Audit & IIA
KYC & Regulations
Banking & Finance
Lending
IT, Investments & Broker/Dealer
100

This is the person or group that owns the day-to-day risks and controls in a process.

Management

100

This acronym refers to knowing who the customer is and understanding the nature and purpose of the relationship.

KYC—Know Your Customer.


100

This control helps prevent one person from initiating, approving, and recording the same transaction.

Segregation of duties.

100

A loan exception should be supported by rationale and approved by the proper delegated this.

Authority level.

100

Giving users only the access necessary to perform their job is called this.

Least privilege

200

Internal Audit should use this approach when determining which engagements deserve the most attention.

A risk-based approach.

200

An employee sees unusual activity and should never tell the customer that this may be filed.

A SAR.

200

A reconciliation is strongest when prepared by one person and reviewed by this type of person.

An independent reviewer.

200

An adverse-action notice cannot simply say, “You did not meet Bank policy.” It must provide these.

Specific reasons for the action taken.

200

This is the primary problem with shared system IDs.

Activity cannot be traced to an individual; accountability is lost.

300

This is not Internal Audit’s job: assess controls, identify risks, report observations, or own the corrective-action plan.

Own the corrective-action plan.

300

True or False: One red flag by itself always proves fraud or money laundering.

False—it may warrant review or escalation, but it does not prove wrongdoing.

300

A report supports a key control, but no one can explain where the data comes from or whether the full population is included. This is an issue with this.

IPE completeness and accuracy.

300

For a completed consumer credit application, Regulation B generally requires notification of action taken within this many days.

30 days

300

Before a significant system change goes into production, it should be approved, tested, and this.

Documented

400

For Internal Audit to remain independent, the CAE should have functional accountability to this governing body.

The Board or Audit Committee.

400

Under CIP, which is not one of the basic identifying items generally collected: name, date of birth, address, or occupation?

Occupation

400

A large, unsupported, round-dollar journal entry posted at month-end may indicate this type of risk.

Potential management override or an unsupported adjustment.

400

This independent credit-risk function assesses loan quality and helps identify deterioration or emerging issues after a loan is made.

Loan review.

400

A representative discusses a securities recommendation through personal text messages. This creates potential supervision and this concern.

Recordkeeping concern

500

An auditor is assigned to review a process they managed just last year. Before beginning work, the auditor should disclose this potential impairment to their:

Objectivity/independence—and have the work reassigned or otherwise independently safeguarded.

500

An employee may discuss a potential SAR only with authorized personnel who need to know—never with this person.

The customer/account holder (or the subject of the SAR).

500

A control report is used to evidence daily monitoring, but the report’s population excludes transactions processed after 5:00 p.m. This is primarily a failure of report this.

Completeness.

500

A lender has enough information to deny an application but is still missing another document. The lender cannot use “incomplete application” as the reason for denial; it must provide this instead.

The specific reason(s) for the credit denial.

500

A representative recommends an investment to a retail customer. Under Regulation Best Interest, the recommendation must be in the customer’s this—not merely suitable for the representative or firm.

Best interest.