โ† All CCEP Flashcard Decks

Risk Assessment & Monitoring Flashcards

7 cards from real CCEP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Assessment & Monitoring flashcards as text
  1. What is the primary purpose of a compliance 'heat map'?

    Answer: To visually represent risks by likelihood and impact for prioritization

    A compliance heat map plots risks on a grid of likelihood versus impact, enabling quick visual identification of the highest-priority risks.

  2. Which of the following BEST describes the 'three lines of defense' model as applied to compliance risk monitoring?

    Answer: Business operations, compliance/risk functions, and internal audit provide layered oversight

    The three lines model assigns risk ownership to business units (first line), compliance and risk management (second line), and internal audit (third line) for layered oversight.

  3. A company's compliance risk assessment reveals a high-impact risk with a very low likelihood of occurrence. What is the MOST appropriate response?

    Answer: Implement cost-effective monitoring controls and document the risk

    Low-likelihood but high-impact risks warrant cost-proportionate monitoring and documentation to ensure they are watched and can be acted upon if conditions change.

  4. When assessing corruption risk under the FCPA, which factor most significantly increases inherent risk for a multinational company?

    Answer: Operating in countries with high corruption perception index scores

    Countries with high corruption scores significantly increase the inherent risk of FCPA violations due to the prevalence of bribery in those environments.

  5. Which element is ESSENTIAL for a risk monitoring program to be considered effective under the DOJ's compliance program evaluation framework?

    Answer: The program must be continuously evaluated and improved based on performance data

    The DOJ expects compliance programs to be living systems that evolve based on testing, monitoring results, and lessons learned.

  6. An internal audit identifies a control that has been operating effectively for five years but is now outdated due to a regulatory change. What should a compliance officer do?

    Answer: Update or redesign the control to align with the current regulatory requirement

    Controls must be kept current with applicable regulations; an outdated control that no longer meets requirements must be updated or replaced promptly.

  7. What is the key distinction between 'risk tolerance' and 'risk appetite' in a compliance context?

    Answer: Risk appetite is the desired risk level; risk tolerance is the acceptable deviation from that level

    Risk appetite defines the desired level of risk, while risk tolerance specifies the permissible variation around that level before action is required.