Regulatory Frameworks & Compliance Flashcards
7 cards from real Certified Internal Auditor practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Regulatory Frameworks & Compliance flashcards as text
Under the IIA's International Standards, an internal audit function must be independent from the activities it audits. This independence is primarily achieved through:
Answer: Organizational reporting relationships
Organizational independence is achieved when the chief audit executive reports functionally to the board (or audit committee), free from management interference.
A company operating in multiple states must comply with varying data privacy laws. Which US state law is most often used as a baseline due to its broad scope?
Answer: California Consumer Privacy Act (CCPA)
The CCPA (and its amendment CPRA) is the most comprehensive US state privacy law and is widely used as a baseline for multi-state compliance programs.
An auditor reviews a company's export control compliance program. Which US agency administers the Export Administration Regulations (EAR)?
Answer: Commerce Department (BIS)
The Bureau of Industry and Security (BIS) within the Commerce Department administers and enforces the Export Administration Regulations.
Which element is NOT typically included in a regulatory change management process?
Answer: Filing comments on proposed regulations
Filing comments on proposed regulations is a lobbying/advocacy activity, not a standard element of an internal regulatory change management process.
Under SEC Regulation FD (Fair Disclosure), companies are prohibited from:
Answer: Selectively disclosing material nonpublic information to certain investors
Reg FD prohibits selective disclosure of material nonpublic information to certain investors or analysts without simultaneous public disclosure.
A compliance officer finds that management is overriding established controls to meet financial targets. The MOST appropriate internal audit response is to:
Answer: Report the override to the audit committee as a significant deficiency
Management override of controls is a significant finding that must be escalated to the audit committee, as it undermines the control environment.
The Office of Inspector General (OIG) model compliance program guidance for healthcare organizations emphasizes which of the following as the cornerstone of an effective program?
Answer: Commitment by senior and middle management
OIG guidance consistently identifies management commitment and a strong ethical culture as the foundation upon which all other compliance elements depend.