AML Regulatory Compliance & Legal Framework 2 — Questions and Answers
Question 1: Under the EU AI Act, which risk category requires mandatory conformity assessments before deployment?
- Minimal risk
- Limited risk
- High risk (Correct answer)
- Prohibited risk
Correct answer: High risk
High-risk AI systems under the EU AI Act must undergo mandatory conformity assessments and meet strict requirements before market deployment.
Question 2: Which US federal agency primarily oversees algorithmic accountability in consumer financial products?
- FTC
- CFPB (Correct answer)
- SEC
- OCC
Correct answer: CFPB
The Consumer Financial Protection Bureau (CFPB) has primary authority over algorithmic models used in consumer lending, credit scoring, and financial products.
Question 3: The principle of 'legitimate interest' under GDPR is relevant to ML systems primarily because it:
- Eliminates the need for any user consent
- Provides a lawful basis for processing personal data when outweighed by subject rights (Correct answer)
- Allows unrestricted data retention
- Applies only to non-profit organizations
Correct answer: Provides a lawful basis for processing personal data when outweighed by subject rights
Legitimate interest can serve as a lawful basis for processing personal data in ML pipelines, but only when the controller's interests are not overridden by data subjects' rights.
Question 4: A company deploys an ML model that denies loans to applicants disproportionately from a protected class. Under US law, this most directly implicates:
- Sarbanes-Oxley Act
- Equal Credit Opportunity Act (ECOA) (Correct answer)
- Health Insurance Portability Act (HIPAA)
- Computer Fraud and Abuse Act (CFAA)
Correct answer: Equal Credit Opportunity Act (ECOA)
ECOA prohibits credit discrimination on the basis of protected characteristics, and disparate impact from ML models can trigger ECOA violations.
Question 5: Model documentation requirements under the Federal Reserve's SR 11-7 guidance apply to:
- Only externally facing customer models
- All models regardless of complexity or use
- Statistical models used for risk management decisions (Correct answer)
- Open-source models only
Correct answer: Statistical models used for risk management decisions
SR 11-7 defines a model broadly as a statistical, economic, or mathematical tool used for decision-making, requiring documentation and validation for all such tools in banking.
Question 6: What does 'algorithmic impact assessment' (AIA) most closely resemble in existing regulatory practice?
- Software penetration testing
- Environmental impact assessment (Correct answer)
- Financial stress testing
- Network vulnerability scanning
Correct answer: Environmental impact assessment
AIA is modeled conceptually on environmental impact assessments, systematically evaluating potential harms of algorithmic systems before and during deployment.
Question 7: Under the NIST AI Risk Management Framework (AI RMF), the 'Govern' function primarily addresses:
- Technical performance benchmarking
- Organizational policies, accountability structures, and culture for AI risk (Correct answer)
- Real-time model monitoring pipelines
- Dataset curation and labeling standards
Correct answer: Organizational policies, accountability structures, and culture for AI risk
The Govern function in NIST AI RMF establishes organizational context, accountability, and culture that enable effective AI risk management across the other functions.
Under the EU AI Act, which risk category requires mandatory conformity assessments before deployment?