CFP Regulatory Compliance & Risk Management 3 — Questions and Answers
Question 1: The CFPB's Dodd-Frank Section 1033 rule primarily concerns which fintech activity?
- Anti-money laundering reporting for crypto exchanges
- Consumer right to access and share their own financial data (Correct answer)
- Licensing requirements for payment processors
- Stress testing requirements for neobanks
Correct answer: Consumer right to access and share their own financial data
Section 1033 establishes a consumer's right to access their own financial data and share it with third parties like fintech apps.
Question 2: What is 'regulatory arbitrage' in the fintech industry?
- Using technology to automate compliance processes
- Exploiting differences in regulations across jurisdictions to reduce compliance burden (Correct answer)
- Arbitrating disputes with regulators through legal channels
- Investing in underregulated asset classes for higher returns
Correct answer: Exploiting differences in regulations across jurisdictions to reduce compliance burden
Regulatory arbitrage occurs when companies structure operations or choose jurisdictions to take advantage of less stringent regulatory requirements.
Question 3: Under GDPR, a fintech company experiences a data breach. Within how many hours must it notify the supervisory authority?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 requires data controllers to notify the relevant supervisory authority within 72 hours of becoming aware of a personal data breach.
Question 4: Which principle of operational risk management requires fintech firms to identify single points of failure in their technology infrastructure?
- Business Continuity Planning (BCP) (Correct answer)
- Vendor Due Diligence
- Concentration Risk Assessment
- Change Management
Correct answer: Business Continuity Planning (BCP)
Business Continuity Planning requires identifying all critical systems and single points of failure to ensure operations can continue during disruptions.
Question 5: A crypto exchange in the US that facilitates trading of tokens deemed securities must register with which regulator?
- FinCEN
- FDIC
- SEC (Correct answer)
- OCC
Correct answer: SEC
If tokens are classified as securities under the Howey Test, the platforms trading them must register as a national securities exchange or broker-dealer with the SEC.
Question 6: What is the primary purpose of a 'red team' exercise in fintech cybersecurity risk management?
- Training staff on phishing awareness
- Simulating real-world adversarial attacks to identify vulnerabilities (Correct answer)
- Reviewing compliance documentation for gaps
- Monitoring network traffic for anomalies
Correct answer: Simulating real-world adversarial attacks to identify vulnerabilities
A red team exercise involves ethical hackers simulating sophisticated attacks to uncover weaknesses that standard security controls might miss.
Question 7: Which regulatory requirement mandates that fintech companies verify the identity of their business customers, including beneficial ownership?
- Know Your Customer (KYC)
- Customer Due Diligence (CDD) / Know Your Business (KYB) (Correct answer)
- Suspicious Activity Reporting (SAR)
- Anti-Bribery Compliance (ABC)
Correct answer: Customer Due Diligence (CDD) / Know Your Business (KYB)
FinCEN's CDD Rule requires covered financial institutions to identify and verify beneficial owners who own 25% or more of a legal entity customer.
The CFPB's Dodd-Frank Section 1033 rule primarily concerns which fintech activity?