APRP APRP Quality & Compliance 3 — Questions and Answers
Question 1: Under Regulation E, how many business days does a financial institution have to investigate a consumer's reported unauthorized electronic fund transfer?
- 5 business days
- 10 business days (Correct answer)
- 45 calendar days
- 60 calendar days
Correct answer: 10 business days
Regulation E requires institutions to complete an EFT error investigation within 10 business days, or provisionally credit the consumer's account while continuing investigation for up to 45 days.
Question 2: What is the primary purpose of an acquirer's merchant underwriting process from a compliance standpoint?
- To negotiate interchange rates
- To assess and mitigate financial and fraud risk before onboarding a merchant (Correct answer)
- To assign a merchant category code (MCC)
- To establish chargeback arbitration procedures
Correct answer: To assess and mitigate financial and fraud risk before onboarding a merchant
Merchant underwriting evaluates a prospective merchant's financial stability, business type, and risk profile to prevent acquirers from bearing undue liability.
Question 3: A payments company's compliance officer discovers that transaction monitoring rules have not been updated in 18 months despite the emergence of new fraud schemes. This is best described as a failure in:
- Model validation
- Key Risk Indicator (KRI) tracking
- Control environment maintenance (Correct answer)
- Customer due diligence
Correct answer: Control environment maintenance
Failure to update controls to address evolving risks represents a breakdown in the control environment, which requires ongoing maintenance and tuning.
Question 4: Which of the following best defines 'three lines of defense' in a payments risk management framework?
- Firewall, encryption, and tokenization layers
- Business operations, risk/compliance functions, and internal audit (Correct answer)
- Issuer, acquirer, and card network
- Fraud detection, chargeback management, and collections
Correct answer: Business operations, risk/compliance functions, and internal audit
The three lines of defense model assigns risk ownership to business lines (1st), oversight to risk and compliance functions (2nd), and independent assurance to internal audit (3rd).
Question 5: What is the significance of the 'MATCH' (Member Alert to Control High-Risk) list for merchant acquirers?
- It lists approved high-volume merchants eligible for reduced interchange
- It identifies merchants previously terminated for cause, such as fraud or excessive chargebacks (Correct answer)
- It tracks merchants with outstanding chargeback disputes
- It contains a registry of PCI-compliant merchants
Correct answer: It identifies merchants previously terminated for cause, such as fraud or excessive chargebacks
The MATCH list is a shared database acquirers must query before onboarding a new merchant to check if the merchant was previously terminated for risk-related reasons.
Question 6: Under the Durbin Amendment to the Dodd-Frank Act, interchange fee caps on debit card transactions apply to issuers with assets of at least:
- $1 billion
- $5 billion
- $10 billion (Correct answer)
- $50 billion
Correct answer: $10 billion
The Durbin Amendment's interchange cap applies to debit card issuers with consolidated assets of $10 billion or more.
Question 7: A compliance audit reveals a processor is routing transactions to avoid certain fraud screening rules. This practice is known as:
- Transaction laundering (Correct answer)
- Selective routing optimization
- Interchange downgrade management
- Risk-weighted processing
Correct answer: Transaction laundering
Transaction laundering (also called factoring) involves routing transactions through another merchant's account to circumvent fraud controls and compliance requirements.
Under Regulation E, how many business days does a financial institution have to investigate a consumer's reported unauthorized electronic fund transfer?