← All CCE Flashcard Decks

Regulatory & Legal Framework Flashcards

6 cards from real CCE practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Regulatory & Legal Framework flashcards as text
  1. Under the FATF Travel Rule, a virtual asset service provider (VASP) transfers 1,050 USD worth of cryptocurrency to another VASP. The receiving VASP cannot identify the originator's beneficiary institution. According to FATF Recommendation 16, what is the CORRECT course of action for the receiving VASP?

    Answer: Apply a risk-based approach — it may execute the transaction but must adopt risk mitigation measures and consider filing a SAR

    FATF Recommendation 16 requires VASPs to obtain and transmit originator and beneficiary information for transactions at or above the threshold (USD/EUR 1,000). When required information is missing, the receiving VASP must apply a risk-based approach: it is not automatically required to reject, but must implement risk mitigation (e.g., enhanced due diligence) and consider filing a SAR. Blanket rejection is not mandated; instead, the institution exercises judgment proportional to risk.

  2. Under the EU's Markets in Crypto-Assets Regulation (MiCA), which category of crypto-asset is explicitly EXCLUDED from MiCA's scope?

    Answer: Crypto-assets that qualify as financial instruments under MiFID II

    MiCA Article 2(4) explicitly excludes crypto-assets that already qualify as financial instruments under MiFID II (such as tokenized securities), deposits, structured deposits, or insurance products from its scope. These assets remain regulated under existing EU financial law. E-money tokens issued by credit institutions, utility tokens, and ARTs backed by a single fiat currency are all within MiCA's scope (though with different requirements).

  3. The Howey Test is used in the United States to determine whether a crypto-asset is a security. Which of the following scenarios would MOST LIKELY cause a token that initially passed the Howey Test to subsequently fall outside the definition of a security over time?

    Answer: The network achieves sufficient decentralization such that no central party's efforts are essential to the token's value

    SEC Director William Hinman's 2018 speech articulated the concept that a token can start as a security but evolve out of that classification as the underlying network becomes sufficiently decentralized. When no central party's managerial efforts are the primary driver of value — the fourth prong of the Howey Test — the 'expectation of profits from others' element erodes. Market cap thresholds do not determine regulatory classification; SEC registration satisfies compliance but does not remove security status; and CFTC listing does not automatically transfer jurisdiction.

  4. A decentralized exchange (DEX) operates via immutable smart contracts with no company, legal entity, or identifiable operator behind it. Under the Bank Secrecy Act (BSA) and FinCEN guidance, which statement BEST describes the AML obligations of a U.S.-based developer who wrote and deployed these contracts?

    Answer: FinCEN's 2019 guidance indicates that merely writing and publishing software — without control over transmission — does not make someone an MSB, but the analysis is fact-specific and ongoing enforcement actions create legal uncertainty

    FinCEN's May 2019 guidance ('Application of FinCEN's Regulations to Certain Business Models Involving Convertible Virtual Currencies') distinguishes between those who merely publish software and those who control or operate a system that transmits value. A developer who solely writes and deploys immutable code without ongoing control may not meet the definition of an MSB. However, subsequent CFTC and OFAC enforcement actions (e.g., Tornado Cash) demonstrate significant and evolving legal uncertainty. The 'fact-specific' nature of the analysis — not bright-line thresholds or absolute speech protections — is the correct framing.

  5. Under the EU's Transfer of Funds Regulation (TFR) as amended to cover crypto-assets (effective 2023), what rule applies to transfers between a regulated VASP and an unhosted (self-custodied) wallet when the transfer amount exceeds EUR 1,000?

    Answer: The VASP must collect originator and beneficiary information, verify that the unhosted wallet belongs to its own customer, and apply enhanced due diligence measures

    The amended EU Transfer of Funds Regulation requires VASPs, for transfers exceeding EUR 1,000 to or from unhosted wallets, to collect information about the originator and beneficiary AND to verify that the unhosted wallet is actually controlled by their own customer (e.g., through cryptographic proof-of-ownership or micro-transaction verification). Standard KYC completion alone is insufficient — the wallet ownership link must be established. Transfers are not blanket-prohibited, and the EUR 1,000 threshold — not EUR 10,000 — triggers the enhanced requirements.

  6. OFAC's 2021 sanctions designation of Suex OTC and its 2022 designation of Tornado Cash established an important precedent in crypto enforcement. Which legal argument, raised in subsequent litigation (Van Loon v. Department of Treasury), challenged the Tornado Cash designation on constitutional grounds?

    Answer: That immutable smart contracts are not 'property' under IEEPA because they cannot be owned or controlled by any person, including their original developer

    The core legal argument in Van Loon v. Department of Treasury (5th Circuit, 2024) was that immutable, autonomous smart contracts — once deployed — cannot constitute 'property' of a foreign national under IEEPA (International Emergency Economic Powers Act) because no person, including the original developer, retains ownership or control over them. The 5th Circuit agreed with this reasoning regarding the immutable pool contracts, ruling that OFAC overstepped. This distinction between mutable (controlled) and immutable (autonomous) code is central to the case. First Amendment arguments, dollar thresholds, and SEC shareholder frameworks were not the primary basis of the ruling.