All Practice Exams

100+ Free CProf (SA) Practice Questions

CISA Compliance Professional CProf (SA) Board Examination practice questions are available now; exam metadata is being verified.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
100+ Questions
100% Free

Loading practice questions...

Same family resources

Explore More Compliance Institute Southern Africa Board Exams

Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.

Sample CProf (SA) Practice Questions

Try these sample questions to test your CProf (SA) exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1Under the Compliance Institute Southern Africa (CISA) Generally Accepted Compliance Practice (GACP) framework, which body holds ultimate accountability for the organization's compliance governance and risk appetite?
A.The Chief Compliance Officer (CCO)
B.The Board of Directors or Governing Body
C.The Audit and Risk Committee
D.The Internal Audit Department
Explanation: Under GACP framework principles and King IV governance standards, the Board of Directors or Governing Body holds ultimate accountability for compliance governance, ethics, and setting the organizational risk appetite. Executive officers implement and manage compliance, but governance responsibility cannot be abdicated. The Chief Compliance Officer manages the compliance function operational activities, while Audit and Risk oversight committees assist the board without relieving it of final accountability.
2According to GACP Principle 2, what is the primary purpose of a formal Compliance Charter approved by the governing body?
A.To specify annual performance targets for compliance officers
B.To define the authority, independence, role, and reporting lines of the compliance function
C.To document detailed step-by-step operational monitoring procedures
D.To list all regulatory fines incurred by the organization over the preceding reporting period
Explanation: A Compliance Charter establishes the formal authority, organizational independence, scope, responsibilities, and direct reporting lines of the compliance function to the board or its committee. It ensures the compliance officer can operate objectively without operational interference. Operational monitoring manuals contain granular procedures, whereas annual targets belong in performance management documents.
3Under King IV Corporate Governance principles in South Africa, how should compliance be integrated into the organization's broader risk management framework?
A.Compliance risk should be treated as a separate, isolated risk silo managed without reference to operational risk
B.Compliance risk should be integrated into the overarching enterprise risk management (ERM) framework and combined assurance model
C.Compliance risk should be delegated entirely to external legal counsel for risk assessment
D.Compliance risk should only be evaluated following a formal regulatory inspection or enforcement order
Explanation: King IV recommends an integrated approach to governance, risk, and compliance (GRC) where compliance risk is embedded within Enterprise Risk Management (ERM) and evaluated through a combined assurance model. Treating compliance in isolation creates blind spots, and delegating core risk oversight to external counsel violates internal control principles.
4In the GACP methodology, what distinguishes 'inherent compliance risk' from 'residual compliance risk'?
A.Inherent risk evaluates risk after controls are applied, while residual risk evaluates risk before controls
B.Inherent risk assesses exposure assuming no internal controls are in place, while residual risk is the remaining exposure after accounting for control effectiveness
C.Inherent risk applies only to financial penalties, while residual risk applies only to reputational damage
D.Inherent risk is determined by regulators, while residual risk is determined exclusively by external auditors
Explanation: Inherent compliance risk reflects the raw level of risk exposure prior to the application of internal controls, policies, or mitigating actions. Residual compliance risk is the remaining exposure after evaluating the design and operating effectiveness of internal controls.
5A financial institution in South Africa subject to the Financial Intelligence Centre Act (FICA) fails to verify the legal status of an ultimate beneficial owner (UBO) controlling 30% of a corporate client. Under FICA provisions, what type of non-compliance is this considered?
A.A technical accounting error carryover
B.A non-compliance failure under customer due diligence (CDD) obligations subject to administrative sanctions by the FIC or FSCA
C.A criminal offense under the Companies Act 71 of 2008 only
D.A permissive exception under South African common law
Explanation: Under FICA (Act 38 of 2001, as amended), accountable institutions must establish and verify the identity of beneficial owners holding 25% or more of voting rights or ownership. Failure to perform beneficial ownership verification violates customer due diligence statutory duties and incurs administrative penalties under Section 45C of FICA.
6Under the Financial Sector Regulation Act (FSRA) 9 of 2017 Twin Peaks regulatory model in South Africa, which authority regulates market conduct and fair treatment of financial customers?
A.The Prudential Authority (PA)
B.The Financial Sector Conduct Authority (FSCA)
C.The South African Reserve Bank (SARB) Financial Stability Committee
D.The National Credit Regulator (NCR)
Explanation: South Africa operates a 'Twin Peaks' regulatory framework under the FSRA. The Financial Sector Conduct Authority (FSCA) regulates market conduct, consumer protection, and business ethics, while the Prudential Authority (PA) located within the SARB oversees safety, soundness, and capital adequacy.
7When developing a Compliance Risk Management Plan (CRMP) under GACP Guidelines, what is the first essential step in the risk identification process?
A.Assigning internal audit resources to audit high-risk departments
B.Establishing and documenting a complete compliance universe of statutory laws, regulations, codes, and standards applicable to the entity
C.Calculating potential fines for regulatory non-compliance
D.Drafting disciplinary policy procedures for staff non-compliance
Explanation: The foundational step in constructing a CRMP is mapping the compliance universe — identifying all regulatory instruments, legislation, license conditions, industry codes, and statutory standards governing the business operations.
8Under Protection of Personal Information Act (POPIA) Act 4 of 2013 in South Africa, who bears statutory liability for ensuring lawful processing of personal information by an operator acting on behalf of the responsible party?
A.The external operator exclusively
B.The Information Regulator exclusively
C.The Responsible Party, who must ensure operator compliance through written contract and security safeguards
D.The individual Data Subject
Explanation: Under POPIA Sections 20 and 21, the Responsible Party retains ultimate statutory duty to ensure operators process personal data only with knowledge or authorization, under a written contract mandating security measures matching Section 19 standards.
9In a combined assurance framework recommended by King IV, what constitutes the 'Third Line' of defense?
A.Operational management implementing day-to-day internal controls
B.Risk management and compliance monitoring functions
C.Independent internal audit providing objective assurance to the audit committee
D.External regulatory inspectors conducting statutory audits
Explanation: In the standard Three Lines Model endorsed by King IV and internal audit standards: Line 1 is operational management; Line 2 is risk and compliance oversight; Line 3 is independent internal audit providing objective assurance to the board.
10Under GACP Principle 4, what operational reporting relationship is mandatory to maintain the Chief Compliance Officer's (CCO) independence?
A.The CCO must report functionally to the Chief Operating Officer for sales budget approval
B.The CCO must have direct, unimpeded access to the Board Chair or Audit and Risk Committee Chair
C.The CCO must obtain approval from line management before submitting compliance reports to regulators
D.The CCO must be subordinate to the Head of Legal Counsel
Explanation: To preserve independence and objectivity, GACP and King IV require that the Chief Compliance Officer has direct access to the Board Chair, CEO, or relevant Board Committee Chair without operational filtering by business management.

About the CProf (SA) Practice Questions

Verified exam format metadata for CISA Compliance Professional CProf (SA) Board Examination is pending. The practice questions above remain available while official exam length, timing, passing score, fee, and administrator details are reviewed.