โ† All CFP Flashcard Decks

Regulatory Compliance & Risk Management Flashcards

7 cards from real CFP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Regulatory Compliance & Risk Management flashcards as text
  1. Under the Bank Secrecy Act (BSA), what is the threshold for filing a Currency Transaction Report (CTR)?

    Answer: $10,000

    Financial institutions must file a CTR for any cash transaction exceeding $10,000.

  2. A fintech lender uses an algorithm that disproportionately denies credit to applicants from certain ZIP codes. This is most likely a violation of which regulation?

    Answer: Equal Credit Opportunity Act (ECOA)

    ECOA prohibits credit discrimination based on race, color, religion, national origin, sex, marital status, or age, including disparate impact via algorithmic proxies like ZIP codes.

  3. Which risk management framework is most commonly used by fintech companies to assess and manage cybersecurity risks?

    Answer: NIST Cybersecurity Framework

    The NIST Cybersecurity Framework provides a policy framework of computer security guidance specifically designed to help organizations manage cybersecurity risk.

  4. What does 'regulatory sandbox' mean in the context of fintech?

    Answer: A controlled environment where startups can test products with relaxed regulations

    A regulatory sandbox allows fintech companies to test innovative products and services under regulator supervision without full regulatory compliance for a defined period.

  5. Under PCI DSS, what is the minimum requirement for storing cardholder Primary Account Numbers (PANs)?

    Answer: They must be rendered unreadable using strong cryptography

    PCI DSS Requirement 3 mandates that stored PANs be rendered unreadable using methods such as hashing, tokenization, or strong encryption.

  6. A money services business (MSB) operating a mobile payment app must register with which US federal body?

    Answer: Financial Crimes Enforcement Network (FinCEN)

    MSBs, including mobile payment providers that qualify, must register with FinCEN under the Bank Secrecy Act.

  7. Which of the following best describes 'model risk' in a fintech context?

    Answer: The risk of adverse consequences from decisions based on incorrect or misused models

    Model risk arises when a financial model produces inaccurate outputs or is used inappropriately, leading to poor business decisions or compliance failures.