CFP Regulatory Compliance & Risk Management 2 — Questions and Answers
Question 1: Under the Bank Secrecy Act (BSA), what is the threshold for filing a Currency Transaction Report (CTR)?
- $5,000
- $10,000 (Correct answer)
- $25,000
- $50,000
Correct answer: $10,000
Financial institutions must file a CTR for any cash transaction exceeding $10,000.
Question 2: A fintech lender uses an algorithm that disproportionately denies credit to applicants from certain ZIP codes. This is most likely a violation of which regulation?
- Truth in Lending Act (TILA)
- Equal Credit Opportunity Act (ECOA) (Correct answer)
- Electronic Fund Transfer Act (EFTA)
- Gramm-Leach-Bliley Act (GLBA)
Correct answer: Equal Credit Opportunity Act (ECOA)
ECOA prohibits credit discrimination based on race, color, religion, national origin, sex, marital status, or age, including disparate impact via algorithmic proxies like ZIP codes.
Question 3: Which risk management framework is most commonly used by fintech companies to assess and manage cybersecurity risks?
- COSO ERM
- NIST Cybersecurity Framework (Correct answer)
- ISO 9001
- COBIT 5
Correct answer: NIST Cybersecurity Framework
The NIST Cybersecurity Framework provides a policy framework of computer security guidance specifically designed to help organizations manage cybersecurity risk.
Question 4: What does 'regulatory sandbox' mean in the context of fintech?
- A secure testing environment for software code
- A controlled environment where startups can test products with relaxed regulations (Correct answer)
- A compliance checklist provided by regulators
- A database of all applicable fintech regulations
Correct answer: A controlled environment where startups can test products with relaxed regulations
A regulatory sandbox allows fintech companies to test innovative products and services under regulator supervision without full regulatory compliance for a defined period.
Question 5: Under PCI DSS, what is the minimum requirement for storing cardholder Primary Account Numbers (PANs)?
- They must be stored in plaintext for audit purposes
- They must be rendered unreadable using strong cryptography (Correct answer)
- They can be stored in any format if access is restricted
- They must be deleted within 30 days of transaction completion
Correct answer: They must be rendered unreadable using strong cryptography
PCI DSS Requirement 3 mandates that stored PANs be rendered unreadable using methods such as hashing, tokenization, or strong encryption.
Question 6: A money services business (MSB) operating a mobile payment app must register with which US federal body?
- Securities and Exchange Commission (SEC)
- Office of the Comptroller of the Currency (OCC)
- Financial Crimes Enforcement Network (FinCEN) (Correct answer)
- Consumer Financial Protection Bureau (CFPB)
Correct answer: Financial Crimes Enforcement Network (FinCEN)
MSBs, including mobile payment providers that qualify, must register with FinCEN under the Bank Secrecy Act.
Question 7: Which of the following best describes 'model risk' in a fintech context?
- The risk that a software model crashes due to hardware failure
- The risk of adverse consequences from decisions based on incorrect or misused models (Correct answer)
- The risk that a competitor launches a better product
- The risk of regulatory non-compliance due to outdated technology
Correct answer: The risk of adverse consequences from decisions based on incorrect or misused models
Model risk arises when a financial model produces inaccurate outputs or is used inappropriately, leading to poor business decisions or compliance failures.
Under the Bank Secrecy Act (BSA), what is the threshold for filing a Currency Transaction Report (CTR)?