← All AAP Flashcard Decks

Compliance and Audit Flashcards

6 cards from real AAP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Compliance and Audit flashcards as text
  1. The unauthorized entry return rate threshold (using codes R05, R07, R10, R29, R51) that triggers NACHA scrutiny is:

    Answer: 0.5% of debit entries originated

    The unauthorized return rate threshold is 0.5%—much stricter than the 15% overall threshold—because unauthorized entries indicate serious authorization failures.

  2. Regulation E primarily protects:

    Answer: Consumers from unauthorized electronic fund transfers

    Regulation E (Electronic Fund Transfer Act) establishes the rights of consumers and the responsibilities of financial institutions regarding unauthorized electronic fund transfers.

  3. Under Regulation E, a consumer must report an unauthorized transaction within what timeframe to receive maximum protection?

    Answer: 2 business days of learning of the loss or theft of an access device

    Reporting within 2 business days of learning of a lost or stolen access device limits consumer liability to $50; waiting longer increases potential liability.

  4. BSA/AML requirements that apply to ACH transactions include:

    Answer: Monitoring for suspicious activity and filing SARs when warranted

    Financial institutions must monitor ACH transactions for suspicious activity patterns and file Suspicious Activity Reports (SARs) with FinCEN when warranted under BSA requirements.

  5. OFAC compliance in ACH processing requires financial institutions to:

    Answer: Screen transactions against the SDN list and block or reject prohibited transactions

    Financial institutions must screen ACH transaction parties against OFAC's Specially Designated Nationals (SDN) list and block or reject any transactions involving prohibited parties.

  6. The ACH audit requirement under NACHA rules applies to:

    Answer: ODFIs, RDFIs, Third-Party Senders, and Third-Party Processors participating in the ACH network

    The annual ACH audit requirement applies broadly to all participants in the ACH network, including ODFIs, RDFIs, Third-Party Senders, and Third-Party Processors.