APRP Emerging Payment Risks 4 β Questions and Answers
Question 1: Which emerging risk does 'ghost broking' represent in embedded insurance products bundled with payment cards?
- Fraudulent intermediaries sell fake insurance policies funded by cardholder interchange (Correct answer)
- Cardholders double-claim insurance from both the card benefit and a standalone policy
- Insurers deny claims citing the embedded nature of the coverage as non-binding
- Payment networks assume underwriting liability for card-linked insurance products
Correct answer: Fraudulent intermediaries sell fake insurance policies funded by cardholder interchange
Ghost broking involves fraudulent intermediaries who collect premiums for insurance policies that are either fake or quickly cancelled after issuance, leaving victims uninsured.
Question 2: In the context of AI-driven payment fraud detection, what is 'model drift' and why is it a risk?
- Gradual degradation of model accuracy as fraudster behavior evolves away from training data patterns (Correct answer)
- Unauthorized access to the ML model's weights by external threat actors
- Regulatory non-compliance when AI models replace human fraud analysts
- Excessive false positives causing customer friction during the model training period
Correct answer: Gradual degradation of model accuracy as fraudster behavior evolves away from training data patterns
Model drift occurs when fraud patterns in production diverge from the patterns the model was trained on, reducing detection accuracy as fraudsters adapt their tactics.
Question 3: A gig economy platform processes instant earnings disbursements to workers via debit card push-to-card. Which risk framework most directly applies to this activity?
- Mastercard Send and Visa Direct program rules governing push-to-card disbursements (Correct answer)
- Nacha Same-Day ACH operating rules for next-day payroll settlement
- Federal Reserve Regulation CC availability schedules for check holds
- OCC Interpretive Letter 1170 on permissible national bank activities
Correct answer: Mastercard Send and Visa Direct program rules governing push-to-card disbursements
Push-to-card disbursements via Visa Direct or Mastercard Send are governed by those networks' specific program rules, which set requirements for eligible card types, transaction limits, and originator obligations.
Question 4: What is the primary compliance risk when a payment facilitator (PayFac) onboards sub-merchants without adequate underwriting?
- The PayFac assumes liability for sub-merchant fraud and chargeback losses exceeding thresholds (Correct answer)
- Sub-merchants gain direct access to card network settlement without a merchant agreement
- The acquiring bank faces Reg E liability for unauthorized ACH debits by sub-merchants
- Card network rules require sub-merchants to obtain their own merchant IDs within 90 days
Correct answer: The PayFac assumes liability for sub-merchant fraud and chargeback losses exceeding thresholds
PayFacs are contractually liable to their acquirer for all fraud, chargebacks, and compliance violations of their sub-merchants, making inadequate onboarding underwriting a direct financial and regulatory risk.
Question 5: Which risk does 'SIM swapping' pose to multi-factor authentication used in mobile payment authorization?
- Attackers gain control of the victim's phone number, intercepting SMS-based OTPs to authorize payments (Correct answer)
- SIM cards become corrupted, preventing legitimate users from receiving payment notifications
- Duplicate SIM cards create conflicting authorization signals causing payment declines
- Mobile carriers gain visibility into OTP codes used for payment authentication
Correct answer: Attackers gain control of the victim's phone number, intercepting SMS-based OTPs to authorize payments
SIM swapping transfers a victim's phone number to an attacker-controlled SIM, allowing interception of SMS one-time passwords used as a second authentication factor for payment apps.
Question 6: An international remittance provider uses cryptocurrency rails to avoid correspondent banking fees. What is the primary OFAC compliance challenge?
- Screening wallet addresses against OFAC's SDN list when blockchain addresses are pseudonymous and change frequently (Correct answer)
- Calculating transaction values in USD when cryptocurrency prices fluctuate between initiation and settlement
- Reporting cryptocurrency transactions to FinCEN when no CTR threshold exists for digital assets
- Obtaining a specific license for cryptocurrency use from the Office of Foreign Assets Control
Correct answer: Screening wallet addresses against OFAC's SDN list when blockchain addresses are pseudonymous and change frequently
OFAC requires screening against its SDN list, but blockchain's pseudonymous wallet addresses can obscure sanctioned parties, and wallet addresses used by sanctioned entities may not be published promptly.
Question 7: What operational risk does 'banking-as-a-service' (BaaS) model concentration represent for fintechs?
- Reliance on a single sponsor bank whose regulatory enforcement action could immediately halt all fintech operations (Correct answer)
- Inability to offer FDIC-insured accounts because fintechs are not chartered banks
- Card network rules prohibiting non-bank entities from accessing payment rails directly
- State money transmitter licenses becoming invalid when a BaaS sponsor bank is used
Correct answer: Reliance on a single sponsor bank whose regulatory enforcement action could immediately halt all fintech operations
Fintechs using BaaS depend entirely on their sponsor bank's charter and regulatory standing; consent orders, license revocations, or bank failures directly interrupt the fintech's payment operations.
Which emerging risk does 'ghost broking' represent in embedded insurance products bundled with payment cards?