← All CFP Flashcard Decks

Regulatory Compliance & Risk Management Flashcards

7 cards from real CFP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Regulatory Compliance & Risk Management flashcards as text
  1. The CFPB's Dodd-Frank Section 1033 rule primarily concerns which fintech activity?

    Answer: Consumer right to access and share their own financial data

    Section 1033 establishes a consumer's right to access their own financial data and share it with third parties like fintech apps.

  2. What is 'regulatory arbitrage' in the fintech industry?

    Answer: Exploiting differences in regulations across jurisdictions to reduce compliance burden

    Regulatory arbitrage occurs when companies structure operations or choose jurisdictions to take advantage of less stringent regulatory requirements.

  3. Under GDPR, a fintech company experiences a data breach. Within how many hours must it notify the supervisory authority?

    Answer: 72 hours

    GDPR Article 33 requires data controllers to notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach.

  4. Which principle of operational risk management requires fintech firms to identify single points of failure in their technology infrastructure?

    Answer: Business Continuity Planning (BCP)

    Business Continuity Planning requires identifying all critical systems and single points of failure to ensure operations can continue during disruptions.

  5. A crypto exchange in the US that facilitates trading of tokens deemed securities must register with which regulator?

    Answer: SEC

    If tokens are classified as securities under the Howey Test, the platforms trading them must register as a national securities exchange or broker-dealer with the SEC.

  6. What is the primary purpose of a 'red team' exercise in fintech cybersecurity risk management?

    Answer: Simulating real-world adversarial attacks to identify vulnerabilities

    A red team exercise involves ethical hackers simulating sophisticated attacks to uncover weaknesses that standard security controls might miss.

  7. Which regulatory requirement mandates that fintech companies verify the identity of their business customers, including beneficial ownership?

    Answer: Customer Due Diligence (CDD) / Know Your Business (KYB)

    FinCEN's CDD Rule requires covered financial institutions to identify and verify beneficial owners who own 25% or more of a legal entity customer.