CMS Flashcards

1
Q

Outline the monitoring elements of the CMS.

A
  • compliance testing

* remediation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Once an exam finding root cause is determined, what is the next step?

A

determine the extent of the problem (scope)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is purpose of the Compliance Management System (CMS)?

A
  • manage regulatory compliance responsibilities
  • help the bank may risk-based decisions
  • help the bank correlate risk across the enterprise
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Once an exam finding has been analyzed to determine root cause and scope, what is the next step?

A

write an analysis for management explaining the situation

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What lines of defense collaboratively manage regulatory compliance risk?

A

1) business unit

2) governance oversight

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Outline the structure elements of the CMS.

A
  • mission statement
  • roles and responsibilities
  • compliance policies and procedures
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Once the bank is citied in an exam finding, what is the next step?

A

validate the finding

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the elements of risk identification?

A
  • Inherent Risk (before controls)
  • exposure
  • likelihood
  • Residual Risk (after controls)
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Explain the responsibilities of a compliance professional.

A
  • understand operating environment and risk tolerance
  • perform risk assessments (including recommendations for mitigants)
  • elevate unmitigated risk areas
  • provide reporting
  • review and revise policies and procedures
  • assist in correcting errors and providing training
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What are the “three lines of defense” for managing risk on an enterprise-wide basis?

A

1) business unit
2) governance oversight
3) internal or external audit

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Name the 6 primary risk management roles compliance professionals fill.

A
  • provide regulatory advice to help business units mitigate risks
  • regulatory change management
  • compliance monitoring
  • coordinate regulatory exams
  • oversee compliance training
  • review policies, procedures, and marketing materials
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What is the first step a compliance officer should do when a new product is launching?

A

perform a risk assessment to determine the bank’s level of risk in offering the new product

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the high-level purpose of an effective CMS framework?

A

Ensure management understands the bank’s level of compliance risks and any steps to mitigate them.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

How can compliance professionals formalize their risk mitigation system?

A

Risk Assessments

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Outline the compliance training elements of the CMS.

A
  • needs
  • timing
  • applicability
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What are the two types of controls?

A

1) preventative controls

2) detective controls

17
Q

If the business unit has decided on a plan of action to mitigate risk that the compliance officer feels is inadequate, what should be done?

A

nothing yet

The business unit can decide what level of risk to accept. If the high risk continues after mitigation, the problem can be escalated to senior management.

The job of the compliance officer is to assess the risks and inform management of those risks.

18
Q

Once a regulatory proposal becomes final, what are the first step to implement the rule?

A

establish a task force

Note: the question askes about ‘implementing’ the rule, not ‘analyzing’ the final rule

19
Q

What is risk likelihood?

A

the probability that an event will occur

20
Q

What are the basic elements of a CMS?

A
  • written program that addresses
  • structure
  • change management
  • monitoring (testing)
  • regulatory examinations
  • compliance training
  • reviews
  • risk assessment
21
Q

Outline the review elements of the CMS.

A
  • marketing materials
  • policies and procedures
  • disclosures
  • products and services
  • third party relationships
22
Q

Outline the change management elements of the CMS.

A
  • consultation
  • regulatory proposal impact
  • change implementation
23
Q

When evaluating a regulatory proposal, what are the first 3 steps?

A

1) analyze the proposal’s effect on the bank
2) provide a summary to the affected business unit
3) establish a task force to study the proposal

24
Q

What is risk exposure?

A

the extent of potential damage (severity)

25
Q

What are risk dependencies?

A

dependencies on other areas of the bank or third parties for controls

26
Q

Outline the regulatory examination elements of the CMS.

A
  • exam liaison
  • review findings
  • exam responses
  • remediation
27
Q

Once an exam finding is validated, what is the next step?

A

review policies and procedures to determine where failure occurred (root cause)

28
Q

What is the compliance officers most important role on a task force?

A

provide knowledge about compliance risk, such as whether a system is in compliance with relevant laws and regulations