โ† All CFP Flashcard Decks

Regulatory Compliance & Standards Flashcards

7 cards from real CFP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Regulatory Compliance & Standards flashcards as text
  1. Which GDPR principle requires that personal data be kept in a form that allows identification of data subjects for no longer than necessary?

    Answer: Storage limitation

    The storage limitation principle under GDPR Article 5(1)(e) restricts retention of identifiable personal data beyond the period necessary for its purpose.

  2. What is the primary purpose of a Suspicious Activity Report (SAR) filed by a fintech company?

    Answer: Alert FinCEN to potential money laundering or fraud

    SARs are filed with FinCEN to report transactions that may involve money laundering, fraud, or other financial crimes.

  3. Under the Dodd-Frank Act, which threshold determines whether a swap dealer must register with the CFTC?

    Answer: $8 billion in aggregate notional swap positions

    The CFTC set the de minimis threshold at $8 billion in aggregate notional amount of swaps over a 12-month period for swap dealer registration.

  4. A fintech operating in California must comply with the CCPA, which grants consumers the right to:

    Answer: Opt out of the sale of their personal information

    The CCPA gives California residents the right to opt out of the sale of their personal information to third parties.

  5. Which international standard provides a framework for information security management systems (ISMS) commonly used by fintech firms?

    Answer: ISO 27001

    ISO 27001 is the international standard that specifies requirements for establishing, implementing, and maintaining an ISMS.

  6. Under the Electronic Fund Transfer Act (EFTA), what is the maximum liability for a consumer who reports an unauthorized debit card transaction within 60 days of the statement date?

    Answer: $500

    Under EFTA, consumers who report unauthorized EFT transactions after 2 business days but within 60 days face a maximum liability of $500.

  7. Which regulation requires US broker-dealers to maintain records of all communications related to their business for at least three years?

    Answer: SEC Rule 17a-4

    SEC Rule 17a-4 mandates that broker-dealers retain business-related records, including electronic communications, for at least three years.