer)
- To replace civil or criminal penalties imposed by regulators
- To track the performance of the compliance team itself
Correct answer: To reinforce accountability by consistently applying proportionate consequences for compliance violations
A disciplinary policy demonstrates that violations have real consequences, reinforcing a culture of accountability and deterring future non-compliance.
Which element is essential when drafting a compliance program charter?