Internal Controls & Compliance Flashcards
7 cards from real CBA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Internal Controls & Compliance flashcards as text
Which control activity best addresses the risk of unauthorized access to a bank's core banking system?
Answer: Role-based access controls with periodic user access reviews
Role-based access controls limit system access to job-relevant functions, and periodic reviews ensure access remains appropriate as roles change.
Under COSO's Internal Control—Integrated Framework, which component involves an organization's values, ethics, and operating style?
Answer: Control Environment
The Control Environment is the foundation of internal control and encompasses the organization's tone, values, ethical standards, and management philosophy.
A bank's BSA/AML compliance program must include all of the following EXCEPT:
Answer: Annual external audits of all loan files
The four pillars of a BSA/AML program are: internal controls, a designated compliance officer, training, and independent testing—not annual external loan file audits specifically.
What is the primary purpose of a bank's Suspicious Activity Report (SAR) filing requirement?
Answer: To inform law enforcement of potential money laundering or criminal activity
SARs are filed with FinCEN to alert law enforcement of transactions that may involve money laundering, fraud, or other criminal activity.
During a compliance review, an auditor finds that a branch has been waiving overdraft fees for preferred customers without documented approval. This is BEST classified as:
Answer: A fair lending and consumer compliance concern
Inconsistent fee waivers for select customers without documented criteria can indicate discriminatory practices, violating fair lending laws such as the Equal Credit Opportunity Act.
Which control is MOST effective in preventing a teller from both initiating and approving their own cash transactions?
Answer: Separation of duties
Separation of duties ensures no single individual can initiate, approve, and record a transaction, reducing the risk of fraud or error.
A bank auditor is assessing the effectiveness of the institution's interest rate risk controls. Which document is MOST relevant to this review?
Answer: The Asset/Liability Management (ALM) policy
The ALM policy governs how the bank manages interest rate risk, including limits, measurement methods, and reporting requirements.