CCB Compliance Technology & RegTech 3 — Questions and Answers
Question 1: A compliance team is evaluating whether to build or buy a RegTech solution. Which factor most strongly favors a 'buy' decision?
- The firm has unique compliance processes not found elsewhere
- A mature vendor solution already addresses the firm's needs with proven regulatory acceptance (Correct answer)
- The firm wants full control over the source code
- Integration with legacy systems is straightforward
Correct answer: A mature vendor solution already addresses the firm's needs with proven regulatory acceptance
When a proven commercial solution meets the firm's needs and is already accepted by regulators, buying is typically faster and less risky than building a custom solution.
Question 2: Which technology is BEST suited for creating an immutable audit trail for compliance purposes?
- Relational database with soft deletes
- Distributed ledger / blockchain technology (Correct answer)
- Encrypted email archives
- PDF document management systems
Correct answer: Distributed ledger / blockchain technology
Blockchain's immutable, append-only distributed ledger creates tamper-evident records that are ideal for compliance audit trails.
Question 3: Under the EU AI Act, compliance AI systems classified as 'high-risk' are required to have which of the following?
- Open-source code availability
- Human oversight mechanisms and detailed documentation (Correct answer)
- Real-time government access to system outputs
- Annual third-party algorithm audits only
Correct answer: Human oversight mechanisms and detailed documentation
The EU AI Act mandates that high-risk AI systems include human oversight mechanisms, maintain detailed technical documentation, and undergo conformity assessments.
Question 4: A RegTech vendor claims their AML screening tool uses machine learning to reduce false positives by 60%. What should a compliance officer do BEFORE deploying it?
- Accept the vendor's claim and proceed to deployment
- Validate the claim using the firm's own data in a controlled pilot (Correct answer)
- Require the vendor to share their training data only
- Submit the tool to the regulator for pre-approval
Correct answer: Validate the claim using the firm's own data in a controlled pilot
Vendor claims must be independently validated using the firm's own data and transaction patterns before relying on the tool for compliance purposes.
Question 5: What is the primary purpose of an API gateway in a financial institution's RegTech architecture?
- To store regulatory documents securely
- To manage, secure, and route data flows between compliance systems and external services (Correct answer)
- To train machine learning models on transaction data
- To replace legacy core banking systems
Correct answer: To manage, secure, and route data flows between compliance systems and external services
An API gateway acts as a central control point that manages authentication, authorization, and data routing between internal systems and external RegTech services.
Question 6: Which compliance challenge does 'federated learning' help address in financial services?
- Automating suspicious activity reports
- Training AI models on sensitive data across institutions without sharing raw data (Correct answer)
- Managing multi-jurisdictional regulatory filings
- Standardizing KYC documentation formats
Correct answer: Training AI models on sensitive data across institutions without sharing raw data
Federated learning allows AI models to be trained across multiple institutions using distributed data without centralizing or sharing the underlying sensitive data.
Question 7: A firm's compliance monitoring system generates 10,000 alerts monthly but investigators can only review 1,000. What is this situation called?
- Alert suppression
- Alert fatigue and capacity mismatch (Correct answer)
- Regulatory arbitrage
- Model overfitting
Correct answer: Alert fatigue and capacity mismatch
Alert fatigue occurs when the volume of alerts exceeds investigative capacity, leading to prioritization challenges and risk of missed genuine suspicious activity.
A compliance team is evaluating whether to build or buy a RegTech solution.
Which factor most strongly favors a 'buy' decision?