CORES Regulatory Compliance & Industry Standards 4 — Questions and Answers
Question 1: A financial institution's BSA/AML compliance program must include all of the following EXCEPT:
- A designated BSA compliance officer
- Independent testing of the AML program
- Ongoing employee training
- Real-time transaction monitoring for all accounts (Correct answer)
Correct answer: Real-time transaction monitoring for all accounts
The five pillars of a BSA/AML program do not require real-time monitoring for all accounts; risk-based monitoring is the standard.
Question 2: Under the Federal Reserve's SR 11-7 guidance, model risk management requires that models be subject to:
- Annual regulatory approval before use
- Independent validation covering conceptual soundness, data quality, and ongoing monitoring (Correct answer)
- Replacement every three years regardless of performance
- Approval by the model's primary business users
Correct answer: Independent validation covering conceptual soundness, data quality, and ongoing monitoring
SR 11-7 requires independent model validation covering conceptual soundness, data integrity, and ongoing performance monitoring.
Question 3: Which regulation requires U.S. broker-dealers to implement a Business Continuity Plan (BCP) and update it annually?
- SEC Rule 17a-4
- FINRA Rule 4370 (Correct answer)
- CFTC Regulation 1.31
- SEC Regulation SCI
Correct answer: FINRA Rule 4370
FINRA Rule 4370 requires broker-dealers to create and maintain a written BCP and provide summary disclosure to customers.
Question 4: The FFIEC Cybersecurity Assessment Tool (CAT) maps to which two frameworks?
- ISO 27001 and COBIT
- NIST Cybersecurity Framework and FFIEC IT Examination Handbook (Correct answer)
- PCI DSS and SOC 2
- Basel III and COSO ERM
Correct answer: NIST Cybersecurity Framework and FFIEC IT Examination Handbook
The FFIEC CAT aligns with the NIST Cybersecurity Framework and the FFIEC IT Examination Handbook to assess cyber maturity.
Question 5: Under GDPR, which role is responsible for ensuring that personal data processing activities comply with data protection law within an organization?
- Chief Information Security Officer (CISO)
- Data Protection Officer (DPO) (Correct answer)
- Chief Compliance Officer (CCO)
- Chief Risk Officer (CRO)
Correct answer: Data Protection Officer (DPO)
The Data Protection Officer (DPO) is the designated role under GDPR responsible for advising on compliance and acting as a contact for supervisory authorities.
Question 6: A firm conducting business in multiple U.S. states discovers that state money transmission laws conflict with its operational procedures. The BEST compliance strategy is to:
- Apply the most restrictive state's requirements uniformly across all states
- Apply the least restrictive standard to minimize operational burden
- Conduct a state-by-state licensing and compliance analysis and implement controls accordingly (Correct answer)
- Rely solely on federal MSB registration as a substitute for state licensure
Correct answer: Conduct a state-by-state licensing and compliance analysis and implement controls accordingly
State money transmission laws vary significantly; a state-by-state analysis and jurisdiction-specific controls is the only compliant approach.
Question 7: The 'concentration risk' provisions under Basel regulatory standards are PRIMARILY concerned with:
- Excessive credit exposure to a single counterparty or sector (Correct answer)
- Geographic diversification of branch networks
- Over-reliance on a single source of operational risk data
- Concentration of compliance staff in a single department
Correct answer: Excessive credit exposure to a single counterparty or sector
Concentration risk under Basel addresses excessive exposures to a single borrower, sector, or geography that could cause significant losses.
A financial institution's BSA/AML compliance program must include all of the following EXCEPT: