APRP Emerging Payment Risks 2 — Questions and Answers
Question 1: Which regulatory framework specifically governs stablecoin issuers in the US as of recent legislative proposals?
- Bank Secrecy Act amendments only
- State money transmitter licenses with potential federal overlay (Correct answer)
- Securities Exchange Act Section 12
- Gramm-Leach-Bliley Act Title V
Correct answer: State money transmitter licenses with potential federal overlay
Stablecoin issuers currently operate under state money transmitter licensing, while federal legislation has proposed adding a federal overlay requiring reserve backing and prudential supervision.
Question 2: A merchant notices an unusual spike in chargebacks originating from transactions made via a Buy Now, Pay Later (BNPL) provider. What is the most likely root cause?
- Friendly fraud by consumers exploiting BNPL's split payment structure (Correct answer)
- Excessive interchange fees triggering consumer disputes
- ACH return rate violations by the BNPL provider
- Incorrect MCC code assignment by the merchant acquirer
Correct answer: Friendly fraud by consumers exploiting BNPL's split payment structure
BNPL's deferred payment model creates incentives for friendly fraud, where consumers dispute charges after receiving goods to avoid installment payments.
Question 3: What is 'transaction laundering' in the context of emerging payment risks?
- Converting cryptocurrency proceeds into fiat currency through multiple exchanges
- An undisclosed merchant processing transactions through another merchant's account (Correct answer)
- A money mule network using peer-to-peer apps to layer illicit funds
- Structuring cash deposits below CTR thresholds across multiple banks
Correct answer: An undisclosed merchant processing transactions through another merchant's account
Transaction laundering occurs when an undisclosed merchant routes card transactions through a registered merchant's account, hiding the true nature of goods or services sold.
Question 4: Which feature of Central Bank Digital Currencies (CBDCs) poses the greatest privacy risk to payment ecosystem participants?
- Smart contract enforceability on CBDC transactions
- Full transactional visibility by the issuing central bank (Correct answer)
- Interoperability with private stablecoins
- Offline payment capability using NFC tokens
Correct answer: Full transactional visibility by the issuing central bank
CBDCs issued and tracked by central banks can give governments complete visibility into individual payment flows, raising significant civil liberties and surveillance concerns.
Question 5: An APRP candidate is analyzing risks in open banking ecosystems. Which threat vector is most unique to open banking compared to traditional payments?
- Card-not-present fraud during e-commerce checkout
- Third-party API exploitation exposing consumer account data (Correct answer)
- ATM skimming at physical bank branches
- Wire fraud through business email compromise
Correct answer: Third-party API exploitation exposing consumer account data
Open banking's reliance on third-party API access to consumer accounts creates novel attack surfaces where a compromised API or malicious third-party provider can expose broad account data.
Question 6: Which risk does 'pay-by-bank' (account-to-account payments) eliminate compared to card-based payments?
- Chargeback risk from card network dispute rules (Correct answer)
- ACH return risk from insufficient funds
- Regulatory compliance risk under Reg E
- Counterparty settlement risk with correspondent banks
Correct answer: Chargeback risk from card network dispute rules
Pay-by-bank transactions bypass card networks entirely, meaning merchants are not subject to card network chargeback rules, though other dispute mechanisms may still apply.
Question 7: A payment risk analyst is reviewing a DeFi lending protocol that integrates with fiat on-ramps. What is the primary BSA/AML concern?
- Lack of Fedwire connectivity for settlement
- Anonymity of smart contract counterparties making CDD impossible (Correct answer)
- Excessive transaction fees creating customer complaints
- Non-compliance with PCI DSS for stored card data
Correct answer: Anonymity of smart contract counterparties making CDD impossible
DeFi protocols typically involve pseudonymous or anonymous counterparties in smart contracts, making Customer Due Diligence (CDD) and beneficial ownership identification extremely difficult.
Which regulatory framework specifically governs stablecoin issuers in the US as of recent legislative proposals?