APRP Regulatory Environment 3 — Questions and Answers
Question 1: Under NACHA Operating Rules, an Originating Depository Financial Institution (ODFI) that originates ACH debits is required to conduct which type of ongoing monitoring of its originators?
- Annual PCI DSS audits of originator systems
- Risk-based monitoring of originator return rates and transaction patterns (Correct answer)
- Monthly OFAC sanctions screening of all ACH batches
- Quarterly reviews of originator interchange revenue
Correct answer: Risk-based monitoring of originator return rates and transaction patterns
NACHA rules require ODFIs to perform risk-based monitoring of originators, including tracking return rates and identifying unusual patterns that signal potential fraud or rule violations.
Question 2: Which regulatory framework governs the issuance and use of prepaid cards under U.S. federal law?
- Regulation Z (Truth in Lending Act)
- Regulation E and the CFPB Prepaid Rule (Correct answer)
- PCI DSS Level 1 compliance standards
- Gramm-Leach-Bliley Act (GLBA)
Correct answer: Regulation E and the CFPB Prepaid Rule
The CFPB Prepaid Rule (an amendment to Regulation E) established comprehensive consumer protections for prepaid accounts including disclosure requirements and error resolution rights.
Question 3: The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requires financial institutions to protect which category of information?
- Publicly available corporate financial statements
- Nonpublic personal information (NPI) of consumers (Correct answer)
- Aggregate transaction volume data reported to regulators
- Interbank settlement records processed through Fedwire
Correct answer: Nonpublic personal information (NPI) of consumers
GLBA's Safeguards Rule requires financial institutions to develop and maintain a comprehensive information security program to protect consumers' nonpublic personal information (NPI).
Question 4: A currency transaction report (CTR) must be filed with FinCEN for cash transactions exceeding what threshold in a single business day?
- $1,000
- $5,000
- $10,000 (Correct answer)
- $25,000
Correct answer: $10,000
The BSA requires financial institutions to file a CTR for any currency transaction exceeding $10,000 conducted by or on behalf of the same person in a single business day.
Question 5: Under the Electronic Fund Transfer Act (EFTA), which of the following scenarios represents a 'preauthorized electronic fund transfer' requiring special consumer notice rights?
- A one-time ACH debit authorized by phone for a utility bill
- A recurring monthly mortgage payment debited automatically from a checking account (Correct answer)
- A point-of-sale debit card transaction at a grocery store
- A wire transfer initiated by the consumer at a bank branch
Correct answer: A recurring monthly mortgage payment debited automatically from a checking account
Preauthorized EFTs are recurring debits authorized in advance, such as automatic monthly payments, which trigger specific notice and stop-payment rights under EFTA/Regulation E.
Question 6: Which of the following is a key difference between Enhanced Due Diligence (EDD) and standard Customer Due Diligence (CDD) in AML compliance?
- EDD applies only to corporate accounts; CDD applies to all customers
- EDD requires deeper investigation and ongoing monitoring for higher-risk customers (Correct answer)
- CDD is mandated by OFAC; EDD is mandated by FinCEN
- EDD is a one-time process; CDD must be performed annually
Correct answer: EDD requires deeper investigation and ongoing monitoring for higher-risk customers
EDD involves more intensive scrutiny — such as verifying source of funds, senior management approval, and increased monitoring — for customers classified as higher risk than standard CDD covers.
Question 7: The FFIEC Examination Manual for retail payment systems is used primarily by which parties?
- Card network operators setting global interchange standards
- Federal and state examiners when assessing bank payment system risk management (Correct answer)
- Merchants disputing chargebacks with their acquiring banks
- Payment card brands auditing PCI DSS level-1 service providers
Correct answer: Federal and state examiners when assessing bank payment system risk management
The FFIEC (Federal Financial Institutions Examination Council) Retail Payment Systems booklet guides federal and state examiners in evaluating the risk management of payment systems at financial institutions.
Under NACHA Operating Rules, an Originating Depository Financial Institution (ODFI) that originates ACH debits is required to conduct which type of ongoing monitoring of its originators?