CCB Compliance Technology & RegTech 4 — Questions and Answers
Question 1: Which approach does SupTech (Supervisory Technology) represent from a regulator's perspective?
- Technology that firms use to comply with regulations
- Technology used by regulators to supervise financial institutions more efficiently (Correct answer)
- Software for managing compliance training programs
- A cybersecurity framework for regulatory data
Correct answer: Technology used by regulators to supervise financial institutions more efficiently
SupTech refers to technology adopted by regulators and supervisory authorities to enhance their ability to monitor, analyze, and enforce compliance across regulated entities.
Question 2: A compliance officer must ensure third-party RegTech vendors meet the firm's data security standards. What document BEST formalizes these requirements?
- A non-disclosure agreement (NDA)
- A vendor due diligence questionnaire and contractual data processing agreement (Correct answer)
- An internal compliance policy update
- A letter of intent from the vendor
Correct answer: A vendor due diligence questionnaire and contractual data processing agreement
A vendor due diligence questionnaire assesses security capabilities while a data processing agreement legally obligates the vendor to meet required security standards.
Question 3: What is 'model risk' in the context of RegTech compliance systems?
- The risk that a compliance model is too expensive
- The risk that a model produces inaccurate outputs that lead to incorrect compliance decisions or missed violations (Correct answer)
- The risk of model intellectual property theft
- The risk that regulators won't approve the model
Correct answer: The risk that a model produces inaccurate outputs that lead to incorrect compliance decisions or missed violations
Model risk is the potential for adverse outcomes resulting from errors in model design, assumptions, data, or use that cause incorrect compliance decisions.
Question 4: Under SR 11-7, which US federal guidance governs the management of model risk at banks, what are the two key elements of effective model risk management?
- Cost control and technology selection
- Robust model development and validation, plus sound model governance (Correct answer)
- Vendor selection and contract management
- Algorithm testing and IT security
Correct answer: Robust model development and validation, plus sound model governance
SR 11-7 requires effective model risk management through rigorous development and validation processes combined with strong governance policies and controls.
Question 5: Which scenario BEST illustrates the concept of 'compliance by design' using RegTech?
- Adding compliance checks after a product is launched
- Embedding automated compliance controls and limits directly into a product's technology architecture from inception (Correct answer)
- Hiring more compliance officers to review products post-launch
- Creating a compliance manual before product development begins
Correct answer: Embedding automated compliance controls and limits directly into a product's technology architecture from inception
Compliance by design integrates regulatory requirements into the technical architecture of a product or process from the start, preventing violations rather than detecting them later.
Question 6: A compliance officer reviews a vendor's SOC 2 Type II report. What does this report specifically attest to?
- The vendor's financial solvency
- The operating effectiveness of the vendor's controls over a defined period, typically 6-12 months (Correct answer)
- The vendor's compliance with AML regulations
- The accuracy of the vendor's marketing claims
Correct answer: The operating effectiveness of the vendor's controls over a defined period, typically 6-12 months
A SOC 2 Type II report provides independent attestation that a vendor's security, availability, and confidentiality controls operated effectively over a sustained review period.
Question 7: What is 'regulatory reporting automation' and what risk does it primarily mitigate?
- Automation of internal policies; mitigates training costs
- Automated generation and submission of required regulatory reports; mitigates manual errors and late filing penalties (Correct answer)
- Automation of customer onboarding; mitigates KYC costs
- Automated alert generation; mitigates false negative risk
Correct answer: Automated generation and submission of required regulatory reports; mitigates manual errors and late filing penalties
Regulatory reporting automation uses technology to extract, validate, and submit required reports to regulators, reducing human error and ensuring timely, accurate filings.
Which approach does SupTech (Supervisory Technology) represent from a regulator's perspective?