Compliance Monitoring & Testing Flashcards
7 cards from real RCMS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Compliance Monitoring & Testing flashcards as text
A compliance monitoring plan should be updated MOST frequently in response to:
Answer: New or amended regulations, significant business changes, or emerging risk areas
The monitoring plan must remain aligned with the current regulatory environment and business risk profile, requiring updates as those change.
What is the MAIN difference between compliance monitoring and compliance auditing?
Answer: Monitoring is an ongoing, risk-based management activity; auditing is a periodic, independent assessment
Monitoring is a continuous, second-line management activity while auditing is a periodic, independent third-line assessment of overall control effectiveness.
A compliance officer notices a significant spike in customer complaints related to a specific product. Under a risk-based approach, this SHOULD trigger:
Answer: An escalation of monitoring intensity and a targeted compliance review of that product
Elevated complaints are a KRI signaling potential compliance risk and should trigger increased monitoring and a targeted review.
Which element is MOST critical to include in a corrective action plan (CAP) resulting from a monitoring finding?
Answer: A description of the finding, root cause, specific remediation steps, responsible owner, and target completion date
An effective CAP requires clear identification of the problem, its root cause, specific steps to fix it, accountability, and a timeline.
When designing a compliance test for a consumer lending disclosure requirement, the tester should FIRST:
Answer: Identify the specific regulatory requirements and map them to testable control attributes
Test design must begin with a clear understanding of the specific regulatory requirements before defining what to test and how to test it.
Under the COSO framework, which component MOST directly supports ongoing compliance monitoring activities?
Answer: Monitoring Activities
The COSO 'Monitoring Activities' component specifically covers ongoing evaluations and separate evaluations used to assess whether internal controls are present and functioning.
A compliance officer receives a request from a business line manager to delay reporting a monitoring finding to senior management until the business unit can self-remediate. The MOST appropriate response is to:
Answer: Decline and follow the established escalation and reporting protocols regardless of remediation status
Compliance reporting protocols exist to ensure timely transparency to senior management and must not be circumvented even when remediation is underway.