APRP Regulatory Compliance 4 — Questions and Answers
Question 1: Which rule governs the liability shift for card-present counterfeit fraud in the U.S. EMV migration?
- NACHA Operating Rules
- Card network chargeback liability shift rule (Correct answer)
- Regulation Z dispute resolution rule
- PCI DSS Requirement 9
Correct answer: Card network chargeback liability shift rule
Card networks implemented a liability shift rule that transfers counterfeit fraud liability to whichever party in the transaction has not adopted EMV technology.
Question 2: Under FinCEN's Customer Due Diligence (CDD) Rule, which of the following is a required element for legal entity customers?
- Annual financial statement review
- Identification of beneficial owners with 25% or more ownership (Correct answer)
- On-site inspection of business premises
- Monthly transaction pattern analysis
Correct answer: Identification of beneficial owners with 25% or more ownership
FinCEN's CDD Rule requires financial institutions to identify and verify beneficial owners who own 25% or more of a legal entity customer.
Question 3: What is the primary purpose of a Suspicious Activity Report (SAR) in the payments context?
- To recover funds from fraudulent transactions
- To notify law enforcement of potentially illicit financial activity (Correct answer)
- To dispute chargebacks with card networks
- To report data breaches to regulators
Correct answer: To notify law enforcement of potentially illicit financial activity
SARs are filed with FinCEN to alert law enforcement about transactions that may involve money laundering, fraud, or other financial crimes.
Question 4: Which U.S. law requires financial institutions to maintain programs for identifying and reporting transactions involving proceeds of illegal activity?
- Gramm-Leach-Bliley Act
- Bank Secrecy Act (Correct answer)
- USA PATRIOT Act
- Fair Credit Reporting Act
Correct answer: Bank Secrecy Act
The Bank Secrecy Act (BSA) of 1970 establishes the legal foundation for AML programs, including recordkeeping and reporting requirements.
Question 5: An acquiring bank is held responsible for the fraudulent activity of one of its merchants. What compliance concept does this illustrate?
- Vicarious liability
- Respondeat superior
- Acquirer liability / merchant sponsorship (Correct answer)
- Strict products liability
Correct answer: Acquirer liability / merchant sponsorship
Acquirer liability means that acquiring banks are responsible for ensuring their sponsored merchants comply with card network rules and applicable laws.
Question 6: The Children's Online Privacy Protection Act (COPPA) affects payment companies when they:
- Process transactions over $1,000 for minors
- Collect personal information from children under 13 through their platforms (Correct answer)
- Offer prepaid cards to customers under 18
- Process payroll for employees under 18
Correct answer: Collect personal information from children under 13 through their platforms
COPPA requires parental consent before collecting personal information from children under 13, which can apply to payment platforms accessible to children.
Question 7: What does the term 'regulatory arbitrage' mean in the payments compliance context?
- Using different compliance frameworks in parallel for efficiency
- Structuring operations to exploit gaps or differences between regulatory regimes (Correct answer)
- Arbitrating disputes between regulators and financial institutions
- Calculating regulatory capital requirements across jurisdictions
Correct answer: Structuring operations to exploit gaps or differences between regulatory regimes
Regulatory arbitrage refers to structuring business activities to take advantage of less stringent regulations in certain jurisdictions or business models.
Which rule governs the liability shift for card-present counterfeit fraud in the U.S.
EMV migration?