CRB Risk Management & Fraud Prevention 2 — Questions and Answers
Question 1: A customer reports that someone made several small test charges on their debit card before a large unauthorized purchase. This pattern is known as:
- Skimming
- Account takeover
- Card testing fraud (Correct answer)
- Synthetic identity fraud
Correct answer: Card testing fraud
Card testing fraud involves making small transactions to verify a stolen card is active before committing larger fraudulent purchases.
Question 2: Under the Bank Secrecy Act, financial institutions must file a Currency Transaction Report (CTR) when a customer conducts cash transactions totaling more than:
- $5,000 in a single day
- $10,000 in a single day (Correct answer)
- $25,000 in a single day
- $50,000 in a single day
Correct answer: $10,000 in a single day
CTRs must be filed for cash transactions exceeding $10,000 in a single business day, whether in one or multiple transactions.
Question 3: Which risk management framework component involves identifying potential losses before they occur and assigning probability ratings?
- Risk mitigation
- Risk appetite statement
- Risk assessment (Correct answer)
- Risk transfer
Correct answer: Risk assessment
Risk assessment is the process of identifying, analyzing, and evaluating potential risks and their likelihood of occurrence.
Question 4: A retail banker notices a longtime customer suddenly requesting large wire transfers to overseas accounts. The BEST first step is to:
- Immediately file a SAR without speaking to the customer
- Refuse the transaction outright
- Ask the customer questions to understand the purpose of the transfers (Correct answer)
- Alert local law enforcement
Correct answer: Ask the customer questions to understand the purpose of the transfers
Bankers should gather additional information through customer due diligence before escalating, as there may be a legitimate explanation.
Question 5: The concept of 'tipping off' in AML compliance refers to:
- Notifying regulators of a suspicious transaction
- Informing a customer that a SAR has been or may be filed about them (Correct answer)
- Sharing SAR data with correspondent banks
- Reporting internal control weaknesses to management
Correct answer: Informing a customer that a SAR has been or may be filed about them
Tipping off is illegal under the BSA and occurs when a bank employee alerts a customer that their activity has triggered a SAR filing.
Question 6: Which type of operational risk event involves a bank employee deliberately circumventing internal controls for personal gain?
- External fraud
- Internal fraud (Correct answer)
- Business disruption
- Execution error
Correct answer: Internal fraud
Internal fraud involves intentional acts by bank employees to defraud or circumvent controls, such as embezzlement or unauthorized account access.
Question 7: Regulation E primarily protects consumers by governing:
- Mortgage loan disclosures
- Electronic fund transfers and debit card liability limits (Correct answer)
- Credit card interest rate caps
- Overdraft fee limits on checking accounts
Correct answer: Electronic fund transfers and debit card liability limits
Regulation E establishes the rights and liabilities of consumers and financial institutions for electronic fund transfers, including error resolution procedures.
A customer reports that someone made several small test charges on their debit card before a large unauthorized purchase.
This pattern is known as: