Certified Regulatory Compliance Manager (CRCM) — Questions and Answers
Question 1: A CRCM using IFPUG metrics to estimate a regulatory reporting project finds that a transaction updates data in two ILFs and references one EIF. What is the minimum number of Data Element Types (DETs) that must be counted for the EIF?
- One fixed DET regardless of fields
- Zero, because EIFs are not counted at the transaction level
- One DET per unique field referenced by the transaction (Correct answer)
- DETs are only counted for ILFs, not EIFs
Correct answer: One DET per unique field referenced by the transaction
DETs for an EIF are counted as the unique user-recognizable, non-repeated fields that are referenced across all transactions that use that EIF.
Question 2: Which federal agencies are responsible for conducting CRA examinations?
- The SEC, FINRA, and the Treasury Department
- The NCUA for all federally insured institutions
- The Federal Reserve, OCC, and FDIC (Correct answer)
- Only the CFPB for all consumer compliance matters
Correct answer: The Federal Reserve, OCC, and FDIC
The three primary federal bank regulators — the Federal Reserve (state member banks), OCC (national banks and federal thrifts), and FDIC (state nonmember banks) — each conduct CRA examinations for their supervised institutions.
Question 3: Under the Electronic Fund Transfer Act (EFTA), what is a consumer's maximum liability for unauthorized electronic transfers if they notify the bank within 2 days?
- $5,000
- $0
- $500
- $50 (Correct answer)
Correct answer: $50
Under Regulation E, if a consumer reports an unauthorized EFT within two business days, their liability is limited to $50.
Question 4: Under 12 CFR Part 30 (OCC Safety and Soundness Standards), banks are required to maintain:
- Separate compliance and risk management departments in all cases
- A compliance management system sufficient to ensure compliance with applicable laws and regulations (Correct answer)
- An independent board compliance committee with a majority of outside directors
- A minimum of five compliance officers
Correct answer: A compliance management system sufficient to ensure compliance with applicable laws and regulations
OCC safety and soundness standards require national banks to have compliance management systems adequate to identify, manage, and control compliance risks.
Question 5: The principle of 'data minimization' in information security compliance means:
- Reducing the font size of privacy notices to save paper
- Collecting and retaining only the personal data necessary for a specific purpose (Correct answer)
- Minimizing the number of employees who receive data security training
- Using the smallest possible servers for data storage
Correct answer: Collecting and retaining only the personal data necessary for a specific purpose
Data minimization means limiting data collection and retention to only what is necessary for the stated business purpose, reducing exposure risk.
Question 6: Which regulation implements the Home Mortgage Disclosure Act (HMDA)?
- Regulation B
- Regulation Z
- Regulation X
- Regulation C (Correct answer)
Correct answer: Regulation C
Regulation C is the CFPB's implementing regulation for the Home Mortgage Disclosure Act.
Question 7: The Equal Credit Opportunity Act (ECOA) prohibits discrimination in credit transactions based on which of the following?
- Credit score below 600
- Race, color, religion, national origin, sex, marital status, or age (Correct answer)
- Loan amount below $1,000
- Employment less than two years
Correct answer: Race, color, religion, national origin, sex, marital status, or age
ECOA prohibits credit discrimination based on race, color, religion, national origin, sex, marital status, age, and receipt of public assistance.
Question 8: In a compliance risk assessment, 'inherent risk' is best defined as:
- Risk identified during a regulatory examination
- The risk remaining after controls are applied
- The level of risk present before any mitigating controls are considered (Correct answer)
- The risk associated with third-party vendors only
Correct answer: The level of risk present before any mitigating controls are considered
Inherent risk is the gross or raw level of risk that exists in a process or product before any controls, policies, or mitigating factors are taken into account.
Question 9: Under the Gramm-Leach-Bliley Act (GLBA), financial institutions must provide customers with a privacy notice:
- Only when a customer requests it
- Only when sharing data with third parties
- At account opening and annually thereafter (Correct answer)
- Once every five years
Correct answer: At account opening and annually thereafter
GLBA requires institutions to provide privacy notices at account opening and annually, informing customers of information sharing practices.
Question 10: A bank employee who knowingly assists a customer in structuring transactions to avoid reporting requirements may be charged with:
- Federal criminal violations including conspiracy (Correct answer)
- Negligence only
- A minor compliance infraction
- A civil violation only
Correct answer: Federal criminal violations including conspiracy
Bank employees who assist in structuring can face federal criminal charges including conspiracy and aiding and abetting.
Question 11: Under IFPUG guidelines, which statement best describes the relationship between Function Point Analysis and software quality metrics for a compliance program?
- FPA measures size only; quality metrics such as defect density must be separately applied using FP as the denominator (Correct answer)
- FPA directly measures both size and software reliability in a single metric
- FPA quality scores are reported directly to regulatory bodies as compliance evidence
- FPA replaces the need for quality audits in regulated environments
Correct answer: FPA measures size only; quality metrics such as defect density must be separately applied using FP as the denominator
IFPUG FPA is a pure size measurement; it enables quality metrics like defects per function point when defect data is combined with the FP count.
Question 12: Regulation Z implements which federal consumer protection law?
- Truth in Lending Act (Correct answer)
- Fair Credit Reporting Act
- Electronic Fund Transfer Act
- Fair Debt Collection Practices Act
Correct answer: Truth in Lending Act
Regulation Z is the Federal Reserve's (and now CFPB's) implementing regulation for the Truth in Lending Act.
Question 13: The Military Lending Act (MLA) caps the Military Annual Percentage Rate (MAPR) for most consumer credit products at:
- 50%
- 28%
- 18%
- 36% (Correct answer)
Correct answer: 36%
The MLA imposes a 36% MAPR cap on most consumer credit extended to covered servicemembers and their dependents.
Question 14: Under GLBA, which sharing arrangement does NOT require customer opt-out rights?
- Sharing with nonaffiliated credit card processors under a joint marketing agreement
- Sharing with a nonaffiliated data broker for marketing purposes
- Sharing customer data with affiliated companies (Correct answer)
- Sharing with nonaffiliated insurance companies for cross-selling
Correct answer: Sharing customer data with affiliated companies
Sharing customer information with affiliated companies (companies under common control) does not require an opt-out right under the GLBA Privacy Rule, though customers may be given a limit right.
Question 15: The Military Lending Act (MLA) caps the Military Annual Percentage Rate (MAPR) for covered loans to active-duty servicemembers at:
- 18%
- 28%
- 21%
- 36% (Correct answer)
Correct answer: 36%
The MLA imposes a 36% MAPR cap on consumer credit extended to covered active-duty servicemembers and their dependents.
Question 16: A bank that receives a CRA rating of 'Needs to Improve' is MOST likely to face which consequence?
- Loss of federal deposit insurance within 90 days
- Mandatory reduction of all loan interest rates to below-prime levels
- Immediate closure of all branches in low-income areas
- Increased regulatory scrutiny and potential delays or denials on applications for expansion (Correct answer)
Correct answer: Increased regulatory scrutiny and potential delays or denials on applications for expansion
A 'Needs to Improve' CRA rating subjects the bank to heightened regulatory scrutiny and can result in delays or denial of merger, acquisition, or branching applications.
Question 17: A bank's compliance management system (CMS) is evaluated during examinations on which key components?
- IT infrastructure, cybersecurity posture, vendor management, and capital planning
- Board and management oversight, compliance program, response to consumer complaints, and compliance audit (Correct answer)
- Profitability, liquidity, capital adequacy, and asset quality
- Branch network efficiency, product pricing, and customer satisfaction scores
Correct answer: Board and management oversight, compliance program, response to consumer complaints, and compliance audit
Examiners assess a bank's CMS based on board/management oversight, the compliance program's design and implementation, complaint management, and internal audit.
Question 18: The CRA strategic plan option allows a bank to:
- Defer CRA compliance for up to three years while developing internal systems
- Use peer bank benchmarks instead of assessment-area-specific targets
- Set its own measurable CRA goals, subject to public comment and regulatory approval (Correct answer)
- Be exempt from the lending test if it commits to community investment targets
Correct answer: Set its own measurable CRA goals, subject to public comment and regulatory approval
Under the strategic plan option, a bank may develop its own CRA goals, make the plan available for public comment, and then submit it to its regulator for approval, providing a customized compliance framework.
Question 19: Recently, a compliance specialist learned that the bank had failed to submit and disclose a complete covered agreement as required by the CRA Sunshine Act. What has to be supplied in order to guarantee accurate reporting going forward?
- All individual mortgage loans
- Non-public or confidential information that will be provided in the public file
- A copy of the agreement to the regulatory agency 24 months after the end of the term
- Grants or loans to fulfill CRA activity (Correct answer)
Correct answer: Grants or loans to fulfill CRA activity
The CRA Sunshine Act requires certain financial institutions to report and disclose information about covered agreements, which are agreements related to the institution's CRA activities. This includes agreements for grants, loans, or other forms of assistance provided to fulfill CRA obligations.
Question 20: Under the Electronic Fund Transfer Act (EFTA), consumers have how many business days to report an unauthorized electronic fund transfer to limit liability to $50?
- 60 days
- 2 business days (Correct answer)
- 30 days
- 10 business days
Correct answer: 2 business days
Consumers must report unauthorized EFTs within 2 business days of learning of the loss to limit liability to $50.
Question 21: When auditing a compliance system's function point count, a CRCM notices the count includes a password field. Under IFPUG rules, how should a password or encrypted field typically be handled?
- It is counted as one DET if it is user-identifiable, regardless of whether it is displayed in encrypted form (Correct answer)
- Password fields count as a full RET within the ILF
- Each character of a password counts as a separate DET
- Encrypted fields are always excluded from DETs
Correct answer: It is counted as one DET if it is user-identifiable, regardless of whether it is displayed in encrypted form
A password field is a single user-identifiable attribute and counts as one DET even if its value is masked or encrypted in the user interface.
Question 22: In IFPUG's enhancement function point counting formula, which equation correctly represents the size of an enhancement project?
- EFP = (ADD + MOD) / DEL
- EFP = (ADD + CHGA + CFP) - DEL (Correct answer)
- EFP = CFP + DEL - ADD
- EFP = ADD + MOD + DEL + CFP
Correct answer: EFP = (ADD + CHGA + CFP) - DEL
The IFPUG enhancement formula is EFP = (ADD + CHGA + CFP) - DEL, where CHGA is changed functionality, CFP is conversion function points, and DEL is deleted functionality.
Question 23: Which of the following categories of workers needs to get instruction on how to utilize W-9 forms precisely?
- Auditors and accountants
- Senior Management
- New account officers (Correct answer)
- Security officers
Correct answer: New account officers
W-9 forms are used to collect taxpayer identification information from individuals or entities that may be subject to certain reporting requirements, such as providing payments or income to them. The purpose of the W-9 form is to obtain the recipient's correct taxpayer identification number (TIN) and other relevant information for tax reporting purposes.
Question 24: A Suspicious Activity Report (SAR) must generally be filed within how many days of detecting a suspicious transaction?
- 30 days (Correct answer)
- 15 days
- 45 days
- 60 days
Correct answer: 30 days
SARs must be filed within 30 calendar days of the date of initial detection of suspicious activity.
Question 25: Under the interagency guidelines for safeguarding customer information, financial institutions must conduct which activity to identify risks to customer data?
- A quarterly review of employee social media accounts
- A risk assessment to identify reasonably foreseeable risks (Correct answer)
- A customer survey on data handling preferences
- An annual external penetration test only
Correct answer: A risk assessment to identify reasonably foreseeable risks
The interagency guidelines require financial institutions to conduct a risk assessment to identify and evaluate internal and external risks to customer data security.
Question 26: Under the CRA service test for large banks, examiners evaluate:
- Whether the bank has met its minimum community development loan targets
- Exclusively the bank's mobile banking and online service delivery channels
- The accessibility and distribution of retail delivery systems and the range of community development services provided (Correct answer)
- The profitability of the bank's retail service network in LMI census tracts
Correct answer: The accessibility and distribution of retail delivery systems and the range of community development services provided
The service test evaluates how accessible the bank's retail delivery systems (branches, ATMs) are to LMI individuals and areas, as well as the extent and innovativeness of community development services provided.
Question 27: The CRA lending test for large banks primarily evaluates:
- The profitability of loans made in the bank's assessment area
- The total number of loans approved versus denied each calendar year
- Only home mortgage loans made to LMI borrowers in LMI census tracts
- Geographic distribution and borrower characteristics of home mortgage, small business, small farm, and community development loans (Correct answer)
Correct answer: Geographic distribution and borrower characteristics of home mortgage, small business, small farm, and community development loans
The lending test evaluates the full range of a large bank's home mortgage, small business, small farm, and community development lending, examining geographic distribution and the income levels of borrowers served.
Question 28: The Right to Financial Privacy Act (RFPA) restricts federal government agencies from obtaining customer financial records without:
- Board of directors approval
- Regulatory approval from the OCC
- Written authorization from FinCEN
- Customer notice or legal process such as a subpoena (Correct answer)
Correct answer: Customer notice or legal process such as a subpoena
The RFPA requires federal government agencies to either notify the customer or use legal process (e.g., subpoena, court order) before obtaining financial records.
Question 29: A compliance officer reviewing an IFPUG count finds that the counting team included the same data group as both an ILF and an EIF. Which IFPUG rule does this violate?
- An ILF can also be counted as an EIF if referenced by more than one transaction
- The CPM permits dual-counting when regulatory data is involved
- A data group maintained by the application cannot simultaneously be counted as an EIF for the same application (Correct answer)
- EIFs and ILFs may share the same data group if they have different RET structures
Correct answer: A data group maintained by the application cannot simultaneously be counted as an EIF for the same application
IFPUG rules state that if data is maintained by the application being counted, it is an ILF for that application and cannot also be an EIF within the same count.
Question 30: Which federal agency has primary responsibility for administering the Bank Secrecy Act for depository institutions?
- FDIC
- FinCEN (Correct answer)
- OCC
- SEC
Correct answer: FinCEN
The Financial Crimes Enforcement Network (FinCEN), a bureau of the Treasury Department, administers the BSA.
Certified Regulatory Compliance Manager (CRCM)
The CRCM, administered by the American Bankers Association (ABA), validates expertise in bank regulatory compliance across consumer protection regulations, foundational banking rules, and compliance management systems. It is the premier compliance certification for banking professionals.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds