Certified Regulatory Compliance Manager (CRCM) — Questions and Answers
Question 1: The Fair Debt Collection Practices Act (FDCPA) restricts debt collectors from contacting consumers:
- At any time if the consumer has an outstanding balance
- During business hours without a court order
- Before 8 a.m. or after 9 p.m. local time (Correct answer)
- More than once per week for each debt
Correct answer: Before 8 a.m. or after 9 p.m. local time
The FDCPA prohibits debt collectors from contacting consumers before 8 a.m. or after 9 p.m. in the consumer's local time zone.
Question 2: Under the Fair Debt Collection Practices Act (FDCPA), a debt collector may NOT contact a consumer:
- Before 8 AM or after 9 PM local time (Correct answer)
- More than twice per week
- At the consumer's place of employment under any circumstance
- On weekdays between 9 AM and 5 PM
Correct answer: Before 8 AM or after 9 PM local time
The FDCPA prohibits debt collectors from contacting consumers before 8 AM or after 9 PM in the consumer's local time zone.
Question 3: A compliance software vendor claims their tool requires 500 function points to build. Under IFPUG, what additional information is needed to convert this to an effort estimate?
- The programming language chosen for implementation
- The number of regulatory agencies the tool must report to
- The number of end users who will access the system
- A productivity rate expressed as function points per person-month for the specific context (Correct answer)
Correct answer: A productivity rate expressed as function points per person-month for the specific context
Function points are a size measure; converting to effort requires a productivity rate that relates size to the effort needed in a given organizational context.
Question 4: Which bank products are NOT governed by the Interagency Statement on Retail Sales of Nondeposit Investment Products' disclosure requirements?
- Fixed-rate annuities
- Variable-rate savings accounts (Correct answer)
- Variable-rate annuities
- Mutual funds
Correct answer: Variable-rate savings accounts
Variable-rate savings accounts are NOT subject to the disclosure provisions of the Interagency Statement on Retail Sales of Nondeposit Investment Products.
Question 5: Under HMDA (Home Mortgage Disclosure Act), financial institutions must collect and report data to:
- Determine deposit insurance eligibility
- Set maximum loan amounts by geography
- Identify possible discriminatory lending patterns and community credit needs (Correct answer)
- Verify borrower income and assets
Correct answer: Identify possible discriminatory lending patterns and community credit needs
HMDA data is used by regulators and the public to identify discriminatory lending patterns and assess whether institutions are meeting community credit needs.
Question 6: Under the CARD Act (Credit CARD Act of 2009), credit card issuers must provide how much advance notice before increasing an interest rate?
- 15 days
- 60 days
- 10 days
- 45 days (Correct answer)
Correct answer: 45 days
The CARD Act requires 45 days advance notice before a credit card issuer can increase an interest rate or make other significant changes.
Question 7: A regulatory compliance system's External Input adds a record to one ILF, updates a second ILF, and references an EIF for validation. What is the File Type Referenced (FTR) count for this EI?
- 3 (two ILFs maintained plus one EIF referenced) (Correct answer)
- 4 (each field in each file counts as a separate FTR)
- 1 (only the EIF counts as an FTR for an EI)
- 2 (only the ILFs that are maintained count as FTRs)
Correct answer: 3 (two ILFs maintained plus one EIF referenced)
For an EI, FTRs include all ILFs maintained and all EIFs referenced during processing, so 2 maintained ILFs plus 1 referenced EIF equals 3 FTRs.
Question 8: A bank's BSA/AML compliance program must include which four pillars as required by federal regulation?
- Internal controls, independent testing, designated BSA officer, and customer due diligence (Correct answer)
- Customer identification, due diligence, enhanced due diligence, and SAR filing
- Board oversight, risk assessment, monitoring, and reporting
- Policies, procedures, training, and audit
Correct answer: Internal controls, independent testing, designated BSA officer, and customer due diligence
The four required BSA/AML program pillars are internal controls, independent testing (audit), a designated BSA compliance officer, and training.
Question 9: The principle of 'data minimization' in information security compliance means:
- Using the smallest possible servers for data storage
- Reducing the font size of privacy notices to save paper
- Minimizing the number of employees who receive data security training
- Collecting and retaining only the personal data necessary for a specific purpose (Correct answer)
Correct answer: Collecting and retaining only the personal data necessary for a specific purpose
Data minimization means limiting data collection and retention to only what is necessary for the stated business purpose, reducing exposure risk.
Question 10: Under the Real Estate Settlement Procedures Act (RESPA), which section prohibits kickbacks and unearned fees in connection with federally related mortgage loans?
- Section 6
- Section 8 (Correct answer)
- Section 12
- Section 10
Correct answer: Section 8
RESPA Section 8 prohibits giving or accepting fees, kickbacks, or anything of value in exchange for referrals of settlement service business.
Question 11: Regulation E disclosures MUST be given at the time of account opening when creating a deposit account online, or:
- Before the first EFT occurs (Correct answer)
- Within three business days of account opening
- Along with the first periodic statement
- Within three business days of a customer's request for the EFT service
Correct answer: Before the first EFT occurs
When opening a deposit account online, Regulation E disclosures must be provided either at the time of account opening or before the first Electronic Fund Transfer (EFT) occurs. Regulation E, which is part of the Electronic Fund Transfer Act (EFTA) in the United States, establishes the rights and responsibilities of consumers and financial institutions regarding electronic transfers of funds.
Question 12: Under Regulation O, which types of loans require prior board of directors approval?
- All mortgage loans regardless of borrower
- All consumer loans over $50,000
- Extensions of credit to executive officers, directors, and principal shareholders above certain thresholds (Correct answer)
- All unsecured business loans to bank customers
Correct answer: Extensions of credit to executive officers, directors, and principal shareholders above certain thresholds
Regulation O requires board approval for extensions of credit to insiders (executive officers, directors, principal shareholders) that exceed specific thresholds.
Question 13: A regulatory compliance project manager uses IFPUG function point counts to establish a software cost model. Which risk does the CRCM need to flag regarding this approach?
- IFPUG prohibits use of FP counts in cost estimation models
- Cost models based on FP counts require ISO 27001 certification to be valid
- Historical productivity data used in the model must come from comparable projects or the estimates will be unreliable (Correct answer)
- Function point counts automatically adjust for regulatory overhead costs
Correct answer: Historical productivity data used in the model must come from comparable projects or the estimates will be unreliable
Cost models derived from FP counts are only reliable when the underlying productivity rates come from similar projects; mismatched benchmarks produce inaccurate estimates.
Question 14: A bank's 'compliance risk appetite' statement describes:
- The bank's target ROE before compliance costs
- The number of regulatory findings the bank expects per examination cycle
- The bank's preferred compliance software vendor
- The level and type of compliance risk the board is willing to accept in pursuit of its strategy (Correct answer)
Correct answer: The level and type of compliance risk the board is willing to accept in pursuit of its strategy
A compliance risk appetite statement formally documents the board's tolerance for compliance risk, guiding resource allocation and strategic decisions.
Question 15: Which regulation implements the Home Mortgage Disclosure Act (HMDA)?
- Regulation C (Correct answer)
- Regulation Z
- Regulation X
- Regulation B
Correct answer: Regulation C
Regulation C is the CFPB's implementing regulation for the Home Mortgage Disclosure Act.
Question 16: Under the Gramm-Leach-Bliley Act's Safeguards Rule, financial institutions are required to:
- Hire a Chief Information Security Officer with at least 10 years of experience
- Develop, implement, and maintain a comprehensive information security program (Correct answer)
- Encrypt all customer data with AES-256 by default
- Report all data incidents to FinCEN within 24 hours
Correct answer: Develop, implement, and maintain a comprehensive information security program
The GLBA Safeguards Rule requires financial institutions to have a written comprehensive information security program protecting customer financial information.
Question 17: Which privacy concept requires that personal data be used only for the purposes for which it was originally collected?
- Retention scheduling
- Data portability
- Purpose limitation (Correct answer)
- Data minimization
Correct answer: Purpose limitation
Purpose limitation is the principle that personal data should only be processed for the specific purposes disclosed at the time of collection.
Question 18: Under the interagency guidelines for safeguarding customer information, financial institutions must conduct which activity to identify risks to customer data?
- A customer survey on data handling preferences
- An annual external penetration test only
- A quarterly review of employee social media accounts
- A risk assessment to identify reasonably foreseeable risks (Correct answer)
Correct answer: A risk assessment to identify reasonably foreseeable risks
The interagency guidelines require financial institutions to conduct a risk assessment to identify and evaluate internal and external risks to customer data security.
Question 19: Under the CRA service test for large banks, examiners evaluate:
- Whether the bank has met its minimum community development loan targets
- The accessibility and distribution of retail delivery systems and the range of community development services provided (Correct answer)
- Exclusively the bank's mobile banking and online service delivery channels
- The profitability of the bank's retail service network in LMI census tracts
Correct answer: The accessibility and distribution of retail delivery systems and the range of community development services provided
The service test evaluates how accessible the bank's retail delivery systems (branches, ATMs) are to LMI individuals and areas, as well as the extent and innovativeness of community development services provided.
Question 20: A notification to customers affected by a data breach is required under:
- A combination of federal agency guidance and state data breach notification laws (Correct answer)
- BSA/AML regulations exclusively
- HMDA reporting requirements
- The Community Reinvestment Act
Correct answer: A combination of federal agency guidance and state data breach notification laws
Data breach notifications are governed by both federal agency guidance (OCC, FDIC, Federal Reserve) and state-level data breach notification statutes.
Question 21: Under ECOA, an adverse action notice must include:
- The amount the borrower was approved for instead
- The borrower's credit score only
- Only the creditor's contact information
- The specific reasons for denial or a statement that reasons are available upon request (Correct answer)
Correct answer: The specific reasons for denial or a statement that reasons are available upon request
Adverse action notices must state specific reasons for the adverse action or inform the applicant they may request the reasons within 60 days.
Question 22: Which IFPUG concept most closely aligns with a compliance manager's concern about measuring the true business value delivered by a software project?
- Technical complexity adjustments based on system architecture
- Functional size, which measures user-visible functionality independent of implementation (Correct answer)
- Defect density as a measure of software quality
- Lines of code as a proxy for development investment
Correct answer: Functional size, which measures user-visible functionality independent of implementation
Functional size captures the amount of business functionality delivered to users, making it the most business-relevant IFPUG measure for compliance managers.
Question 23: A compliance officer reviewing an IFPUG count finds that the counting team included the same data group as both an ILF and an EIF. Which IFPUG rule does this violate?
- The CPM permits dual-counting when regulatory data is involved
- EIFs and ILFs may share the same data group if they have different RET structures
- An ILF can also be counted as an EIF if referenced by more than one transaction
- A data group maintained by the application cannot simultaneously be counted as an EIF for the same application (Correct answer)
Correct answer: A data group maintained by the application cannot simultaneously be counted as an EIF for the same application
IFPUG rules state that if data is maintained by the application being counted, it is an ILF for that application and cannot also be an EIF within the same count.
Question 24: What is the term for the compliance risk management framework that includes policies, procedures, training, monitoring, and corrective action?
- Enterprise Risk Management System
- Internal Control Framework
- Compliance Management System (CMS) (Correct answer)
- Three Lines of Defense Model
Correct answer: Compliance Management System (CMS)
A Compliance Management System (CMS) is the formal framework regulators expect financial institutions to use to manage compliance risk across all business lines.
Question 25: A compliance manager needs to estimate the effort for converting a legacy regulatory database. Under IFPUG, conversion functions are typically counted as part of which project type?
- A separate standalone conversion application count
- Enhancement project count of the legacy system
- Development project count, as conversion functions supporting the new application (Correct answer)
- They are excluded from all IFPUG counts
Correct answer: Development project count, as conversion functions supporting the new application
Conversion functions that are required to support migration of data for the new application are included in the development project function point count.
Question 26: A bank's vendor management program should include which of the following to address data security?
- Price negotiations only
- Due diligence on vendor security practices and contractual data protection requirements (Correct answer)
- Annual in-person vendor audits by the bank president
- A requirement that all vendors be headquartered in the United States
Correct answer: Due diligence on vendor security practices and contractual data protection requirements
Effective vendor management programs include security due diligence and contractual protections requiring vendors to maintain appropriate data security standards.
Question 27: A bank's fair lending self-assessment program should include:
- Customer satisfaction surveys as the primary compliance metric
- Statistical analysis of lending data to detect potential disparities by protected class (Correct answer)
- Annual review of the bank's marketing materials only
- Comparison of loan denial rates only across branches
Correct answer: Statistical analysis of lending data to detect potential disparities by protected class
Effective fair lending self-assessment includes statistical analysis of lending decisions, pricing, and terms to identify potential disparities by protected class.
Question 28: What information must a bank's CRA public notice include?
- Information about the CRA process and how the public may submit comments to the bank and its regulator (Correct answer)
- A list of all loan applicants denied credit in the past year
- The names and contact information of examiners who conducted the most recent CRA exam
- The bank's internal CRA compliance budget for the current fiscal year
Correct answer: Information about the CRA process and how the public may submit comments to the bank and its regulator
The CRA public notice must inform the public about the CRA, explain how to access the bank's public file, and describe how community members may submit comments to the bank and its federal regulator.
Question 29: Under the Fair Housing Act, which of the following is NOT a protected class?
- Income level (Correct answer)
- Race
- Familial status
- National origin
Correct answer: Income level
Income level is not a protected class under the Fair Housing Act; the protected classes are race, color, religion, national origin, sex, disability, and familial status.
Question 30: Which type of fair lending discrimination occurs when a lender applies credit standards inconsistently based on a prohibited basis such as race or gender?
- Disparate treatment (Correct answer)
- Redlining
- Steering
- Disparate impact
Correct answer: Disparate treatment
Disparate treatment occurs when a lender intentionally treats applicants differently based on a prohibited characteristic, even without explicit discriminatory policy.
Question 31: Under Regulation E, within how many business days must a financial institution complete its investigation of a reported error on an electronic fund transfer?
- 45 business days
- 60 business days
- 10 business days (Correct answer)
- 5 business days
Correct answer: 10 business days
Regulation E requires financial institutions to investigate and resolve EFT error claims within 10 business days, with an extension to 45 days if a provisional credit is provided.
Question 32: When a financial institution discovers a 'notification incident' involving customer data, current OCC/FDIC guidance requires notification to the primary federal regulator within:
- 36 hours (Correct answer)
- 30 days
- 72 hours
- 24 hours
Correct answer: 36 hours
The interagency computer-security incident notification rules require banks to notify their primary federal regulator within 36 hours of determining a notification incident occurred.
Question 33: Regulation CC (Expedited Funds Availability Act) requires banks to make funds from local check deposits available no later than:
- Next business day
- Second business day (Correct answer)
- Fifth business day
- Same business day
Correct answer: Second business day
Regulation CC generally requires that funds from local checks be available no later than the second business day after deposit.
Question 34: Under the Gramm-Leach-Bliley Act (GLBA), financial institutions must provide customers with a privacy notice:
- Only when a customer requests it
- At account opening and annually thereafter (Correct answer)
- Only when sharing data with third parties
- Once every five years
Correct answer: At account opening and annually thereafter
GLBA requires institutions to provide privacy notices at account opening and annually, informing customers of information sharing practices.
Question 35: What is a 'pre-application' fair lending risk in the mortgage context?
- Discouraging applicants from applying based on protected characteristics (Correct answer)
- Not verifying employment before loan closing
- Requiring excessive documentation after application
- Failing to provide loan estimates on time
Correct answer: Discouraging applicants from applying based on protected characteristics
Pre-application risks include discouraging or deterring protected class members from applying, which occurs before a formal application is submitted.
Question 36: A compliance officer conducting a Fair Lending review finds that the bank's pricing model results in higher rates for a protected class even though lending policies appear neutral on their face. This best describes which legal theory?
- Disparate impact (Correct answer)
- Predatory lending
- Disparate treatment
- Redlining
Correct answer: Disparate impact
Disparate impact occurs when a facially neutral policy or practice disproportionately harms a protected class without business justification.
Question 37: Which of the following is an example of 'disparate treatment' in lending?
- Requiring income verification for all mortgage applicants
- Charging minority applicants higher rates than similarly qualified non-minority applicants (Correct answer)
- A policy requiring 20% down payment for all borrowers
- A standard credit score cutoff applied to all applicants
Correct answer: Charging minority applicants higher rates than similarly qualified non-minority applicants
Disparate treatment involves treating similarly situated applicants differently based on a protected characteristic, such as charging higher rates to minorities.
Question 38: Under Regulation E, a financial institution must resolve an error investigation within how many business days for most transactions?
- 10 business days (Correct answer)
- 45 business days
- 5 business days
- 90 business days
Correct answer: 10 business days
Under Regulation E, institutions generally have 10 business days to investigate and resolve EFT error claims.
Question 39: Under the Equal Credit Opportunity Act (ECOA), how many days does a creditor have to notify an applicant of adverse action on a credit application?
- 60 days
- 15 days
- 30 days (Correct answer)
- 45 days
Correct answer: 30 days
ECOA and Regulation B require creditors to notify applicants of adverse action within 30 days of receiving a completed application.
Question 40: Regulation Z implements which federal consumer protection law?
- Truth in Lending Act (Correct answer)
- Fair Credit Reporting Act
- Fair Debt Collection Practices Act
- Electronic Fund Transfer Act
Correct answer: Truth in Lending Act
Regulation Z is the Federal Reserve's (and now CFPB's) implementing regulation for the Truth in Lending Act.
Question 41: Under the Bank Secrecy Act, financial institutions must file a Currency Transaction Report (CTR) for cash transactions exceeding what threshold?
- $25,000
- $5,000
- $50,000
- $10,000 (Correct answer)
Correct answer: $10,000
The BSA requires CTR filing for cash transactions exceeding $10,000 in a single business day.
Question 42: Which of the following is NOT a required element of an effective compliance management system (CMS) as described by the CFPB?
- Customer complaint response
- Compliance program
- Annual third-party vendor audits (Correct answer)
- Board and management oversight
Correct answer: Annual third-party vendor audits
The CFPB's four CMS elements are board/management oversight, compliance program, consumer complaint response, and compliance audit — not specifically annual third-party vendor audits.
Question 43: Under ECOA, how many days does a creditor have to notify an applicant of action taken on a completed credit application?
- 30 days (Correct answer)
- 15 days
- 60 days
- 45 days
Correct answer: 30 days
Creditors must notify applicants of credit decisions within 30 days of receiving a completed application.
Question 44: What does the term 'layering' refer to in the three stages of money laundering?
- Moving funds through complex transactions to obscure their origin (Correct answer)
- Depositing illicit cash into financial accounts
- Filing false tax returns to conceal income
- Integrating laundered money back into the economy
Correct answer: Moving funds through complex transactions to obscure their origin
Layering is the second stage of money laundering, involving complex transactions designed to disguise the audit trail.
Question 45: Which FinCEN rule requires covered financial institutions to identify and verify the identity of the beneficial owners of legal entity customers?
- Anti-Money Laundering (AML) Rule
- Enhanced Due Diligence (EDD) Rule
- Customer Due Diligence (CDD) Rule (Correct answer)
- Know Your Customer (KYC) Rule
Correct answer: Customer Due Diligence (CDD) Rule
FinCEN's Customer Due Diligence Rule, effective May 2018, requires financial institutions to identify beneficial owners with 25% or more ownership and one control person for legal entities.
Question 46: Under the Servicemembers Civil Relief Act (SCRA), what is the interest rate cap applied to pre-service debts of active-duty servicemembers?
- 8%
- 3%
- 6% (Correct answer)
- 4%
Correct answer: 6%
The SCRA caps interest rates on debts incurred before active military service at 6% per year for the duration of the active-duty period.
Question 47: Under the CRA, a bank's assessment area is primarily defined by:
- The entire metropolitan statistical area of the bank's headquarters city
- The geographies surrounding the bank's main office, branches, and deposit-taking ATMs (Correct answer)
- Only the zip codes where loans were made in the past year
- All counties in the state where the bank is chartered
Correct answer: The geographies surrounding the bank's main office, branches, and deposit-taking ATMs
Assessment areas must include the geographies where the bank maintains its main office, branches, and deposit-taking ATMs, reflecting where it has a physical retail presence.
Question 48: A compliance manager is comparing two software releases using IFPUG metrics. Release A delivered 300 UFPs in 6 months; Release B delivered 450 UFPs in 8 months. Which release had higher productivity?
- Release B, because it delivered more total function points
- They are equal because both teams worked the same technology stack (Correct answer)
- Release A, at 50 UFP/month versus Release B at approximately 56 UFP/month — Release B is actually higher
- Release A, because it was completed in fewer months
Correct answer: They are equal because both teams worked the same technology stack
Release A = 50 UFP/month and Release B ≈ 56.25 UFP/month, so Release B had higher productivity per month despite taking longer.
Question 49: A customer opens a new account and provides identification. Under the Customer Identification Program (CIP) rules, the bank must verify the customer's identity:
- Within a reasonable time before or after account opening (Correct answer)
- Only if the transaction exceeds $10,000
- Within 30 days of account opening
- Before the account is opened
Correct answer: Within a reasonable time before or after account opening
CIP rules require identity verification within a reasonable time before or after account opening, allowing flexibility for low-risk situations while ensuring due diligence.
Question 50: Which regulation implements the Home Ownership and Equity Protection Act (HOEPA) for high-cost mortgages?
- Regulation C
- Regulation B
- Regulation X
- Regulation Z (Correct answer)
Correct answer: Regulation Z
Regulation Z implements both TILA and HOEPA, establishing special disclosures and restrictions for high-cost mortgage loans that exceed certain APR and fee thresholds.
Question 51: What is the maximum civil money penalty per day for knowing violations of the Bank Secrecy Act?
- $1,000,000 (Correct answer)
- $25,000
- $10,000,000
- $10,000
Correct answer: $1,000,000
Knowing violations of the BSA can result in civil money penalties up to $1,000,000 per day or twice the amount of the transaction, whichever is greater.
Question 52: The Telephone Consumer Protection Act (TCPA) requires businesses to obtain prior express written consent before:
- Mailing promotional materials to a consumer's address
- Emailing product offers to existing customers
- Calling a consumer's home landline during business hours
- Sending marketing text messages or robocalls to a consumer's cell phone (Correct answer)
Correct answer: Sending marketing text messages or robocalls to a consumer's cell phone
The TCPA requires prior express written consent before sending marketing text messages or making robocalls to consumers' cell phones.
Question 53: Congress limited financial organizations' ability to share consumer information with other parties. By the law, financial institutions must also provide disclosures when starting a client relationship and then once a year after that.
- Gramm-Leach -Billey Act of 1999 (Correct answer)
- Gramm-Leach-Billey Act of 2001
- Gramm-Leach Act of 2000
- Gramm-Billey Act of 1998
Correct answer: Gramm-Leach -Billey Act of 1999
The correct answer is the Gramm-Leach-Bliley Act of 1999. Congress enacted the Gramm-Leach-Bliley Act (GLBA) in 1999 to address various aspects of the financial services industry, including the disclosure of customer information by financial institutions.
Question 54: When applying IFPUG FPA to assess scope changes in a compliance system mid-project, which type of count is most appropriate?
- Baseline function point count
- Application function point count
- Development function point count
- Enhancement function point count (Correct answer)
Correct answer: Enhancement function point count
An Enhancement Function Point Count measures the size of changes (additions, modifications, deletions) made to an existing application during an enhancement project.
Question 55: Regulation DD, which implements the Truth in Savings Act, requires depository institutions to disclose:
- Maximum loan amounts available to depositors
- Branch hours and ATM locations
- Minimum balance requirements and fees for deposit accounts (Correct answer)
- Employee compensation linked to deposit growth
Correct answer: Minimum balance requirements and fees for deposit accounts
Regulation DD requires clear disclosure of interest rates, fees, and terms for deposit accounts so consumers can compare savings products.
Question 56: Which federal law specifically prohibits discrimination in residential mortgage lending based on race or national origin?
- Fair Housing Act (Correct answer)
- Truth in Lending Act
- Gramm-Leach-Bliley Act
- Community Reinvestment Act
Correct answer: Fair Housing Act
The Fair Housing Act prohibits discrimination in residential real estate transactions, including mortgage lending, based on protected characteristics.
Question 57: Which federal agency is primarily responsible for enforcing the Equal Credit Opportunity Act (ECOA)?
- Federal Reserve Board
- Federal Deposit Insurance Corporation (FDIC)
- Consumer Financial Protection Bureau (CFPB) (Correct answer)
- Office of the Comptroller of the Currency (OCC)
Correct answer: Consumer Financial Protection Bureau (CFPB)
The CFPB has primary enforcement authority over ECOA for most financial institutions, prohibiting credit discrimination.
Question 58: Which federal agency has primary rulemaking authority under the Dodd-Frank Act for most consumer financial protection laws?
- Federal Reserve Board
- Office of the Comptroller of the Currency
- Consumer Financial Protection Bureau (Correct answer)
- Federal Deposit Insurance Corporation
Correct answer: Consumer Financial Protection Bureau
The CFPB was created by the Dodd-Frank Act of 2010 and holds primary rulemaking, supervisory, and enforcement authority for most federal consumer financial protection laws.
Question 59: Under Regulation DD (Truth in Savings), annual percentage yield (APY) must reflect:
- The average rate paid over the prior 12 months
- The rate after deducting all account maintenance fees
- The effect of compounding over a full year (Correct answer)
- The simple interest rate offered on the account
Correct answer: The effect of compounding over a full year
APY is a standardized rate that includes the effect of compounding over a 365-day year, allowing consumers to compare savings accounts.
Question 60: In the context of IFPUG and regulatory compliance, how does function point sizing help a compliance manager evaluate outsourced software development contracts?
- It provides a technology-neutral unit for defining deliverable scope and verifying what was actually built (Correct answer)
- It replaces the need for a statement of work in vendor contracts
- It automatically generates compliance reports for regulatory review
- It measures vendor adherence to data privacy regulations
Correct answer: It provides a technology-neutral unit for defining deliverable scope and verifying what was actually built
Function points offer a consistent, language-independent size metric that can be used to specify contractual scope and objectively verify delivery.
Question 61: The Equal Credit Opportunity Act (ECOA) prohibits discrimination in credit transactions based on which of the following?
- Race, color, religion, national origin, sex, marital status, or age (Correct answer)
- Employment less than two years
- Loan amount below $1,000
- Credit score below 600
Correct answer: Race, color, religion, national origin, sex, marital status, or age
ECOA prohibits credit discrimination based on race, color, religion, national origin, sex, marital status, age, and receipt of public assistance.
Question 62: Which of the following best describes the role of a bank's compliance audit function?
- It provides independent testing to verify that the compliance program is working effectively (Correct answer)
- It approves all new products before launch
- It creates and updates compliance policies and procedures
- It directly supervises the compliance department
Correct answer: It provides independent testing to verify that the compliance program is working effectively
The compliance audit function independently tests and assesses whether the bank's compliance controls and program are working as intended.
Question 63: Under the Electronic Fund Transfer Act (EFTA), consumers have how many business days to report an unauthorized electronic fund transfer to limit liability to $50?
- 60 days
- 2 business days (Correct answer)
- 10 business days
- 30 days
Correct answer: 2 business days
Consumers must report unauthorized EFTs within 2 business days of learning of the loss to limit liability to $50.
Question 64: HMDA data is most directly useful during CRA examinations because it:
- Provides information on the bank's capital ratios in LMI census tracts
- Shows the geographic distribution and borrower demographics of mortgage loan applications and originations (Correct answer)
- Documents the bank's CRA rating history over the past decade
- Identifies fraudulent lending activity in underserved communities
Correct answer: Shows the geographic distribution and borrower demographics of mortgage loan applications and originations
HMDA data captures loan application and origination information by census tract and borrower income/race, which CRA examiners use to assess the geographic and demographic distribution of the bank's mortgage lending.
Question 65: Which rule requires banks to collect and verify beneficial ownership information for legal entity customers?
- Volcker Rule
- UDAAP Rule
- Regulation CC
- FinCEN Beneficial Ownership Rule (Correct answer)
Correct answer: FinCEN Beneficial Ownership Rule
FinCEN's Customer Due Diligence Final Rule requires banks to collect beneficial ownership information for legal entity customers.
Question 66: A CRCM using IFPUG metrics to estimate a regulatory reporting project finds that a transaction updates data in two ILFs and references one EIF. What is the minimum number of Data Element Types (DETs) that must be counted for the EIF?
- Zero, because EIFs are not counted at the transaction level
- DETs are only counted for ILFs, not EIFs
- One DET per unique field referenced by the transaction (Correct answer)
- One fixed DET regardless of fields
Correct answer: One DET per unique field referenced by the transaction
DETs for an EIF are counted as the unique user-recognizable, non-repeated fields that are referenced across all transactions that use that EIF.
Question 67: Which of the following is considered a 'red flag' for potential money laundering?
- A customer who asks detailed questions about account features
- A customer who always provides complete identification
- Large cash deposits inconsistent with the customer's business (Correct answer)
- Regular payroll deposits from the same employer
Correct answer: Large cash deposits inconsistent with the customer's business
Cash deposits inconsistent with a customer's stated business or income profile are a classic money laundering red flag.
Question 68: Under the Military Lending Act (MLA), what is the maximum Military Annual Percentage Rate (MAPR) that can be charged on consumer credit extended to covered active duty servicemembers?
- 28%
- 18%
- 36% (Correct answer)
- 24%
Correct answer: 36%
The Military Lending Act caps the Military Annual Percentage Rate at 36% for most consumer credit products extended to covered active duty servicemembers and their dependents.
Question 69: A compliance manager uses IFPUG metrics to benchmark software vendors. Which IFPUG-derived metric most directly compares development productivity across vendors?
- Function Points per person-month (Correct answer)
- Lines of code per defect
- Total test cases per release
- Number of ILFs per system
Correct answer: Function Points per person-month
Function Points per person-month is a standard IFPUG-aligned productivity metric that normalizes output across different technologies and vendor teams.
Question 70: The Dodd-Frank Wall Street Reform and Consumer Protection Act created the CFPB and granted it authority over:
- Nonbank financial companies offering consumer financial products or services, and large banks (Correct answer)
- Only banks with assets over $10 billion
- Only federally chartered institutions
- All financial institutions regardless of size
Correct answer: Nonbank financial companies offering consumer financial products or services, and large banks
The CFPB has supervisory authority over nonbank financial companies and depository institutions with over $10 billion in assets, while smaller banks are supervised by their prudential regulators.
Question 71: The CFPB's UDAP authority under Dodd-Frank prohibits:
- Lenders from using automated underwriting systems
- Unfair, deceptive, or abusive acts or practices (UDAAP) (Correct answer)
- Variable rate products for first-time homebuyers
- All forms of relationship-based pricing
Correct answer: Unfair, deceptive, or abusive acts or practices (UDAAP)
The CFPB enforces UDAAP standards, which prohibit unfair, deceptive, or abusive acts or practices in consumer financial products and services.
Question 72: Approximately how often are CRA performance evaluations typically conducted for banks in good standing?
- Every 2 to 5 years, depending on bank size and prior rating (Correct answer)
- Only when a bank applies for a merger or new branch
- Annually for all banks regardless of prior rating
- Monthly as part of ongoing regulatory supervision
Correct answer: Every 2 to 5 years, depending on bank size and prior rating
CRA examinations are generally conducted on a cycle of approximately every 2 to 5 years, with the frequency influenced by the bank's asset size and its most recent CRA rating.
Question 73: Under CRA, the public file that a bank must maintain includes:
- The bank's current CRA public notice and its most recent CRA performance evaluation (Correct answer)
- Individual borrower credit scores and underwriting notes
- Proprietary loan pricing models used by underwriters
- Compensation details for CRA compliance officers
Correct answer: The bank's current CRA public notice and its most recent CRA performance evaluation
A bank's public CRA file must contain its current CRA notice and its most recent written CRA performance evaluation, among other items, but never confidential borrower or employee information.
Question 74: Under the Truth in Lending Act (TILA), the Annual Percentage Rate (APR) must be disclosed to allow consumers to:
- Compare the true cost of credit across different lenders (Correct answer)
- Negotiate a lower rate with the lender
- Determine their credit score impact
- Calculate their monthly insurance premium
Correct answer: Compare the true cost of credit across different lenders
The APR standardizes the cost of credit as an annualized rate, allowing consumers to meaningfully compare loan offers from different lenders.
Question 75: Under the Real Estate Settlement Procedures Act (RESPA), a kickback paid for the referral of settlement service business is:
- Prohibited (Correct answer)
- Permissible if disclosed on the Closing Disclosure
- Required to be disclosed to the state regulator only
- Allowed if under $500
Correct answer: Prohibited
RESPA Section 8 prohibits kickbacks and unearned fees in connection with federally related mortgage transactions.
Question 76: The purpose of a risk-based compliance monitoring program is primarily to:
- Document all regulatory changes for management
- Ensure all regulations receive equal review time
- Concentrate monitoring resources where the risk of harm is greatest (Correct answer)
- Replace annual compliance audits
Correct answer: Concentrate monitoring resources where the risk of harm is greatest
Risk-based monitoring allocates compliance resources to areas with the highest potential for regulatory violations and consumer harm.
Question 77: When auditing a compliance system's function point count, a CRCM notices the count includes a password field. Under IFPUG rules, how should a password or encrypted field typically be handled?
- Each character of a password counts as a separate DET
- Encrypted fields are always excluded from DETs
- Password fields count as a full RET within the ILF
- It is counted as one DET if it is user-identifiable, regardless of whether it is displayed in encrypted form (Correct answer)
Correct answer: It is counted as one DET if it is user-identifiable, regardless of whether it is displayed in encrypted form
A password field is a single user-identifiable attribute and counts as one DET even if its value is masked or encrypted in the user interface.
Question 78: A bank's BSA/AML compliance program must be approved and overseen by whom?
- The state banking regulator only
- FinCEN directly
- The bank's external auditors
- The board of directors or a designated committee (Correct answer)
Correct answer: The board of directors or a designated committee
BSA regulations require that the BSA/AML compliance program be approved and overseen by the board of directors or a senior committee.
Question 79: When a consumer disputes the accuracy of information in their credit report under the Fair Credit Reporting Act (FCRA), the credit reporting agency (CRA) must complete its investigation within:
- 30 days (with a possible 15-day extension) (Correct answer)
- 45 days
- 60 days
- 15 business days
Correct answer: 30 days (with a possible 15-day extension)
The FCRA requires CRAs to investigate disputes within 30 days, extendable to 45 days if the consumer provides additional relevant information during the investigation.
Question 80: Under the Home Ownership and Equity Protection Act (HOEPA), a loan is classified as a 'high-cost mortgage' if it exceeds certain rate or fee thresholds. Which of the following is a consequence of HOEPA coverage?
- Additional disclosures and restrictions on loan terms are required (Correct answer)
- The borrower receives an automatic rate reduction
- The lender must file a special report with HUD
- The loan becomes automatically void
Correct answer: Additional disclosures and restrictions on loan terms are required
HOEPA-covered high-cost mortgages trigger mandatory additional disclosures, restrictions on certain loan terms (e.g., balloon payments, prepayment penalties), and enhanced borrower protections.
Question 81: In IFPUG counting, a Record Element Type (RET) is used to measure complexity of which function type?
- Transaction Functions only (EI, EO, EInq)
- Only External Inputs (EIs)
- Data Functions (ILFs and EIFs) (Correct answer)
- Both Data and Transaction Functions equally
Correct answer: Data Functions (ILFs and EIFs)
RETs are subgroups of logically related data within an ILF or EIF, and they are used along with DETs to determine the complexity of Data Functions.
Question 82: A bank that receives a CRA rating of 'Needs to Improve' is MOST likely to face which consequence?
- Loss of federal deposit insurance within 90 days
- Immediate closure of all branches in low-income areas
- Increased regulatory scrutiny and potential delays or denials on applications for expansion (Correct answer)
- Mandatory reduction of all loan interest rates to below-prime levels
Correct answer: Increased regulatory scrutiny and potential delays or denials on applications for expansion
A 'Needs to Improve' CRA rating subjects the bank to heightened regulatory scrutiny and can result in delays or denial of merger, acquisition, or branching applications.
Question 83: Which agency primarily enforces fair lending laws for national banks?
- Office of the Comptroller of the Currency (OCC) (Correct answer)
- State banking departments
- FDIC
- Department of Justice only
Correct answer: Office of the Comptroller of the Currency (OCC)
The OCC is the primary federal regulator for national banks and enforces fair lending laws including ECOA and the Fair Housing Act.
Question 84: The Military Lending Act (MLA) caps the Military Annual Percentage Rate (MAPR) for most consumer credit products at:
- 28%
- 50%
- 18%
- 36% (Correct answer)
Correct answer: 36%
The MLA imposes a 36% MAPR cap on most consumer credit extended to covered servicemembers and their dependents.
Question 85: Which of the following categories of workers needs to get instruction on how to utilize W-9 forms precisely?
- New account officers (Correct answer)
- Security officers
- Senior Management
- Auditors and accountants
Correct answer: New account officers
W-9 forms are used to collect taxpayer identification information from individuals or entities that may be subject to certain reporting requirements, such as providing payments or income to them. The purpose of the W-9 form is to obtain the recipient's correct taxpayer identification number (TIN) and other relevant information for tax reporting purposes.
Question 86: What is the primary purpose of the Community Reinvestment Act (CRA)?
- To encourage banks to help meet the credit needs of the entire community, including low- and moderate-income areas (Correct answer)
- To establish minimum capital requirements for banks operating in underserved communities
- To mandate that banks offer accounts to all applicants regardless of creditworthiness
- To require banks to report loan data by race and gender
Correct answer: To encourage banks to help meet the credit needs of the entire community, including low- and moderate-income areas
The CRA was enacted to encourage depository institutions to meet the credit needs of all segments of their communities, with particular emphasis on low- and moderate-income neighborhoods.
Question 87: Under the Bank Secrecy Act (BSA), what is the threshold amount that triggers a Currency Transaction Report (CTR)?
- $10,000 (Correct answer)
- $50,000
- $25,000
- $5,000
Correct answer: $10,000
The BSA requires financial institutions to file a CTR for any currency transaction exceeding $10,000 in a single business day.
Question 88: What is the purpose of a bank's AML risk assessment?
- To determine the bank's capital adequacy ratio
- To set customer credit limits
- To evaluate employee performance in compliance roles
- To identify and prioritize money laundering and terrorist financing risks (Correct answer)
Correct answer: To identify and prioritize money laundering and terrorist financing risks
The AML risk assessment identifies, measures, and prioritizes the institution's exposure to money laundering and terrorist financing.
Question 89: Under the USA PATRIOT Act, banks must implement a Customer Identification Program (CIP) verifying identity for which customers?
- Only commercial business accounts
- All new account holders (Correct answer)
- Only non-US citizens
- Only accounts with balances over $50,000
Correct answer: All new account holders
CIP requirements apply to all new account holders regardless of account type or balance.
Question 90: During a compliance examination, a 'Matters Requiring Attention' (MRA) citation indicates:
- A deficiency that requires corrective action but is not yet an unsafe or unsound practice (Correct answer)
- A minor clerical error in compliance documentation
- Criminal referral to the Department of Justice
- The bank has passed all compliance requirements
Correct answer: A deficiency that requires corrective action but is not yet an unsafe or unsound practice
An MRA is a supervisory finding that identifies a practice or condition requiring corrective action before it becomes an unsafe or unsound practice.
Question 91: Which federal agency has primary responsibility for administering the Bank Secrecy Act for depository institutions?
- OCC
- FDIC
- FinCEN (Correct answer)
- SEC
Correct answer: FinCEN
The Financial Crimes Enforcement Network (FinCEN), a bureau of the Treasury Department, administers the BSA.
Question 92: A 'Consent Order' issued by a bank regulator is:
- A legally binding agreement requiring specific corrective actions and subject to court enforcement (Correct answer)
- A recommendation issued to improve bank practices
- A voluntary agreement with no legal effect
- An informal supervisory letter with no public disclosure requirement
Correct answer: A legally binding agreement requiring specific corrective actions and subject to court enforcement
A consent order is a formal, legally binding enforcement action requiring the bank to take specified corrective steps and subject to potential court enforcement if violated.
Question 93: The 'similarly situated' analysis in fair lending compares:
- Different loan products offered by the same lender
- Branch performance across geographic regions
- Applicants who are comparable in creditworthiness but differ by protected class (Correct answer)
- Borrowers from different income brackets regardless of creditworthiness
Correct answer: Applicants who are comparable in creditworthiness but differ by protected class
'Similarly situated' analysis compares applicants with comparable qualifications, loan features, and risk factors who differ only in protected class membership.
Question 94: Under the BSA's Monetary Instrument Log (MIL) requirements, banks must record cash purchases of monetary instruments between which dollar amounts?
- $5,000 and $25,000
- $10,000 and $50,000
- $1,000 and $3,000
- $3,000 and $10,000 (Correct answer)
Correct answer: $3,000 and $10,000
Banks must maintain a MIL for cash purchases of monetary instruments (e.g., cashier's checks, money orders) between $3,000 and $10,000.
Question 95: Enhanced Due Diligence (EDD) is required for which category of customers?
- Customers who use online banking exclusively
- All customers with more than three accounts
- Customers with accounts open less than one year
- High-risk customers such as foreign politically exposed persons (Correct answer)
Correct answer: High-risk customers such as foreign politically exposed persons
EDD is required for higher-risk customers, including foreign politically exposed persons (PEPs) and high-risk business types.
Question 96: The CRA strategic plan option allows a bank to:
- Be exempt from the lending test if it commits to community investment targets
- Set its own measurable CRA goals, subject to public comment and regulatory approval (Correct answer)
- Use peer bank benchmarks instead of assessment-area-specific targets
- Defer CRA compliance for up to three years while developing internal systems
Correct answer: Set its own measurable CRA goals, subject to public comment and regulatory approval
Under the strategic plan option, a bank may develop its own CRA goals, make the plan available for public comment, and then submit it to its regulator for approval, providing a customized compliance framework.
Question 97: Under CRA, a 'low- and moderate-income' (LMI) census tract generally refers to one where median family income is:
- Below the federal poverty level for a family of four
- Less than 120% of the national median income
- Less than 80% of the area median income (Correct answer)
- Below 50% of the area median income
Correct answer: Less than 80% of the area median income
LMI areas are defined as census tracts where median family income is less than 80% of the area median income (AMI), with 'low income' below 50% AMI and 'moderate income' between 50-79% AMI.
Question 98: Which of the following will boost a cash transaction-based anti-money laundering program the MOST?
- Complete CTR worksheets on all cash transactions of $5,000 or more
- Review all deposits of $25,000 or more
- Monitor cash transactions of less than $10,000 for suspicious patterns (Correct answer)
- Complete SAR worksheets on all cash transactions of $5,000 or more
Correct answer: Monitor cash transactions of less than $10,000 for suspicious patterns
Monitoring cash transactions of less than $10,000 for suspicious patterns is the most effective measure in strengthening an anti-money laundering program involving cash transactions.
Question 99: A compliance reporting system has an External Output that retrieves data from two ILFs and formats a regulatory report. The report contains 12 unique data fields. What complexity level does the FTR and DET combination suggest?
- Low complexity, because only two files are referenced
- Low complexity, because regulatory reports default to low
- High complexity, based on 2 FTRs and more than 5 DETs (Correct answer)
- Medium complexity, because 12 DETs always yields medium
Correct answer: High complexity, based on 2 FTRs and more than 5 DETs
An EO referencing 2 FTRs and more than 5 DETs falls into the High complexity cell of the IFPUG EO complexity matrix.
Question 100: Under IFPUG's Counting Practices Manual, which component is classified as a Data Function rather than a Transaction Function?
- External Input (EI)
- External Output (EO)
- External Inquiry (EInq)
- Internal Logical File (ILF) (Correct answer)
Correct answer: Internal Logical File (ILF)
Internal Logical Files are Data Functions because they represent user-identifiable groups of logically related data maintained within the application boundary.
Question 101: Which BSA/AML program element requires banks to understand the nature and purpose of customer relationships?
- Customer Due Diligence (CDD) (Correct answer)
- Monetary Instrument Log
- Currency Transaction Reporting
- Office of Foreign Assets Control screening
Correct answer: Customer Due Diligence (CDD)
Customer Due Diligence rules require banks to understand customer relationships to assess risk and detect unusual activity.
Question 102: Under the Truth in Savings Act, what term describes the percentage rate reflecting the total amount of interest paid on an account based on the annual percentage rate and frequency of compounding?
- Nominal Interest Rate (NIR)
- Effective Annual Rate (EAR)
- Annual Percentage Yield (APY) (Correct answer)
- Annual Percentage Rate (APR)
Correct answer: Annual Percentage Yield (APY)
The Annual Percentage Yield (APY) reflects the total interest earned on a deposit account in one year, taking compounding frequency into account, as required by Regulation DD.
Question 103: A bank employee who knowingly assists a customer in structuring transactions to avoid reporting requirements may be charged with:
- A civil violation only
- A minor compliance infraction
- Negligence only
- Federal criminal violations including conspiracy (Correct answer)
Correct answer: Federal criminal violations including conspiracy
Bank employees who assist in structuring can face federal criminal charges including conspiracy and aiding and abetting.
Question 104: Under interagency CRA examination procedures, a bank with assets between $376 million and $1.564 billion is evaluated under:
- The intermediate small bank CRA test (lending + community development) (Correct answer)
- The small bank CRA test (lending test only)
- The strategic plan CRA test
- The large bank CRA test (lending, investment, service)
Correct answer: The intermediate small bank CRA test (lending + community development)
Intermediate small banks are evaluated under the lending test and the community development test rather than the full three-part large bank test.
Question 105: Under IFPUG guidelines, which statement best describes the relationship between Function Point Analysis and software quality metrics for a compliance program?
- FPA quality scores are reported directly to regulatory bodies as compliance evidence
- FPA replaces the need for quality audits in regulated environments
- FPA measures size only; quality metrics such as defect density must be separately applied using FP as the denominator (Correct answer)
- FPA directly measures both size and software reliability in a single metric
Correct answer: FPA measures size only; quality metrics such as defect density must be separately applied using FP as the denominator
IFPUG FPA is a pure size measurement; it enables quality metrics like defects per function point when defect data is combined with the FP count.
Question 106: A CRCM overseeing an IT compliance audit finds the project team counted a file that stores temporary processing data not visible to end users. Under IFPUG rules, this file should be:
- Excluded from the count because it is not a user-identifiable group of data (Correct answer)
- Counted as an EIF since it is referenced but not displayed
- Counted as a low-complexity ILF by default
- Counted as an ILF since it is maintained by the application
Correct answer: Excluded from the count because it is not a user-identifiable group of data
IFPUG requires that ILFs be user-identifiable groups of logically related data; temporary or technical files invisible to users do not qualify.
Question 107: Which of the following would MOST likely qualify as a CRA investment under the investment test?
- Buying AAA-rated commercial mortgage-backed securities on the secondary market
- Investing in a Low-Income Housing Tax Credit (LIHTC) partnership in the assessment area (Correct answer)
- Acquiring stock in a large regional competitor bank with strong earnings
- Purchasing U.S. Treasury bills for the bank's investment portfolio
Correct answer: Investing in a Low-Income Housing Tax Credit (LIHTC) partnership in the assessment area
Investments in LIHTC projects that benefit LMI populations or areas in the bank's assessment area are a classic example of qualified CRA investments, satisfying the primary community development purpose requirement.
Question 108: The four CRA performance rating categories are:
- Superior, Acceptable, Marginal, Unsatisfactory
- Excellent, Good, Fair, Poor
- Exceptional, Outstanding, Satisfactory, Needs Improvement
- Outstanding, Satisfactory, Needs to Improve, Substantial Noncompliance (Correct answer)
Correct answer: Outstanding, Satisfactory, Needs to Improve, Substantial Noncompliance
The CRA uses exactly four ratings: Outstanding, Satisfactory, Needs to Improve, and Substantial Noncompliance.
Question 109: Under the CRA, which rating reflects a bank that has substantially helped meet community credit needs and may have outstanding programs?
- Satisfactory
- Outstanding (Correct answer)
- Substantial Noncompliance
- Needs to Improve
Correct answer: Outstanding
Outstanding is the highest CRA rating, awarded when an institution substantially exceeds expectations in helping meet the credit needs of its assessment area.
Question 110: The Right to Financial Privacy Act (RFPA) restricts federal government agencies from obtaining customer financial records without:
- Regulatory approval from the OCC
- Customer notice or legal process such as a subpoena (Correct answer)
- Board of directors approval
- Written authorization from FinCEN
Correct answer: Customer notice or legal process such as a subpoena
The RFPA requires federal government agencies to either notify the customer or use legal process (e.g., subpoena, court order) before obtaining financial records.
Question 111: The Home Mortgage Disclosure Act (HMDA) requires financial institutions to collect and report data primarily to identify what?
- Fraudulent mortgage applications
- Borrowers who default on their loans
- Possible fair lending violations and underserved communities (Correct answer)
- Interest rate manipulation by mortgage lenders
Correct answer: Possible fair lending violations and underserved communities
HMDA data is used by regulators and the public to identify potential discriminatory lending patterns and determine whether financial institutions are serving community needs.
Question 112: Regulation E primarily governs:
- Equal credit opportunities
- Securities transactions
- Mortgage loan disclosures
- Electronic fund transfers (Correct answer)
Correct answer: Electronic fund transfers
Regulation E implements the Electronic Fund Transfer Act and establishes the rights and liabilities of consumers and financial institutions for EFTs.
Question 113: A principal in municipal securities must directly supervise municipal securities activities. This entails going through all but one of the items below. What activity DOES NOT directly entail the direct supervision of municipal securities operations?
- Providing quotations to customers (Correct answer)
- Handling customer complaints
- Opening the customer’s account
- Handling a municipal securities transaction
Correct answer: Providing quotations to customers
Providing quotations to customers is a customer-facing sales activity, not a supervisory function, so it is not part of directly supervising municipal securities operations. Opening accounts, handling customer complaints, and overseeing transactions are oversight and compliance duties that a principal must directly supervise.
Question 114: What is the primary purpose of the Suspicious Activity Report (SAR) filing requirement under BSA?
- To document all large currency transactions above $3,000
- To notify state banking regulators of unusual customer behavior
- To alert the IRS of unreported taxable income
- To report potential money laundering or other financial crimes to FinCEN (Correct answer)
Correct answer: To report potential money laundering or other financial crimes to FinCEN
SARs are filed with FinCEN to report transactions that a financial institution suspects involve money laundering, fraud, or other criminal activity.
Question 115: Which of the following marketing initiatives would NOT imply that a bank would be free from SEC registration requirements?
- A listing of the bank's wide trust service's securities services for trust accounts
- Stating in a commercial for services related to employee benefit plans that the bank offers stocks brokerage services for accounts related to employee benefit plans
- Mentioning in a print advertisement that the bank provides accommodation securities trades for its regular custodial accounts (Correct answer)
- Along with other IRA perks, the bank should list its securities transfer services as a service it offers for IRA accounts.
Correct answer: Mentioning in a print advertisement that the bank provides accommodation securities trades for its regular custodial accounts
In the United States, banks are exempt from registration with the Securities and Exchange Commission (SEC) under certain conditions when engaging in certain securities-related activities. However, the exemption does not apply to activities that go beyond traditional banking activities.
Question 116: Under the Truth in Lending Act (TILA) and Regulation Z, the right of rescission applies to which type of transaction?
- Home equity loan used for business purposes
- Non-purchase refinance secured by the consumer's primary dwelling (Correct answer)
- Purchase-money mortgage for a primary residence
- Reverse mortgage transaction
Correct answer: Non-purchase refinance secured by the consumer's primary dwelling
The three-day right of rescission applies to non-purchase credit transactions secured by the consumer's principal dwelling, such as refinances and HELOCs.
Question 117: Under the Children's Online Privacy Protection Act (COPPA), websites directed at children under what age must obtain verifiable parental consent before collecting personal information?
- 21
- 13 (Correct answer)
- 16
- 18
Correct answer: 13
COPPA requires operators of websites directed to children under 13 to obtain verifiable parental consent before collecting personal information from those children.
Question 118: Under the Dodd-Frank Act, the CFPB has supervisory authority over which institutions without regard to asset size?
- Mortgage brokers operating only in one state
- Only credit unions with federal charters
- All community banks
- Non-bank financial companies offering consumer financial products (Correct answer)
Correct answer: Non-bank financial companies offering consumer financial products
The CFPB has supervisory authority over non-bank entities (e.g., payday lenders, mortgage companies) offering consumer financial products regardless of size.
Question 119: What is the purpose of a 'clean desk policy' in a bank's information security program?
- To enforce uniform branch appearance standards
- To comply with OSHA workplace safety regulations
- To reduce paper usage and support sustainability goals
- To prevent unauthorized access to sensitive information left unattended in work areas (Correct answer)
Correct answer: To prevent unauthorized access to sensitive information left unattended in work areas
A clean desk policy requires employees to secure sensitive documents and data when leaving their workstations, reducing risk of unauthorized access.
Question 120: Under the Fair Debt Collection Practices Act (FDCPA), what is the maximum number of times a debt collector may call a consumer at their workplace if told calls are unwelcome?
- Once more after being told
- No more than three times per week
- None — calls must cease immediately (Correct answer)
- No more than once per day
Correct answer: None — calls must cease immediately
Under the FDCPA, once a consumer tells a debt collector they cannot receive calls at work, the collector must cease all future workplace calls.
Question 121: The CRA lending test for large banks primarily evaluates:
- Only home mortgage loans made to LMI borrowers in LMI census tracts
- The profitability of loans made in the bank's assessment area
- Geographic distribution and borrower characteristics of home mortgage, small business, small farm, and community development loans (Correct answer)
- The total number of loans approved versus denied each calendar year
Correct answer: Geographic distribution and borrower characteristics of home mortgage, small business, small farm, and community development loans
The lending test evaluates the full range of a large bank's home mortgage, small business, small farm, and community development lending, examining geographic distribution and the income levels of borrowers served.
Question 122: A contract to ship goods to Country M, a nation that is being boycotted, was signed by PTestGeeks Co. A letter of credit approved by First National Bank will be used for payment. Before being paid, PTestGeeks Co. must attest by the terms of the letter of credit that none of its directors is a citizen of any country that Country M has chosen to boycott. After confirming all the paperwork is in place, First National Bank issues the letter of credit to PTestGeeks. Does First National Bank need to notify the IRS about its involvement in a boycott?
- No. Only ABC Co. is required to report to the IRS.
- Yes, but no reporting requirements were triggered.
- Yes. The action was participation in a boycott and the bank must report the action to the IRS. (Correct answer)
- No. The bank’s action was only ministerial.
Correct answer: Yes. The action was participation in a boycott and the bank must report the action to the IRS.
Yes—under U.S. anti-boycott laws, issuing a letter of credit that requires attestation tied to a boycott counts as participation in or support of that boycott, which triggers a mandatory reporting requirement to the IRS. The bank's action is more than ministerial because it knowingly facilitated the boycott condition, so it cannot avoid reporting, and the obligation applies to the bank itself, not only to the exporting company.
Question 123: The Bank Secrecy Act requires financial institutions to retain records of funds transfers of $3,000 or more (the 'Travel Rule'). What information must 'travel' with the payment order?
- Social Security numbers of both parties
- Only the originator's account number
- Only the beneficiary's routing number and account number
- Originator's name, address, and account number plus beneficiary's name and account number (Correct answer)
Correct answer: Originator's name, address, and account number plus beneficiary's name and account number
The Travel Rule requires that specific originator and beneficiary identifying information accompany funds transfers of $3,000 or more to help law enforcement trace illicit funds.
Question 124: Under the GLBA, which of the following is considered 'nonpublic personal information' (NPI)?
- A customer's name listed in a public telephone directory
- A customer's address listed in the local newspaper
- The publicly available interest rates offered by the bank
- Account balances and transaction history provided by the customer (Correct answer)
Correct answer: Account balances and transaction history provided by the customer
NPI includes any financial information a customer provides to a financial institution, such as account balances and transaction data, that is not publicly available.
Question 125: When a bank provides customer data to a nonaffiliated third party under an exception to GLBA sharing restrictions, that third party:
- May use the data only with written customer consent
- Is restricted in how it may use and redisclose the data (Correct answer)
- Must notify the customer within 10 days
- May freely share the data with any affiliated company
Correct answer: Is restricted in how it may use and redisclose the data
GLBA exceptions allow sharing under certain conditions, but the receiving third party's use and redisclosure of the data is restricted to the purpose of the exception.
Question 126: Which type of bank is evaluated solely under a community development test rather than the standard lending, investment, and service tests?
- Wholesale or limited purpose bank (Correct answer)
- Small bank
- Large retail bank
- Intermediate small bank
Correct answer: Wholesale or limited purpose bank
Wholesale and limited purpose banks do not offer retail products to the general public, so they are evaluated only on a community development test rather than the standard three-part test.
Question 127: A corporation that would become a financial subsidiary of First State Bank, a state nonmember institution, is planned for acquisition. First State will inform the FDIC of its intended purchase via a notification. Which of the following considerations would NOT be considered by the FDIC when deciding whether to acquire the bank?
- First State Bank's asset size (Correct answer)
- Whether Fist State Bank is well capitalized
- Fist state Bank's CRA rating
- The impact of the acquisition on First State Bank's safety and soundness
Correct answer: First State Bank's asset size
First State Bank's asset size would NOT be relevant to the FDIC's consideration of the bank's acquisition in this scenario. When a state nonmember institution, like First State Bank, plans to purchase a company that would become its financial subsidiary, the FDIC (Federal Deposit Insurance Corporation) is involved in the review and approval process.
Question 128: Under GLBA, which sharing arrangement does NOT require customer opt-out rights?
- Sharing with nonaffiliated credit card processors under a joint marketing agreement
- Sharing customer data with affiliated companies (Correct answer)
- Sharing with a nonaffiliated data broker for marketing purposes
- Sharing with nonaffiliated insurance companies for cross-selling
Correct answer: Sharing customer data with affiliated companies
Sharing customer information with affiliated companies (companies under common control) does not require an opt-out right under the GLBA Privacy Rule, though customers may be given a limit right.
Question 129: The Office of Foreign Assets Control (OFAC) administers and enforces economic sanctions programs. OFAC is part of which federal department?
- Department of Justice
- Department of the Treasury (Correct answer)
- Department of State
- Department of Homeland Security
Correct answer: Department of the Treasury
OFAC is an office of the U.S. Department of the Treasury that administers and enforces economic and trade sanctions.
Question 130: Which IFPUG complexity level assigns the highest unadjusted function point value to an External Output?
- Medium complexity
- Low complexity
- High complexity (Correct answer)
- Very high complexity
Correct answer: High complexity
High complexity External Outputs are assigned 7 unadjusted function points, the maximum for that transaction type.
Question 131: Regulation E requires that periodic statements for accounts with electronic fund transfer capability be provided:
- Monthly if there is an electronic transfer during the cycle (Correct answer)
- Annually for inactive accounts
- Only on customer request
- Quarterly
Correct answer: Monthly if there is an electronic transfer during the cycle
Regulation E requires monthly periodic statements for accounts that had an EFT during the statement period.
Question 132: What is the primary purpose of the CAN-SPAM Act as it applies to financial institution marketing emails?
- It bans the use of third-party email service providers
- It prohibits all unsolicited email marketing
- It requires email encryption for all customer communications
- It sets standards for commercial email, including opt-out requirements (Correct answer)
Correct answer: It sets standards for commercial email, including opt-out requirements
CAN-SPAM establishes requirements for commercial email, including clear identification, honest subject lines, and a functional opt-out mechanism.
Question 133: A compliance officer at a credit union is reviewing a member's loan file and finds no documentation of income verification. This most likely violates which regulatory requirement?
- Ability-to-Repay (ATR) rule under Regulation Z (Correct answer)
- RESPA's Good Faith Estimate requirements
- Regulation B's adverse action requirements
- Regulation C HMDA data collection
Correct answer: Ability-to-Repay (ATR) rule under Regulation Z
The ATR rule requires lenders to make a reasonable, good-faith determination of the consumer's ability to repay based on verified income and other financial information.
Question 134: For CRCM exam purposes, how does IFPUG define a 'user' in the context of function point analysis?
- Only human end-users who directly operate the compliance system
- Internal IT staff who administer the system
- Any person or application that interacts with the application being measured across its boundary (Correct answer)
- Regulatory agencies that mandate the system's existence
Correct answer: Any person or application that interacts with the application being measured across its boundary
In IFPUG, 'user' includes both human users and other applications that send or receive data across the application boundary.
Question 135: Under the GLBA Privacy Rule, a financial institution must provide customers the right to opt out of:
- Sharing nonpublic personal information with nonaffiliated third parties (Correct answer)
- Receiving marketing calls from affiliated companies
- All data collection by the institution
- Receiving account statements by mail
Correct answer: Sharing nonpublic personal information with nonaffiliated third parties
The GLBA Privacy Rule gives customers the right to opt out of sharing their nonpublic personal information with unaffiliated third parties.
Question 136: Which of the following best describes 'structured transactions' or 'structuring' under BSA/AML regulations?
- Creating multiple accounts to earn higher interest rates
- Filing multiple SARs for the same customer
- Breaking up large cash transactions specifically to evade CTR reporting requirements (Correct answer)
- Organizing multiple wire transfers for efficiency
Correct answer: Breaking up large cash transactions specifically to evade CTR reporting requirements
Structuring involves deliberately breaking up currency transactions into amounts below $10,000 to avoid triggering CTR filing requirements, which is itself a federal crime.
Question 137: What is 'structuring' in the context of BSA compliance?
- Breaking up transactions to avoid CTR filing requirements (Correct answer)
- Organizing a bank's internal compliance team
- Bundling multiple accounts under one customer profile
- Setting up a tiered customer risk rating system
Correct answer: Breaking up transactions to avoid CTR filing requirements
Structuring (also called 'smurfing') is illegally breaking transactions into smaller amounts to avoid the $10,000 CTR threshold.
Question 138: A Suspicious Activity Report (SAR) must be filed within how many calendar days of the initial detection of facts that may constitute a violation?
- 30 days (Correct answer)
- 15 days
- 60 days
- 45 days
Correct answer: 30 days
Financial institutions must file a SAR within 30 calendar days of initial detection, or 60 days if no suspect is identified.
Question 139: Which of the following BEST describes a 'community development loan' for CRA purposes?
- A loan to any nonprofit organization, regardless of its stated mission
- A personal loan made directly to an LMI individual for home improvement
- A loan whose primary purpose is community development, such as financing affordable housing or supporting LMI-serving community organizations (Correct answer)
- Any loan with an interest rate at or below the current prime rate
Correct answer: A loan whose primary purpose is community development, such as financing affordable housing or supporting LMI-serving community organizations
Community development loans are defined by their primary purpose: supporting affordable housing, community services for LMI individuals, economic development for small businesses, or revitalization of LMI areas.
Question 140: Which of the following is NOT a protected class under the Fair Housing Act?
- Religion
- National origin
- Familial status
- Source of income (Correct answer)
Correct answer: Source of income
The federal Fair Housing Act protects race, color, religion, sex, national origin, disability, and familial status, but does not protect source of income at the federal level.
Question 141: 'Steering' in fair lending means:
- Refusing to process applications from certain zip codes
- Offering rate discounts only to existing customers
- Directing qualified minority borrowers to higher-cost loan products (Correct answer)
- Requiring borrowers to use a specific appraiser
Correct answer: Directing qualified minority borrowers to higher-cost loan products
Steering involves directing creditworthy borrowers who qualify for prime products into higher-cost or subprime products based on protected characteristics.
Question 142: The Home Equity Loan Consumer Protection Act requires lenders to provide disclosures for HELOCs at least how many days before account opening?
- 7 days
- 3 days (Correct answer)
- 1 day
- 5 days
Correct answer: 3 days
Lenders must provide HELOC disclosures at least 3 business days before account opening so consumers can shop and compare.
Question 143: An intermediate small bank under CRA regulations is evaluated using:
- A community development test combined with the small bank lending test (Correct answer)
- A voluntary self-assessment submitted directly to the regulator
- The full three-part large bank test covering lending, investment, and service
- Only the small bank lending test, with no community development component
Correct answer: A community development test combined with the small bank lending test
Intermediate small banks are evaluated under the small bank lending test plus a mandatory community development test, giving them more requirements than small banks but fewer than the full three-part large bank framework.
Question 144: According to federal rules, special-purpose credit is defined as follows:
- Any credit assistance program offered by a not-for-profit organization for the benefit of its members or for the benefit of an economically disadvantaged class of person. (Correct answer)
- Any credit assistance program authorized by federal or state law for the benefit of an economically disadvantaged class of persons (Correct answer)
- If the program includes financial need as a criterion, the creditor can never request and consider information regarding the applicant
- A special-purpose credit program may require members to share a particular attribute (such as race or sex), provided the condition was not made to circumvent the ECOA's standards. Special-purpose credit programs may not discriminate on any forbidden grounds. The bank may gather data on that attribute if the participants must provide it to assess eligibility. (Correct answer)
Correct answer: Any credit assistance program offered by a not-for-profit organization for the benefit of its members or for the benefit of an economically disadvantaged class of person.
This answer is correct because the ECOA permits special-purpose credit programs that target a shared characteristic (such as race or sex) as long as the program is not designed to evade ECOA's protections and does not discriminate on prohibited grounds. It also correctly notes the creditor may collect that characteristic when applicants must supply it to determine eligibility. The wrong option is false because such programs are specifically allowed to request and consider applicant information when financial need is a criterion.
Question 145: A regulatory compliance application is being retired. Under IFPUG guidelines, how should this be reflected in a function point count?
- As a new development count for the replacement system only
- No count is required since the application is being removed
- As an EIF addition in the remaining systems that referenced it
- As a deletion in an enhancement count, reducing the application baseline to zero (Correct answer)
Correct answer: As a deletion in an enhancement count, reducing the application baseline to zero
When an application is fully retired, all its functions are counted as deleted in an enhancement count, bringing the baseline size to zero.
Question 146: Which law prohibits financial institutions from sharing nonpublic personal information with nonaffiliated third parties without giving customers an opt-out opportunity?
- Equal Credit Opportunity Act
- Electronic Fund Transfer Act
- Gramm-Leach-Bliley Act (Correct answer)
- Fair Credit Reporting Act
Correct answer: Gramm-Leach-Bliley Act
The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to provide privacy notices and allow customers to opt out of information sharing with nonaffiliated third parties.
Question 147: Under RESPA's Section 10, the maximum amount a servicer may require a borrower to maintain in an escrow account for taxes and insurance is capped at:
- Two months of estimated payments plus a cushion (Correct answer)
- Three months of estimated payments
- Six months of estimated payments
- One month of estimated payments
Correct answer: Two months of estimated payments plus a cushion
RESPA Section 10 limits escrow cushions to no more than one-sixth of total annual disbursements (equivalent to two months of payments).
Question 148: Which of the following is an 'exception hold' permitted under Regulation CC?
- A hold placed on a deposit because the depositor has a repeatedly overdrawn account (Correct answer)
- A hold placed on all payroll deposits regardless of amount
- A hold on all deposits made after 3 p.m.
- A hold on cashier's checks for first-time account holders only
Correct answer: A hold placed on a deposit because the depositor has a repeatedly overdrawn account
Regulation CC allows exception holds for accounts with repeated overdrafts, among other exceptions, extending the standard availability schedule.
Question 149: For creating a deposit account, a bank gave a customer a gift with a fair market value of $25. Which of the following best sums up the gift's legal reporting status?
- The fair market value of the gift is added to the interest paid and reported on Form 1099-INT. (Correct answer)
- If the cost of the gift is under $20.00, it is not reportable to the IRS.
- The fair market value of the gift is reported to the customer on the periodic statement.
- The cost of the gift is credited to the customer's account as a bonus, increasing the account balance.
Correct answer: The fair market value of the gift is added to the interest paid and reported on Form 1099-INT.
The proper reporting status of the gift given to the customer for opening a deposit account is that the fair market value of the gift is added to the interest paid and reported on Form 1099-INT.
Question 150: 'Disparate impact' in fair lending refers to:
- A borrower who disputes a loan denial
- Charging different rates to different bank branches
- A neutral lending policy that disproportionately harms a protected class (Correct answer)
- A lender who openly states discriminatory policies
Correct answer: A neutral lending policy that disproportionately harms a protected class
Disparate impact occurs when a facially neutral policy has a disproportionate adverse effect on a protected class without business justification.
Question 151: Which of the following is NOT one of the three performance tests applied to large banks under CRA?
- Service Test
- Capital Adequacy Test (Correct answer)
- Investment Test
- Lending Test
Correct answer: Capital Adequacy Test
Large banks are evaluated under the Lending Test, Investment Test, and Service Test; there is no Capital Adequacy Test under CRA.
Question 152: Which one of the following bank policies is in violation of the Interagency Policy Statement on the Retail Sales of Nondeposit Investments?
- Tellers and new accounts personnel will receive a $25 fee for all customers referred to the nondeposit investment department on the customer's purchase of an investment product. (Correct answer)
- The incorrectteller will talk to a bank customer about nondeposit investment options.
- The amount of revenue that each department generates and how well each department can help clients identify suitable investments will determine how much supervisors and sales staff are paid.
- Before a customer buys a nondeposit investment product, all bank personnel who are involved in the sale of nondeposit investments must give the consumer the bank's mandatory disclosures.
Correct answer: Tellers and new accounts personnel will receive a $25 fee for all customers referred to the nondeposit investment department on the customer's purchase of an investment product.
The policy stating that tellers and new accounts personnel will receive a $25 fee for all customers referred to the nondeposit investment department on the customer's purchase of an investment product does NOT comply with the Interagency Policy Statement on the Retail Sales of Nondeposit Investments.
Question 153: A compliance system receives data from a third-party regulator's database and stores it internally for reporting. How should the regulator's database be counted in IFPUG FPA?
- As an External Output (EO)
- As an External Interface File (EIF) (Correct answer)
- As an External Input (EI)
- As an Internal Logical File (ILF)
Correct answer: As an External Interface File (EIF)
Data maintained by an external application and referenced (but not maintained) by the counted application is classified as an External Interface File.
Question 154: Which examination procedure involves testing a random sample of loan files to identify patterns of potential discrimination?
- Compliance management system review
- Self-assessment audit
- Mystery shopping
- Comparative file review (Correct answer)
Correct answer: Comparative file review
Comparative file review involves examiners comparing loan files from different demographic groups to identify disparities in treatment that may indicate discrimination.
Question 155: Under the Electronic Fund Transfer Act (EFTA), what is a consumer's maximum liability for unauthorized electronic transfers if they notify the bank within 2 days?
- $5,000
- $50 (Correct answer)
- $500
- $0
Correct answer: $50
Under Regulation E, if a consumer reports an unauthorized EFT within two business days, their liability is limited to $50.
Question 156: Under the Bank Service Company Act, when a bank contracts with a third party for services, the bank's compliance obligations:
- Remain with the bank; it cannot outsource its compliance responsibilities (Correct answer)
- Transfer entirely to the third-party vendor
- Apply only to services over $1 million in annual contract value
- Are split 50-50 between the bank and vendor
Correct answer: Remain with the bank; it cannot outsource its compliance responsibilities
Banks cannot outsource their compliance responsibilities; they remain responsible for compliance even when services are performed by third-party vendors.
Question 157: The Servicemembers Civil Relief Act (SCRA) provides which protection to active duty military members?
- Requires banks to provide free checking accounts
- Waives all mortgage payments during overseas deployment
- Caps interest rates on pre-service debts at 6% during active duty (Correct answer)
- Eliminates all debt obligations during deployment
Correct answer: Caps interest rates on pre-service debts at 6% during active duty
The SCRA caps interest rates at 6% on debts incurred prior to active duty service for qualifying servicemembers.
Question 158: Under 12 CFR Part 30 (OCC Safety and Soundness Standards), banks are required to maintain:
- An independent board compliance committee with a majority of outside directors
- Separate compliance and risk management departments in all cases
- A compliance management system sufficient to ensure compliance with applicable laws and regulations (Correct answer)
- A minimum of five compliance officers
Correct answer: A compliance management system sufficient to ensure compliance with applicable laws and regulations
OCC safety and soundness standards require national banks to have compliance management systems adequate to identify, manage, and control compliance risks.
Question 159: The Military Lending Act (MLA) caps the Military Annual Percentage Rate (MAPR) for covered loans to active-duty servicemembers at:
- 18%
- 28%
- 36% (Correct answer)
- 21%
Correct answer: 36%
The MLA imposes a 36% MAPR cap on consumer credit extended to covered active-duty servicemembers and their dependents.
Question 160: What is the most significant regulatory consequence of receiving a 'Substantial Noncompliance' CRA rating?
- Severe restrictions on regulatory approvals for mergers, acquisitions, and new branch applications (Correct answer)
- Requirement to immediately hire a court-appointed CRA compliance monitor
- Mandatory criminal referrals to the Department of Justice for bank officers
- Automatic revocation of federal deposit insurance within 180 days
Correct answer: Severe restrictions on regulatory approvals for mergers, acquisitions, and new branch applications
A 'Substantial Noncompliance' rating is the most severe CRA outcome and creates major obstacles to obtaining regulatory approval for any expansion activity, including mergers, acquisitions, and new branch openings.
Question 161: Under TILA's right of rescission, a borrower has how many business days to cancel a non-purchase home-secured loan?
- 1 business day
- 5 business days
- 7 business days
- 3 business days (Correct answer)
Correct answer: 3 business days
Borrowers have three business days to rescind (cancel) a non-purchase home-secured loan after consummation, delivery of the rescission notice, or delivery of required disclosures.
Question 162: Under the Bank Secrecy Act, what is the threshold dollar amount that triggers a Currency Transaction Report (CTR)?
- $25,000
- $5,000
- $50,000
- $10,000 (Correct answer)
Correct answer: $10,000
Financial institutions must file a CTR for cash transactions exceeding $10,000 in a single business day by or for any person.
Question 163: Under the Home Mortgage Disclosure Act (HMDA), which type of institution is generally required to report HMDA data?
- Any entity that originates at least one mortgage loan per year
- Only institutions supervised by the Federal Reserve
- All non-bank mortgage companies regardless of size
- Depository institutions meeting asset and loan volume thresholds in metropolitan statistical areas (Correct answer)
Correct answer: Depository institutions meeting asset and loan volume thresholds in metropolitan statistical areas
HMDA coverage depends on asset size, loan volume thresholds, and geographic location in or near an MSA for depository institutions.
Question 164: In a compliance risk assessment, 'inherent risk' is best defined as:
- The risk associated with third-party vendors only
- Risk identified during a regulatory examination
- The risk remaining after controls are applied
- The level of risk present before any mitigating controls are considered (Correct answer)
Correct answer: The level of risk present before any mitigating controls are considered
Inherent risk is the gross or raw level of risk that exists in a process or product before any controls, policies, or mitigating factors are taken into account.
Question 165: Recently, a compliance specialist learned that the bank had failed to submit and disclose a complete covered agreement as required by the CRA Sunshine Act. What has to be supplied in order to guarantee accurate reporting going forward?
- Grants or loans to fulfill CRA activity (Correct answer)
- All individual mortgage loans
- Non-public or confidential information that will be provided in the public file
- A copy of the agreement to the regulatory agency 24 months after the end of the term
Correct answer: Grants or loans to fulfill CRA activity
The CRA Sunshine Act requires certain financial institutions to report and disclose information about covered agreements, which are agreements related to the institution's CRA activities. This includes agreements for grants, loans, or other forms of assistance provided to fulfill CRA obligations.
Question 166: Tellers at ACME Bank are encouraged to assist in the sale of insurance products to both potential and current clients.
- It is hard for tellers to handle so many types of products. (Correct answer)
- It is hard to physically separate insured deposit products from insurance products.
- It is difficult for many people to get an insurance license.
- Tellers should not be rewarded only when the referral results in a sale.
Correct answer: It is hard for tellers to handle so many types of products.
While it may be challenging for tellers to handle multiple types of products, ACME Bank's decision to have tellers help sell insurance products to new and existing customers raises potential concerns.
Question 167: Which federal law requires financial institutions to establish a Customer Identification Program (CIP) as part of their BSA compliance?
- Bank Holding Company Act
- USA PATRIOT Act of 2001 (Correct answer)
- Financial Modernization Act
- Dodd-Frank Wall Street Reform Act
Correct answer: USA PATRIOT Act of 2001
The USA PATRIOT Act of 2001 required financial institutions to implement CIP procedures to verify the identity of customers opening new accounts.
Question 168: Under the National Flood Insurance Program (NFIP), lenders must require flood insurance for loans secured by properties located in:
- A Special Flood Hazard Area (SFHA) as designated by FEMA (Correct answer)
- Any property with a basement
- Any coastal state
- Any property built before 1980
Correct answer: A Special Flood Hazard Area (SFHA) as designated by FEMA
Federal law requires lenders to mandate flood insurance for improved real estate or mobile homes located in a FEMA-designated Special Flood Hazard Area.
Question 169: Which regulation implements the Truth in Savings Act (TISA) and governs disclosure requirements for deposit accounts?
- Regulation E
- Regulation DD (Correct answer)
- Regulation Z
- Regulation B
Correct answer: Regulation DD
Regulation DD implements TISA and requires depository institutions to disclose terms and conditions of deposit accounts, including APY.
Question 170: The Unfair, Deceptive, or Abusive Acts or Practices (UDAAP) authority was granted to the CFPB by which legislation?
- Gramm-Leach-Bliley Financial Services Modernization Act
- Federal Trade Commission Act of 1914
- Dodd-Frank Wall Street Reform and Consumer Protection Act (Correct answer)
- Consumer Financial Protection Act of 1987
Correct answer: Dodd-Frank Wall Street Reform and Consumer Protection Act
The Dodd-Frank Act of 2010 granted the CFPB authority to prohibit unfair, deceptive, or abusive acts or practices, adding 'abusive' to the long-standing UDAP standard.
Question 171: A bank's compliance management system (CMS) is evaluated during examinations on which key components?
- Profitability, liquidity, capital adequacy, and asset quality
- IT infrastructure, cybersecurity posture, vendor management, and capital planning
- Board and management oversight, compliance program, response to consumer complaints, and compliance audit (Correct answer)
- Branch network efficiency, product pricing, and customer satisfaction scores
Correct answer: Board and management oversight, compliance program, response to consumer complaints, and compliance audit
Examiners assess a bank's CMS based on board/management oversight, the compliance program's design and implementation, complaint management, and internal audit.
Question 172: Which of the following actions would constitute a violation of the Unfair, Deceptive, or Abusive Acts or Practices (UDAAP) standard under Dodd-Frank?
- Declining to approve a high-risk loan application
- Requiring documentation before extending credit
- Misrepresenting the cost of add-on products to obtain consumer consent (Correct answer)
- Charging a disclosed overdraft fee
Correct answer: Misrepresenting the cost of add-on products to obtain consumer consent
Misrepresenting the cost or terms of add-on products to manipulate consumer decision-making is a deceptive act or practice prohibited by UDAAP.
Question 173: Under OFAC regulations, what must a bank do when a transaction involves a specially designated national (SDN)?
- Block or reject the transaction and report to OFAC (Correct answer)
- Notify the customer of the screening result
- File a SAR within 10 days
- Increase the customer's risk rating
Correct answer: Block or reject the transaction and report to OFAC
When an OFAC match is identified, the bank must block or reject the transaction and file a report with OFAC.
Question 174: In IFPUG function point counting, what does the term 'application boundary' define?
- The regulatory jurisdiction governing the software
- The maximum number of users permitted to access the system
- The physical server infrastructure hosting the compliance system
- The conceptual interface between the application being measured and the external world (Correct answer)
Correct answer: The conceptual interface between the application being measured and the external world
The application boundary separates the application being measured from its users and other applications, determining what is counted inside versus outside.
Question 175: Which examination concept describes the risk that a bank's failure to comply with laws and regulations will result in legal penalties, financial loss, or reputational damage?
- Compliance risk (Correct answer)
- Operational risk
- Reputational risk
- Strategic risk
Correct answer: Compliance risk
Compliance risk is defined as the risk of legal or regulatory sanctions, material financial loss, or loss to reputation arising from failure to comply with laws and regulations.
Question 176: Under the BSA, which type of institution is required to file Suspicious Activity Reports?
- Only institutions with assets over $1 billion
- Banks, credit unions, money services businesses, and broker-dealers (Correct answer)
- Only national banks
- Only federally insured institutions
Correct answer: Banks, credit unions, money services businesses, and broker-dealers
SAR filing requirements apply broadly to banks, credit unions, money services businesses, broker-dealers, and other covered institutions.
Question 177: Under the FTC's updated Safeguards Rule, which institutions are subject to the rule?
- Only federally chartered banks and credit unions
- All businesses that handle consumer data
- Financial institutions not subject to the jurisdiction of another federal regulator (e.g., mortgage brokers, auto dealers, tax preparers) (Correct answer)
- Only institutions with revenue over $10 million annually
Correct answer: Financial institutions not subject to the jurisdiction of another federal regulator (e.g., mortgage brokers, auto dealers, tax preparers)
The FTC Safeguards Rule covers non-bank financial institutions under FTC jurisdiction, such as mortgage brokers, payday lenders, auto dealers, and tax preparers.
Question 178: Under the GLBA Safeguards Rule, covered institutions must test or monitor the effectiveness of their security controls:
- Only when they experience a breach
- Every five years via third-party audit
- Only if directed to do so by an examiner
- Regularly, as part of the information security program (Correct answer)
Correct answer: Regularly, as part of the information security program
The Safeguards Rule requires regular testing and monitoring of key controls and systems to ensure they are effective and up to date.
Question 179: A Suspicious Activity Report (SAR) must generally be filed within how many days of detecting a suspicious transaction?
- 45 days
- 60 days
- 30 days (Correct answer)
- 15 days
Correct answer: 30 days
SARs must be filed within 30 calendar days of the date of initial detection of suspicious activity.
Question 180: Which regulation implements the Truth in Lending Act (TILA) and requires disclosure of APR and finance charges?
- Regulation E
- Regulation DD
- Regulation Z (Correct answer)
- Regulation B
Correct answer: Regulation Z
Regulation Z implements TILA and requires lenders to disclose credit terms including APR, finance charges, and total payments to help consumers compare credit offers.
Question 181: Which of the following BEST qualifies as a community development service under CRA?
- Installing ATMs exclusively in high-income shopping districts
- Offering premium interest rates to attract high-net-worth depositors
- Providing free financial literacy workshops to low- and moderate-income individuals (Correct answer)
- Developing mobile banking features targeted at business customers
Correct answer: Providing free financial literacy workshops to low- and moderate-income individuals
Financial literacy education and counseling services targeted to LMI individuals qualify as community development services under CRA.
Question 182: With the exception of the following circumstances, a borrower may cancel a loan agreement:
- A loan to settle a deed contract secured by the borrower's principal residence
- An expansion of a credit line from $5,000 to $10,000 that is secured by the borrower's principal residence
- A revolving line of credit used to upgrade the borrower's principal residence and secured by that property
- A line of credit used for the borrower's business, secured by the borrower's primary dwelling (Correct answer)
Correct answer: A line of credit used for the borrower's business, secured by the borrower's primary dwelling
TILA does not grant the right to rescind for loans that are primarily for business purposes. In the situation you mentioned, where a line of credit is used for the borrower's business and secured by their primary dwelling, the borrower does not have the right to rescind the loan agreement.
Question 183: The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to provide customers with a privacy notice:
- Only when sharing data with unaffiliated third parties
- Every two years
- Only when the customer requests one
- At account opening and annually thereafter (Correct answer)
Correct answer: At account opening and annually thereafter
GLBA requires an initial privacy notice at account opening and annual notices to all existing customers describing information-sharing practices.
Question 184: Under the Community Reinvestment Act (CRA), which examination component evaluates a bank's record of making loans in its assessment area?
- Investment test
- Lending test (Correct answer)
- Service test
- Community development test
Correct answer: Lending test
The lending test is the most heavily weighted CRA component and evaluates the number and dollar amount of loans made within the assessment area.
Question 185: Which federal agencies are responsible for conducting CRA examinations?
- Only the CFPB for all consumer compliance matters
- The SEC, FINRA, and the Treasury Department
- The Federal Reserve, OCC, and FDIC (Correct answer)
- The NCUA for all federally insured institutions
Correct answer: The Federal Reserve, OCC, and FDIC
The three primary federal bank regulators — the Federal Reserve (state member banks), OCC (national banks and federal thrifts), and FDIC (state nonmember banks) — each conduct CRA examinations for their supervised institutions.
Question 186: Under the USA PATRIOT Act Section 326, a Customer Identification Program (CIP) must, at minimum, collect which information for individual accounts?
- Net worth and source of funds
- Credit score and employment history
- Employment and banking history
- Name, date of birth, address, and identification number (Correct answer)
Correct answer: Name, date of birth, address, and identification number
The CIP minimum requirements for individuals are name, date of birth, address, and an identification number (e.g., SSN or passport number).
Question 187: According to IFPUG, what is the unadjusted function point (UFP) value for a low-complexity Internal Logical File?
- 5
- 10
- 15
- 7 (Correct answer)
Correct answer: 7
A low-complexity ILF is assigned 7 unadjusted function points according to the IFPUG Counting Practices Manual.
Question 188: Which section of the GLBA covers the financial privacy provisions and requires initial and annual privacy notices?
- Title II (Functional Regulation)
- Title IV (Unilateral Banking)
- Title I (Bank Affiliations)
- Title V (Privacy of Consumer Financial Information) (Correct answer)
Correct answer: Title V (Privacy of Consumer Financial Information)
Title V of the GLBA contains the privacy provisions requiring financial institutions to provide privacy notices and honor opt-out rights.
Question 189: In IFPUG's enhancement function point counting formula, which equation correctly represents the size of an enhancement project?
- EFP = (ADD + MOD) / DEL
- EFP = (ADD + CHGA + CFP) - DEL (Correct answer)
- EFP = ADD + MOD + DEL + CFP
- EFP = CFP + DEL - ADD
Correct answer: EFP = (ADD + CHGA + CFP) - DEL
The IFPUG enhancement formula is EFP = (ADD + CHGA + CFP) - DEL, where CHGA is changed functionality, CFP is conversion function points, and DEL is deleted functionality.
Question 190: Which IFPUG body is responsible for maintaining and updating the Counting Practices Manual (CPM)?
- The IFPUG Methodologies Committee (Correct answer)
- The Software Engineering Institute (SEI)
- The ISO/IEC JTC1 SC7 subcommittee
- The Object Management Group (OMG)
Correct answer: The IFPUG Methodologies Committee
The IFPUG Methodologies Committee is the internal body responsible for developing and updating the CPM that governs function point counting rules.
Question 191: 'Redlining,' as addressed by the CRA, refers to:
- Refusing or significantly limiting financial services in geographic areas based on the race or ethnicity of residents (Correct answer)
- Setting interest rates higher for loans in certain zip codes due to lower property values
- Marking loan files with color codes to indicate risk levels for internal tracking
- Targeting LMI areas with non-traditional or high-cost loan products
Correct answer: Refusing or significantly limiting financial services in geographic areas based on the race or ethnicity of residents
Redlining is the discriminatory practice of denying or limiting banking services in specific geographic areas based on the racial or ethnic composition of those communities, and is a central concern the CRA was designed to address.
Question 192: Which of the following loans is a loan for which First Savings Bank is exempt from submitting a 1098-E (Student Loan Interest) report?
- A $15,000 loan to Linda Chu to be used for the purpose of paying tuition and fees and purchasing college books, lab equipment, and a computer for use in her education at the local community college
- A $35,000 line of credit made to Don and Barbara Cocelli, secured by their home, for the payment of certified school expenses for their twin daughters at an accredited private school
- A $10,000 tuition loan made to Bobby Wilcox, a student at the state university, guaranteed by the Department of Education
- A $12,000 loan to Paul and Rhonda Pena and their daughter Jennifer, used to pay her college tuition as well as the tuition at the private high school her sister, Jeanne, attends (Correct answer)
Correct answer: A $12,000 loan to Paul and Rhonda Pena and their daughter Jennifer, used to pay her college tuition as well as the tuition at the private high school her sister, Jeanne, attends
First Savings Bank does not have to provide a 1098-E (Student Loan Interest) report for the loan described in the scenario: a $12,000 loan to Paul and Rhonda Pena and their daughter Jennifer, used to pay her college tuition as well as the tuition at the private high school her sister, Jeanne, attends.
Question 193: What is the primary purpose of a 'correspondent banking' due diligence program under BSA?
- To verify domestic retail customers' identities
- To assess the AML risks of foreign financial institutions using the bank's services (Correct answer)
- To screen mortgage applicants
- To monitor employee personal accounts
Correct answer: To assess the AML risks of foreign financial institutions using the bank's services
Correspondent banking due diligence assesses the AML controls and risk profile of foreign banks that access U.S. financial services.
Question 194: The FTC's Safeguards Rule (updated 2023) requires covered financial institutions to designate:
- A dedicated compliance hotline for data breach reports
- A board-level Privacy Committee
- An external auditor to certify the program annually
- A qualified individual to oversee the information security program (Correct answer)
Correct answer: A qualified individual to oversee the information security program
The updated FTC Safeguards Rule requires covered institutions to designate a qualified individual (e.g., CISO) to oversee the information security program.
Question 195: The Community Reinvestment Act (CRA) was enacted primarily to address which practice?
- Excessive bank fees charged to low-income customers
- Unfair debt collection by banks
- Predatory mortgage lending practices
- Redlining and credit discrimination in low-income communities (Correct answer)
Correct answer: Redlining and credit discrimination in low-income communities
CRA was enacted in 1977 to combat redlining, where banks refused to provide credit or services to residents in low-income or minority neighborhoods.
Question 196: Which IFPUG principle ensures that counting is independent of the programming language or technology used?
- Vendor neutrality clause in the CPM
- Technology independence (language-neutral measurement from the user's perspective) (Correct answer)
- Application boundary exclusion of technical components
- ISO/IEC 14143 compliance requirement
Correct answer: Technology independence (language-neutral measurement from the user's perspective)
IFPUG FPA measures functionality from the user's perspective, making the count independent of implementation technology or programming language.
Question 197: Under Regulation W, transactions between a bank and its affiliates are restricted primarily to prevent:
- The bank from offering services in states where its affiliate operates
- Banks from acquiring insurance companies
- The bank from competing with non-affiliated institutions
- The affiliate from using the bank to fund itself at preferential terms at depositor expense (Correct answer)
Correct answer: The affiliate from using the bank to fund itself at preferential terms at depositor expense
Regulation W (implementing Sections 23A and 23B of the Federal Reserve Act) prevents affiliates from using a bank's insured deposits to fund their own operations on favorable terms.
Question 198: What is the minimum retention period for BSA-related records such as CTRs and SARs?
- 2 years
- 5 years (Correct answer)
- 7 years
- 3 years
Correct answer: 5 years
BSA requires financial institutions to retain most BSA records for a minimum of five years.
Question 199: Under the Flood Disaster Protection Act, a lender that fails to require flood insurance when required must:
- File a report with FEMA within 60 days
- Notify the borrower within 10 business days
- Force-place the flood insurance and charge the premium to the borrower (Correct answer)
- Immediately call the loan
Correct answer: Force-place the flood insurance and charge the premium to the borrower
If a lender determines flood insurance is required but not maintained, the lender must force-place insurance and may charge the cost to the borrower.
Question 200: The Main Street branch manager calls and shares the following details: On Tuesday at ten o'clock, Steve bought a cashier's check for one thousand dollars. When Mr. Steve returned at 11:30 a.m., he bought a cashier's check for $2,500 in cash and deposited the traveler's checks into his bank account. Mr. Steve returned at 4:00, putting $8,000 in cash into his bank account. Since this deposit was made after regular banking hours, Wednesday's business date was used to record it. What steps ought the bank to take?
- Record the $1,000 and $2,500 transactions on the bank's monetary instrument sales log because the total exceeds the $3,000 threshold (Correct answer)
- File a Currency Transaction Report (CTR) for $11,500
- None, because no single cash transaction exceeded $10,000
- Record the $1,000, $2,500, and $9,000 transactions on the bank's monetary instrument sales log because the total exceeds the $3,000 threshold
Correct answer: Record the $1,000 and $2,500 transactions on the bank's monetary instrument sales log because the total exceeds the $3,000 threshold
The bank should record the $1,000 and $2,500 transactions on the bank's monetary instrument sales log because the total exceeds the $3,000 threshold.
Certified Regulatory Compliance Manager (CRCM)
The CRCM, administered by the American Bankers Association (ABA), validates expertise in bank regulatory compliance across consumer protection regulations, foundational banking rules, and compliance management systems. It is the premier compliance certification for banking professionals.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds