80. What is the role of the board of directors regarding compliance policy?
Answer: C
The board of directors should establish a compliance function and approve the bank's policies for identifying, assessing, monitoring, reporting, and advising on compliance risk.
The board of directors plays a crucial role in establishing and approving the compliance policies that govern how compliance risks are managed within the organization. This includes ensuring that there are robust processes in place for identifying, assessing, and monitoring compliance risks.
A) The board of directors should be responsible for overseeing the management of the bank's compliance risk but not involved in establishing a compliance policy that explains the processes by which compliance risks are to be identified and managed throughout the organization.
This option is incorrect because it underestimates the board's role. The board is not only responsible for overseeing compliance risk management but also has the duty to establish and approve the compliance policy that details how risks are to be managed throughout the organization.
B) managing compliance risk when required.
This choice is vague and inadequate. While managing compliance risk is important, it does not encompass the proactive responsibilities of the board in establishing a compliance function and approving comprehensive policies that guide the organization’s compliance efforts.
C) The board of directors should establish a compliance function and approve the bank's policies for identifying, assessing, monitoring, reporting, and advising on compliance risk.
This option is correct. It highlights the essential responsibilities of the board in not only establishing the compliance function but also in approving policies that provide a framework for managing compliance risks effectively. This comprehensive approach ensures that the organization meets its legal and ethical obligations.
D) The compliance function must have sufficient authority, stature, independence, and resources to be effective on its own and should not have access to the board of directors.
This statement is misleading. While it is true that the compliance function should have independence and authority, it is incorrect to suggest that it should not have access to the board. Effective compliance requires communication and collaboration with the board to ensure that all compliance risks are adequately addressed.
Conclusion
The correct answer is definitive because it accurately reflects the essential role of the board of directors in establishing and approving compliance policies, which are critical for identifying and managing compliance risks. Other options fail either to recognize the board's proactive involvement in policy creation or mischaracterize the relationship between the compliance function and the board, leading to an incomplete understanding of compliance governance.