โ† All CCS Flashcard Decks

Regulatory Compliance & Risk Management Flashcards

7 cards from real CCS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Regulatory Compliance & Risk Management flashcards as text
  1. Which federal agency is the primary enforcer of the Health Insurance Portability and Accountability Act (HIPAA) Privacy and Security Rules?

    Answer: Office for Civil Rights (OCR) within HHS

    The HHS Office for Civil Rights (OCR) is the primary federal agency responsible for enforcing HIPAA Privacy and Security Rules.

  2. A compliance program gap analysis is BEST described as:

    Answer: A comparison of current compliance practices against regulatory requirements or best practices

    A gap analysis compares an organization's current compliance practices against applicable requirements or standards to identify deficiencies requiring remediation.

  3. The concept of 'residual risk' in compliance refers to:

    Answer: Risk remaining after controls have been applied to inherent risk

    Residual risk is the level of risk that remains after an organization has implemented controls and other risk mitigation measures against the inherent risk.

  4. Under the Consumer Financial Protection Bureau (CFPB) framework, which exam procedure specifically evaluates whether institutions treat consumers fairly throughout the product lifecycle?

    Answer: UDAAP examination

    UDAAP (Unfair, Deceptive, or Abusive Acts or Practices) examinations assess whether financial institutions treat consumers fairly across marketing, sales, and servicing.

  5. Which element is considered the FOUNDATION of an effective compliance program according to the DOJ's evaluation guidance?

    Answer: Genuine commitment and tone from senior leadership

    The DOJ emphasizes that genuine commitment from senior leadership ('tone at the top') is the foundation without which other compliance program elements are ineffective.

  6. An organization identifies that a key vendor processes sensitive customer data with inadequate security controls. The MOST appropriate compliance response is to:

    Answer: Conduct a vendor risk assessment and require remediation with defined timelines

    Third-party risk management best practice requires assessing vendor controls and contractually requiring remediation of identified gaps within defined timelines.

  7. The COSO ERM 2017 framework emphasizes integrating risk management with:

    Answer: Strategy and performance management

    The 2017 COSO ERM framework specifically emphasizes the integration of enterprise risk management with strategy-setting and performance management.