← All CRA Flashcard Decks

Regulatory and Compliance Standards Flashcards

7 cards from real CRA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Regulatory and Compliance Standards flashcards as text
  1. The NIST Risk Management Framework (RMF) Step 3 requires organizations to select security controls. Which NIST publication provides the catalog of controls used in this step?

    Answer: NIST SP 800-53

    NIST SP 800-53 provides the comprehensive catalog of security and privacy controls that organizations select from during RMF Step 3.

  2. Under the Consumer Financial Protection Bureau's (CFPB) UDAAP standards, what does the second 'A' in UDAAP stand for?

    Answer: Abusive

    UDAAP stands for Unfair, Deceptive, or Abusive Acts or Practices, with 'abusive' being a standard added by the Dodd-Frank Act beyond the older FTC UDAP framework.

  3. When conducting a compliance risk assessment, which scenario best illustrates 'inherent risk' as opposed to 'residual risk'?

    Answer: The risk level before any controls or mitigating factors are considered

    Inherent risk is the raw exposure to a compliance violation before any controls, policies, or mitigating activities are factored in.

  4. Which U.S. regulation specifically requires broker-dealers to maintain a minimum net capital ratio and restricts the use of customer funds for proprietary activities?

    Answer: SEC Rule 15c3-1 (Net Capital Rule)

    SEC Rule 15c3-1 establishes minimum net capital requirements for broker-dealers to ensure they have sufficient liquid assets to meet obligations to customers.

  5. A bank's compliance officer discovers that a third-party vendor processing customer data has experienced a breach. Under GLBA notification requirements, which party must notify affected customers?

    Answer: The bank notifies affected customers, not the vendor

    GLBA holds the financial institution responsible for safeguarding customer information, so the bank—not its vendor—must notify affected customers of a breach.

  6. Which international anti-money laundering standard-setting body issues the 40 Recommendations that form the global benchmark for AML/CFT compliance frameworks?

    Answer: Financial Action Task Force (FATF)

    FATF's 40 Recommendations are the internationally recognized framework for combating money laundering, terrorist financing, and proliferation financing.

  7. Under the SEC's Regulation S-P, financial firms must provide customers with a clear and conspicuous notice of their privacy policies. When must the initial privacy notice be delivered?

    Answer: At the time of establishing a customer relationship

    Regulation S-P requires firms to provide an initial privacy notice at the time of establishing a customer relationship, not after the fact.