35. Which of the options below is an indicator of potential insider activity that may warrant escalation for further investigation?

Answer: C, D

Explanation:

A relationship manager makes an exception to company policy and proceeds with onboarding a customer without documenting a passport for customer identification.

This situation indicates a potential insider threat as it reflects a disregard for established protocols that are essential for mitigating risks associated with customer identification. Such exceptions can lead to significant vulnerabilities in the company's compliance and risk management efforts.

A) An investigator does not complete the automated transaction monitoring system alerts assigned to them before the time required by company procedures

While this behavior may reflect poor time management or prioritization issues, it does not directly indicate insider activity that requires escalation. This option pertains to operational inefficiencies rather than malicious intent or risk to the organization.

B) An IT employee shares information about a firm's risk management framework with employees of other firms at an industry convention

This action could potentially lead to information leaks; however, it does not necessarily indicate insider activity requiring immediate investigation. Sharing at industry events may be common practice and does not inherently reflect a malicious intent or breach of policy.

C) A relationship manager makes an exception to company policy and proceeds with onboarding a customer without documenting a passport for customer identification

This behavior is a clear violation of company policies related to customer due diligence and presents a significant risk to the organization. It suggests a willingness to bypass critical compliance measures, which is a strong indicator of potential insider activity warranting further investigation.

D) A relationship manager advocates for overriding the results of the company's client risk rating model that resulted in a client's high-risk rating

This situation raises serious concerns as it demonstrates an attempt to manipulate established risk assessment protocols. Such actions can undermine the integrity of the firm's risk management framework and indicate potential insider activity that should be escalated for investigation.

Conclusion

Both options C and D represent significant breaches of protocol that could expose the organization to heightened risks. They highlight behaviors that not only disregard established policies but also suggest a potential intent to circumvent necessary controls. In contrast, options A and B do not inherently indicate insider threats, making C and D the definitive indicators requiring escalation.