โ† All AML Flashcard Decks

Regulatory Compliance & Legal Framework Flashcards

7 cards from real AML practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Regulatory Compliance & Legal Framework flashcards as text
  1. A company uses an ML model to screen job applicants. Under the NYC Automated Employment Decision Tool (AEDT) Law, employers must:

    Answer: Conduct annual bias audits and provide candidate notice before using the tool

    NYC Local Law 144 requires employers to conduct independent bias audits annually and notify candidates that an AEDT will be used in their evaluation.

  2. Which principle in the OECD AI Principles (2019) most directly addresses the obligation to provide recourse when AI systems cause harm?

    Answer: Accountability

    The OECD Accountability principle requires AI actors to be responsible for the proper functioning of AI systems and for addressing any harm they cause.

  3. In the context of US financial regulation, 'model risk' as defined by SR 11-7 includes which of the following?

    Answer: Adverse consequences from decisions based on incorrect or misused model outputs

    SR 11-7 defines model risk as the potential for adverse consequences from model errors, inappropriate use, or misapplication of model outputs in decision-making.

  4. The 'right to explanation' for automated decisions under GDPR is best characterized as:

    Answer: A right to meaningful information about the logic of automated processing and its significance

    GDPR's right to explanation provides individuals with meaningful information about how automated decisions work and their likely consequences, not full technical disclosure.

  5. The concept of 'human-in-the-loop' is mandated for high-risk AI systems under the EU AI Act primarily to:

    Answer: Ensure meaningful human oversight and the ability to intervene or override AI decisions

    The EU AI Act requires high-risk systems to allow human oversight so that operators can understand, monitor, and intervene in AI decisions to prevent harm.

  6. Which US law most directly regulates the use of ML models in consumer credit reporting and adverse action notices?

    Answer: Fair Credit Reporting Act (FCRA)

    FCRA governs how consumer report information is collected, used, and shared, and requires adverse action notices with reasons when ML-driven credit decisions negatively affect consumers.

  7. A global company seeks to transfer EU personal data used for ML training to a US data center. The most legally robust mechanism under current GDPR rules is:

    Answer: Using Standard Contractual Clauses (SCCs) combined with a Transfer Impact Assessment (TIA)

    Following Schrems II, SCCs supplemented by a Transfer Impact Assessment (TIA) are the primary compliant mechanism for transferring personal data from the EU to the US for ML workloads.