RIMS Regulatory Framework & Compliance 3 — Questions and Answers
Question 1: The Foreign Corrupt Practices Act (FCPA) creates compliance obligations for risk managers primarily related to:
- Misrepresentation on insurance applications filed in foreign countries
- Bribery of foreign government officials and accurate record-keeping (Correct answer)
- Reinsurance arrangements with foreign carriers
- Import/export compliance for insured goods
Correct answer: Bribery of foreign government officials and accurate record-keeping
The FCPA prohibits bribing foreign government officials to obtain business and requires companies to maintain accurate books and records.
Question 2: Which regulatory framework governs the privacy and security of protected health information (PHI) most relevant to employer-sponsored health plans?
- Gramm-Leach-Bliley Act
- HIPAA Privacy and Security Rules (Correct answer)
- California Consumer Privacy Act
- FERPA
Correct answer: HIPAA Privacy and Security Rules
HIPAA's Privacy and Security Rules establish federal standards for protecting PHI held by health plans, healthcare providers, and their business associates.
Question 3: Under the Terrorism Risk Insurance Act (TRIA), what is the insurer's obligation when offering commercial property and casualty policies?
- Insurers must include terrorism coverage at no additional cost
- Insurers must make terrorism coverage available and disclose the premium charge separately (Correct answer)
- Insurers may exclude terrorism coverage without any disclosure requirement
- Federal government assumes all terrorism losses without insurer participation
Correct answer: Insurers must make terrorism coverage available and disclose the premium charge separately
TRIA requires insurers to make terrorism coverage available to commercial policyholders and to separately disclose the premium for that coverage.
Question 4: Which compliance concept describes an organization's obligation to report known violations of law to the government, even absent a specific statutory requirement to do so?
- Mandatory self-disclosure
- Voluntary self-disclosure (Correct answer)
- Proactive compliance certification
- Regulatory confession doctrine
Correct answer: Voluntary self-disclosure
Voluntary self-disclosure involves an organization proactively reporting violations to regulators, often in exchange for reduced penalties and cooperation credit.
Question 5: A risk manager is reviewing a surplus lines placement for a unique risk. What is the PRIMARY regulatory requirement before placing coverage with an unlicensed (non-admitted) insurer?
- Federal Reserve approval for transactions exceeding $1 million
- Diligent search requirement demonstrating the risk cannot be placed in the admitted market (Correct answer)
- State Attorney General notification within 30 days
- Policyholder must waive all state guarantee fund protections in writing
Correct answer: Diligent search requirement demonstrating the risk cannot be placed in the admitted market
Most states require a diligent search of the admitted market demonstrating the coverage is unavailable before a surplus lines placement is permissible.
Question 6: The Nonadmitted and Reinsurance Reform Act (NRRA) of 2010 primarily streamlined which regulatory process?
- Workers' compensation rate filings across multiple states
- Surplus lines tax collection and regulatory jurisdiction for multi-state risks (Correct answer)
- Reinsurance collateral requirements for domestic reinsurers
- State licensing requirements for insurance agents
Correct answer: Surplus lines tax collection and regulatory jurisdiction for multi-state risks
NRRA established that only the home state of the insured has regulatory jurisdiction and tax authority over surplus lines transactions for multi-state risks.
Question 7: Under the EU's General Data Protection Regulation (GDPR), what is the maximum fine for the most serious violations?
- €10 million or 2% of global annual turnover, whichever is higher
- €20 million or 4% of global annual turnover, whichever is higher (Correct answer)
- €50 million regardless of company size
- €5 million or 1% of EU revenue, whichever is lower
Correct answer: €20 million or 4% of global annual turnover, whichever is higher
GDPR's most serious violations carry penalties up to €20 million or 4% of total global annual turnover of the preceding year, whichever is higher.
The Foreign Corrupt Practices Act (FCPA) creates compliance obligations for risk managers primarily related to: