C4 Quality Assurance & Compliance 3 — Questions and Answers
Question 1: A VASP must conduct Enhanced Due Diligence (EDD) on a customer. Which scenario most clearly triggers this requirement?
- A customer makes their first deposit of $50
- A customer is identified as a Politically Exposed Person (PEP) (Correct answer)
- A customer requests email notifications
- A customer updates their mailing address
Correct answer: A customer is identified as a Politically Exposed Person (PEP)
Politically Exposed Persons (PEPs) pose higher corruption and bribery risks, triggering mandatory Enhanced Due Diligence under AML regulations worldwide.
Question 2: What is the primary purpose of a blockchain transaction's on-chain audit trail in a compliance investigation?
- To determine mining reward amounts
- To provide immutable, timestamped records of fund flows (Correct answer)
- To verify smart contract bytecode
- To measure network latency
Correct answer: To provide immutable, timestamped records of fund flows
The immutable, public ledger of a blockchain creates an audit trail that compliance investigators can use to trace the origin and destination of funds across time.
Question 3: Under the SEC's Howey Test, which element must be present for a digital asset to be classified as a security?
- The asset must be mineable
- Profits must be expected primarily from the efforts of others (Correct answer)
- The asset must be issued on a public blockchain
- The asset must have a fixed supply
Correct answer: Profits must be expected primarily from the efforts of others
The Howey Test requires an investment of money in a common enterprise with an expectation of profits derived primarily from the efforts of a third party for something to qualify as a security.
Question 4: A crypto firm's compliance officer receives a National Security Letter (NSL). What is the typical legal constraint associated with an NSL?
- It requires immediate public disclosure
- It comes with a gag order prohibiting disclosure (Correct answer)
- It mandates a 90-day response window
- It requires board approval before complying
Correct answer: It comes with a gag order prohibiting disclosure
NSLs typically include a non-disclosure (gag) order that prohibits the recipient from revealing that the letter was received, even to legal counsel in some cases.
Question 5: Which compliance framework specifically governs the security of payment card data that may be processed by crypto platforms accepting card payments?
- SOC 2 Type II
- PCI DSS (Correct answer)
- NIST CSF
- FedRAMP
Correct answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) applies to any entity that stores, processes, or transmits cardholder data, including crypto platforms accepting card purchases.
Question 6: What does 'proof of reserves' auditing verify for a centralized cryptocurrency exchange?
- The exchange's trading volume is accurate
- The exchange holds sufficient assets to cover all customer liabilities (Correct answer)
- The exchange's smart contracts are bug-free
- The exchange complies with KYC regulations
Correct answer: The exchange holds sufficient assets to cover all customer liabilities
Proof of reserves uses cryptographic techniques (often Merkle trees) to verify that an exchange's on-chain holdings are at least equal to its total customer deposits.
Question 7: Under FinCEN's regulations, within how many days must a US-based MSB file a SAR after initially detecting a suspicious transaction?
- 15 days
- 30 days (Correct answer)
- 45 days
- 60 days
Correct answer: 30 days
FinCEN requires MSBs to file a SAR within 30 days of initially detecting facts that may constitute a basis for filing, or 60 days if no suspect is identified.
A VASP must conduct Enhanced Due Diligence (EDD) on a customer.
Which scenario most clearly triggers this requirement?