Regulatory Bodies
Hodge-Podge
Privacy & Data Security
Real-Life Compliance Scenarios - What action?
Money Movies
100

This U.S. agency oversees investment advisors managing over $100 million in assets.

What is the SEC?

100

What is the first thing an employee should do if they suspect a cybersecurity incident, such as a phishing email or ransomware pop-up?

What is immediately stop what you’re doing and report it to the Incident Response Lead (Mary)?

100

This rule requires RIAs to safeguard client non-public personal information and send annual privacy notices.

What is Regulation S-P?

100

A client accidentally emails you their Social Security number. What should you do?

What is notify compliance and ensure the information is stored securely or deleted appropriately?

100

In this 1983 comedy with Eddie Murphy and dan Ackroyd, a bet between two wealth brothers leads to chaos in the commodities market.

What is Trading Places?

200

This self-regulatory organization oversees broker-dealers.

What is FINRA?

200

The purpose of the Incident Response Plan is to do what three things when an incident occurs?

What are detect, contain, and recover?

200

When sending sensitive information via email, you should always do this.

What is encrypt the email or use a secure portal?

200

You are writing a client email and consider pasting their statement—including account numbers—into ChatGPT for wording help. 

What is “Do not upload PII; summarize generically or ask Compliance”?

200

The 2011 drama starring Kevin Spacey and Zachary Quinto takes places over 24 hours at a collapsing investment bank. 

What is Margin Call?

300

Registered investment advisors file this form annually with the SEC.

What is Form ADV?

300

Gifts to or from clients should be documented and approved to avoid this appearance.

What is impropriety or a conflict of interest?

300

When a third-party vendor may handle client data, this type of oversight is required before approval.

What is vendor due diligence?

300

A long-time client insists on bypassing standard wire request procedures. What’s your next step?

What is explain firm policy and escalate the request to compliance if needed?

300

This 2000 film starring Giovanni Ribisi and Vin Diesel depicts a shady brokerage pushing worthless stocks through boiler-room tactics.  

What is Boiler Room?

400

This is the government agency responsible for enforcing anti-money laundering laws.  

What is the Department of the Treasury?

400

Employees are required to promptly report these to compliance if they may impact their objectivity or duties to clients.

What are potential conflicts of interest?

400

This plan outlines how the firm will operate during and after a cybersecurity incident.

What is a business continuity and disaster recovery plan?

400

A vendor requests access to client files but is not on the approved vendor list.

What is “Decline and escalate to Compliance for review”?

400

This 2015 movie chronicles investors who profited from the 2008 housing collapse.  

What is The Big Short?

500

This law requires advisers to establish and maintain a written business continuity and succession plan.

What is the Investment Advisers Act of 1940 (under Rule 206(4)-7)?

500

This term refers to using non-public information for personal gain.

What is insider trading?

500

You must notify compliance if you believe this has occurred.

What is a data breach?

500

A coworker receives a suspicious MFA prompt and files syncing strangely. What should they do first?

What is “Report immediately and isolate the device”?

500

This 1987 Oliver Stone movie coined the phrase "Greed is good."

What is Wall Street?

M
e
n
u