← All CSCP Flashcard Decks

Compliance Programs & Risk Management Flashcards

7 cards from real CSCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Compliance Programs & Risk Management flashcards as text
  1. Under SEC Rule 38a-1, what is the primary role of a mutual fund's Chief Compliance Officer (CCO)?

    Answer: Administer the fund's compliance policies and procedures

    SEC Rule 38a-1 requires registered investment companies to designate a CCO who administers the fund's policies and procedures designed to prevent violations of federal securities laws.

  2. Which risk management framework, developed by COSO, is most widely referenced in securities compliance programs for enterprise-wide risk assessment?

    Answer: COSO ERM Framework

    The COSO Enterprise Risk Management (ERM) Framework is the most widely adopted framework for integrating risk management with governance and strategy in financial services compliance programs.

  3. A broker-dealer's written supervisory procedures (WSPs) must be reviewed at minimum how frequently under FINRA rules?

    Answer: Annually

    FINRA rules require broker-dealers to conduct an annual review of their written supervisory procedures to ensure they remain current and effective.

  4. What is 'residual risk' in the context of a securities compliance risk assessment?

    Answer: Risk remaining after controls and mitigating measures are applied

    Residual risk is the level of risk that remains after an organization has implemented its risk controls and mitigation strategies, as opposed to inherent risk which exists before controls.

  5. Which element is NOT typically required in a broker-dealer's annual compliance report to senior management?

    Answer: A detailed audit of each registered representative's trades

    Annual compliance reports to senior management address program adequacy, material issues, and recommendations — not individual trade-by-trade audits of all registered representatives.

  6. In a compliance risk matrix, 'likelihood' combined with 'impact' is used to determine which of the following?

    Answer: The risk rating or priority score for each identified risk

    A compliance risk matrix uses the intersection of likelihood and impact to assign a risk rating, which helps prioritize which risks require immediate attention and resource allocation.

  7. A firm's compliance program fails to detect a pattern of unsuitable recommendations due to gaps in supervisory review. This scenario best illustrates which type of compliance failure?

    Answer: Control environment deficiency

    When supervisory reviews fail to catch violations, it reflects a deficiency in the control environment — the internal controls designed to detect and prevent misconduct are inadequate.

Compliance Programs & Risk Management Flashcards — CSCP Study Cards with Answers