APRP Regulatory Environment 5 — Questions and Answers
Question 1: A merchant based in the U.S. processes credit card transactions for customers in the EU and stores cardholder data. Which two frameworks are most directly relevant to its compliance obligations?
- NACHA Operating Rules and Regulation CC
- PCI DSS and GDPR (Correct answer)
- BSA/AML and Regulation E
- FFIEC guidance and the RFPA
Correct answer: PCI DSS and GDPR
PCI DSS governs the security of cardholder data globally, while GDPR applies to the personal data of EU residents regardless of where the processing company is located.
Question 2: Which federal agency has supervisory authority over state-chartered banks that are NOT members of the Federal Reserve System?
- OCC
- FDIC (Correct answer)
- CFPB
- FinCEN
Correct answer: FDIC
The FDIC has primary federal supervisory authority over state-chartered banks that are not members of the Federal Reserve System (state non-member banks).
Question 3: In the context of AML risk assessments, 'geographic risk' for a payments company is most directly increased by:
- High transaction volume during peak holiday shopping seasons
- Customers or transactions linked to FATF high-risk or non-cooperative jurisdictions (Correct answer)
- Operating in states with fewer than five money transmitter license requirements
- Processing a high proportion of card-not-present transactions domestically
Correct answer: Customers or transactions linked to FATF high-risk or non-cooperative jurisdictions
FATF (Financial Action Task Force) designates certain jurisdictions with strategic AML/CFT deficiencies, and transactions involving these high-risk countries elevate geographic risk in AML assessments.
Question 4: Under card network chargeback rules, which regulatory body has authority to impose fines on a card network (e.g., Visa or Mastercard) for systemic rule violations?
- FinCEN
- The card networks are self-regulatory with no external governmental fine authority over rules (Correct answer)
- The CFPB under Dodd-Frank authority
- The OCC under the National Bank Act
Correct answer: The card networks are self-regulatory with no external governmental fine authority over rules
Card network chargeback and operating rules are self-regulatory frameworks enforced by the networks themselves; no government agency has direct authority to fine networks for chargeback rule violations specifically.
Question 5: The Unlawful Internet Gambling Enforcement Act (UIGEA) of 2006 primarily impacts payment processors by:
- Requiring them to obtain gambling licenses in states where they process betting transactions
- Prohibiting them from knowingly processing payments for unlawful internet gambling transactions (Correct answer)
- Mandating quarterly reporting of all gaming-related merchant revenues to FinCEN
- Exempting daily fantasy sports platforms from all payment processing restrictions
Correct answer: Prohibiting them from knowingly processing payments for unlawful internet gambling transactions
UIGEA makes it illegal for payment processors, banks, and credit card companies to knowingly process payments for unlawful internet gambling, creating a due diligence obligation to identify and block such transactions.
Question 6: Which of the following best describes the 'four-pillar' framework of an effective AML compliance program as required by the BSA?
- Policies/procedures, internal controls, independent testing, and a designated compliance officer (Correct answer)
- SAR filing, CTR filing, OFAC screening, and CDD procedures
- Risk assessment, transaction monitoring, employee training, and board reporting
- Customer onboarding, ongoing monitoring, EDD, and exit procedures
Correct answer: Policies/procedures, internal controls, independent testing, and a designated compliance officer
The BSA requires AML programs to include internal policies/procedures/controls, a designated BSA compliance officer, ongoing employee training, and independent testing (audit).
Question 7: When a U.S. payment company acquires a foreign money transfer company operating in sanctioned-country corridors, the acquiring company's most immediate OFAC compliance obligation is to:
- File a SAR with FinCEN disclosing all historical transactions in those corridors
- Conduct a sanctions risk assessment and ensure prohibited transactions are blocked or unwound (Correct answer)
- Apply for a blanket OFAC general license covering the acquired entity's operations
- Notify the acquiring bank and request a 90-day compliance grace period
Correct answer: Conduct a sanctions risk assessment and ensure prohibited transactions are blocked or unwound
Upon acquisition, the acquiring company inherits sanctions exposure and must immediately assess sanctions risk, block any ongoing prohibited transactions, and may need to apply for specific licenses or wind down prohibited activities.
A merchant based in the U.S. processes credit card transactions for customers in the EU and stores cardholder data.
Which two frameworks are most directly relevant to its compliance obligations?