Regulatory Compliance & Risk Management Flashcards
7 cards from real CFP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Regulatory Compliance & Risk Management flashcards as text
Under the Electronic Fund Transfer Act (EFTA) and Regulation E, what is a consumer's maximum liability for unauthorized transactions if reported within 2 business days?
Answer: $50
Regulation E limits consumer liability to $50 for unauthorized EFTs if the consumer notifies the financial institution within 2 business days of learning of the loss.
Which of the following is a key component of an effective AML compliance program under FinCEN requirements?
Answer: Designated compliance officer and independent testing
FinCEN's four pillars of AML compliance include internal policies, a designated compliance officer, employee training, and independent testing/auditing.
What risk does a fintech company face when its third-party cloud provider experiences a prolonged outage?
Answer: Third-party/vendor concentration risk
Over-reliance on a single cloud provider creates vendor concentration risk, where a single point of failure can disrupt the entire fintech operation.
The OCC's 'true lender' doctrine in fintech partnerships primarily determines which party?
Answer: Which party bears the compliance obligations for the loan
The true lender doctrine determines which entity—the bank or the fintech partner—is the actual lender and therefore responsible for compliance with applicable lending laws.
A fintech company's risk appetite statement should primarily align with which of the following?
Answer: Its overall business strategy and board-approved risk tolerance
A risk appetite statement must reflect the company's strategic objectives and the level of risk the board is willing to accept in pursuit of those objectives.
Which US law requires fintech companies handling consumer financial data to implement safeguards and provide privacy notices?
Answer: Gramm-Leach-Bliley Act (GLBA)
GLBA requires financial institutions to explain their information-sharing practices and protect sensitive consumer data through a written information security program.
In the context of DORA (Digital Operational Resilience Act) for EU-regulated fintechs, what is an ITRE?
Answer: ICT-related Incident Threshold and Reporting Event
Under DORA, ITRE refers to significant ICT-related incidents that trigger mandatory reporting obligations to competent authorities.