← All CRA Flashcard Decks

Regulatory and Compliance Standards Flashcards

7 cards from real CRA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Regulatory and Compliance Standards flashcards as text
  1. Under the Basel III framework, the Liquidity Coverage Ratio (LCR) requires banks to hold sufficient high-quality liquid assets to cover net cash outflows over what time period?

    Answer: 30 days

    Basel III's LCR requires banks to maintain enough HQLA to survive a 30-day stress scenario of significant liquidity outflows.

  2. Which regulation established the Volcker Rule, which restricts proprietary trading by U.S. banking entities?

    Answer: Dodd-Frank Wall Street Reform Act

    Section 619 of the Dodd-Frank Act contains the Volcker Rule, prohibiting banks from engaging in short-term proprietary trading of securities.

  3. The EU's General Data Protection Regulation (GDPR) imposes a maximum fine for serious violations of up to what percentage of a company's global annual turnover?

    Answer: 4%

    GDPR's highest tier of fines can reach 4% of total global annual turnover or €20 million, whichever is greater.

  4. Which U.S. federal law primarily governs anti-money laundering (AML) obligations for financial institutions by requiring Suspicious Activity Reports (SARs)?

    Answer: Bank Secrecy Act

    The Bank Secrecy Act (BSA) of 1970 established the core AML framework, including requirements to file SARs and Currency Transaction Reports.

  5. Under NIST SP 800-53, which control family specifically addresses personnel security risks such as background screening and employee termination procedures?

    Answer: Personnel Security (PS)

    The PS (Personnel Security) control family covers screening, onboarding, and separation procedures to mitigate insider threats.

  6. Which compliance framework is specifically designed for securing payment card data and is mandatory for any organization that stores, processes, or transmits cardholder data?

    Answer: PCI DSS

    PCI DSS (Payment Card Industry Data Security Standard) is the mandatory standard for protecting cardholder data across all entities in the payment ecosystem.

  7. A risk architect reviewing a bank's capital adequacy under Basel III would use the Capital Conservation Buffer (CCB) as an add-on above the minimum CET1 ratio. What is the size of the CCB?

    Answer: 2.5%

    Basel III requires a Capital Conservation Buffer of 2.5% of risk-weighted assets above the 4.5% CET1 minimum, bringing the effective minimum to 7%.