CCB Compliance Technology & RegTech 5 — Questions and Answers
Question 1: A firm implements a graph database to map relationships between clients, accounts, and transactions for AML purposes. What compliance capability does this PRIMARILY enhance?
- Automated SAR filing
- Network analysis to detect complex money laundering typologies involving multiple entities (Correct answer)
- Customer risk scoring based on demographics
- Regulatory report generation
Correct answer: Network analysis to detect complex money laundering typologies involving multiple entities
Graph databases excel at revealing hidden connections and relationships across entities, enabling detection of sophisticated layering and structuring schemes in AML investigations.
Question 2: Which principle from the BCBS 239 guidelines is MOST directly supported by RegTech data management solutions?
- Capital adequacy requirements
- Accuracy and integrity of risk data aggregation and reporting (Correct answer)
- Liquidity coverage ratio calculations
- Stress testing methodology
Correct answer: Accuracy and integrity of risk data aggregation and reporting
BCBS 239 requires banks to have strong risk data aggregation capabilities; RegTech data management solutions directly support accuracy, completeness, and timeliness of risk data.
Question 3: When deploying a cloud-based RegTech solution, which legal concept determines which country's data protection laws apply to customer data stored in that cloud?
- Regulatory arbitrage
- Data residency and data sovereignty requirements (Correct answer)
- Cloud service level agreements
- Cross-border licensing agreements
Correct answer: Data residency and data sovereignty requirements
Data residency and sovereignty rules determine the geographic location where data must be stored and which nation's laws govern its protection and access.
Question 4: A RegTech system flags a customer as high-risk based on an algorithmic score. The compliance officer disagrees. What governance principle requires documentation of this override?
- Segregation of duties
- Human-in-the-loop accountability and audit trail requirements (Correct answer)
- Dual control procedures
- Know Your Customer rule
Correct answer: Human-in-the-loop accountability and audit trail requirements
When humans override automated compliance decisions, accountability frameworks require documenting the rationale to maintain a complete and auditable record of compliance judgments.
Question 5: What is the main advantage of using synthetic data for testing compliance monitoring systems?
- Synthetic data is always more accurate than real data
- It allows testing with realistic patterns without exposing actual customer data and its associated privacy risks (Correct answer)
- Regulators prefer synthetic data in validation reports
- Synthetic data reduces system processing requirements
Correct answer: It allows testing with realistic patterns without exposing actual customer data and its associated privacy risks
Synthetic data mimics real transaction patterns while containing no actual customer information, enabling thorough system testing without violating data privacy regulations.
Question 6: Under the FFIEC's cybersecurity assessment framework, which domain specifically addresses the integration of cybersecurity with compliance and risk management processes?
- Threat Intelligence
- Cyber Risk Management and Oversight (Correct answer)
- External Dependency Management
- Incident Management and Resilience
Correct answer: Cyber Risk Management and Oversight
The Cyber Risk Management and Oversight domain of the FFIEC Cybersecurity Assessment Tool covers governance, risk management culture, and board-level accountability for cyber risks.
Question 7: A compliance officer is assessing a new AI-powered sanctions screening tool. Which evaluation factor is UNIQUE to AI-based tools compared to traditional rule-based systems?
- Integration with OFAC databases
- Explainability of match decisions and ongoing model drift monitoring (Correct answer)
- Speed of screening large transaction volumes
- Ability to screen multiple name variations
Correct answer: Explainability of match decisions and ongoing model drift monitoring
AI tools require ongoing monitoring for model drift and must provide explainable outputs, unlike rule-based systems where the decision logic is transparent and static.
A firm implements a graph database to map relationships between clients, accounts, and transactions for AML purposes.
What compliance capability does this PRIMARILY enhance?