โ† All CVA Flashcard Decks

Regulatory Compliance & Audit Standards Flashcards

7 cards from real CVA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Regulatory Compliance & Audit Standards flashcards as text
  1. The National Credit Union Administration (NCUA) and the OCC require that BSA/AML compliance programs include independent testing. Which of the following best describes the independence requirement for this testing?

    Answer: Testing must be conducted by individuals not involved in day-to-day BSA compliance operations

    BSA/AML independent testing must be performed by personnel not responsible for day-to-day implementation of the AML program, ensuring objectivity in the evaluation.

  2. Under HIPAA, a Business Associate Agreement (BAA) is required when a covered entity shares Protected Health Information (PHI) with a vendor that:

    Answer: Performs functions on behalf of the covered entity that require access to PHI

    A BAA is required when a business associate performs functions or activities involving the use or disclosure of PHI on behalf of a HIPAA covered entity.

  3. A CVA auditing a mortgage company's HMDA compliance finds the institution failed to report loan application data for an entire calendar year. HMDA data collection and reporting is overseen by which agency?

    Answer: CFPB as the primary federal regulator under Dodd-Frank

    Under Dodd-Frank, the CFPB assumed primary responsibility for administering HMDA and collecting the data that financial institutions are required to report.

  4. Which sampling methodology is most appropriate when a CVA wants to ensure every item in a population has an equal chance of being selected for audit testing?

    Answer: Simple random sampling

    Simple random sampling ensures that every item in the population has an equal and independent chance of being selected, minimizing selection bias.

  5. Under the Red Flags Rule (FACTA Section 114), which entities are required to implement a written Identity Theft Prevention Program?

    Answer: Financial institutions and creditors with covered accounts

    The Red Flags Rule requires financial institutions and creditors that offer or maintain 'covered accounts' to implement an Identity Theft Prevention Program.

  6. During a verification audit, a CVA discovers that an employer has been using different I-9 List B documents depending on the applicant's perceived ethnicity. This practice violates:

    Answer: INA Section 274B anti-discrimination provisions

    Treating applicants differently in document acceptance during I-9 verification based on perceived ethnicity constitutes document abuse under INA Section 274B.

  7. A CVA reviewing a company's audit findings management process finds that high-risk findings from 18 months ago have no remediation owner assigned. This best represents a failure in:

    Answer: Audit finding remediation tracking and accountability

    Assigning remediation owners and tracking progress on high-risk audit findings to closure is a fundamental element of an effective audit finding remediation process.