RCC Compliance Program Development and Implementation 2 — Questions and Answers
Question 1: Which element is considered the foundation of an effective compliance program according to the OIG Compliance Program Guidance?
- Written policies and procedures (Correct answer)
- Designated compliance officer
- Ongoing training and education
- Internal monitoring and auditing
Correct answer: Written policies and procedures
Written policies and procedures form the foundation because they document expected conduct and provide the basis for all other program elements.
Question 2: When developing a compliance risk assessment, which methodology is most appropriate for prioritizing identified risks?
- Alphabetical ranking of risk categories
- Likelihood-times-impact scoring matrix (Correct answer)
- Chronological order of regulatory issuance
- Staff headcount per department
Correct answer: Likelihood-times-impact scoring matrix
A likelihood-times-impact matrix allows organizations to prioritize risks by combining probability of occurrence with potential severity of harm.
Question 3: A compliance officer discovers that a business unit is bypassing the hotline and handling complaints internally without documentation. What is the primary concern?
- Increased phone costs for the department
- Loss of anonymity and potential retaliation against reporters (Correct answer)
- Reduced workload for the compliance team
- Faster resolution of minor issues
Correct answer: Loss of anonymity and potential retaliation against reporters
Internal handling without documentation risks retaliation against reporters and eliminates the confidentiality protections that encourage reporting.
Question 4: Under the U.S. Federal Sentencing Guidelines, which factor most significantly reduces an organization's culpability score after a compliance violation?
- Having a large legal department
- Self-reporting the offense before investigation (Correct answer)
- Operating in a heavily regulated industry
- Having no prior violations within five years
Correct answer: Self-reporting the offense before investigation
Self-reporting prior to a government investigation is the most significant mitigating factor and can substantially reduce an organization's culpability score.
Question 5: Which approach best ensures that compliance training is effective rather than merely completed?
- Requiring electronic acknowledgment of attendance
- Testing comprehension and tracking behavioral outcomes (Correct answer)
- Using the same training module annually
- Delegating training design to HR
Correct answer: Testing comprehension and tracking behavioral outcomes
Measuring comprehension through testing and tracking changes in behavior ensures training produces actual compliance improvements, not just completion records.
Question 6: A company's compliance committee meets quarterly but rarely escalates issues to the board. What governance gap does this represent?
- Insufficient meeting frequency
- Inadequate board-level oversight and accountability (Correct answer)
- Lack of external auditors
- Absence of a written charter
Correct answer: Inadequate board-level oversight and accountability
When issues are not escalated to the board, directors cannot exercise meaningful oversight, creating a critical governance gap in compliance accountability.
Question 7: Which principle guides the appropriate scope of a compliance investigation when an allegation involves a senior executive?
- The investigation should be narrowed to protect sensitive information
- Independent investigators should be used to avoid conflicts of interest (Correct answer)
- HR should lead all investigations regardless of seniority
- The accused should be informed immediately to allow a response
Correct answer: Independent investigators should be used to avoid conflicts of interest
When allegations involve senior leaders, independence is essential to ensure credibility and avoid conflicts of interest that could compromise the investigation's integrity.
Which element is considered the foundation of an effective compliance program according to the OIG Compliance Program Guidance?