Free CBA Regulatory Compliance and AML Questions and Answers 1 — Questions and Answers
Question 1: An auditor reviewing a bank's marketing materials for a new credit card finds the headline "0% APR for One Year!" The disclosure that this rate only applies to balance transfers—and not to new purchases, which accrue interest at 24.99%—is located in a small-font footnote. This practice is most likely a violation of which of the following?
- Bank Secrecy Act (BSA)
- Community Reinvestment Act (CRA)
- Truth in Lending Act (TILA) and Unfair, Deceptive, or Abusive Acts or Practices (UDAAP) (Correct answer)
- Fair Credit Reporting Act (FCRA)
Correct answer: Truth in Lending Act (TILA) and Unfair, Deceptive, or Abusive Acts or Practices (UDAAP)
This is a classic example of a deceptive practice under UDAAP, where a representation is likely to mislead the consumer. The prominent "0% APR" claim is materially misleading because a key limitation (it not applying to new purchases) is obscured. Additionally, TILA (Regulation Z) requires that credit advertising disclosures be clear and conspicuous.
Question 2: A Certified Bank Auditor is assessing the independent testing pillar of a bank's BSA/AML compliance program. Which of the following is the MOST critical area for the auditor to evaluate to ensure the program's foundation is sound?
- The number of full-time employees in the BSA department.
- The adequacy and completeness of the bank's BSA/AML risk assessment. (Correct answer)
- The cost-effectiveness of the transaction monitoring software.
- The completion rate of annual BSA training for tellers.
Correct answer: The adequacy and completeness of the bank's BSA/AML risk assessment.
According to the FFIEC BSA/AML Examination Manual, the independent audit should be risk-based. Therefore, the most critical starting point is to evaluate the bank's own BSA/AML risk assessment. If the risk assessment is flawed or incomplete, the entire compliance program—including internal controls, monitoring, and training—will not be properly aligned to mitigate the bank's actual risks.
Question 3: During an audit, it is discovered that a wire transfer was processed for a customer whose name was a near-match to an individual on the OFAC Specially Designated Nationals (SDN) list. The bank's interdiction software generated an alert, but the operations clerk, citing a minor spelling difference, cleared the alert and processed the payment without further investigation or escalation. This represents a critical failure in which component of the OFAC compliance program?
- Customer Identification Program (CIP) procedures.
- Currency Transaction Reporting (CTR) processes.
- Annual employee training.
- Internal controls for alert review and escalation. (Correct answer)
Correct answer: Internal controls for alert review and escalation.
The software performed its function by generating an alert. The failure occurred when the employee did not follow a proper procedure for investigating and escalating a potential match. An effective OFAC compliance program's internal controls must include clear, enforced procedures for handling alerts to determine if they are false positives or true matches, which was not done here.
Question 4: The primary purpose of the Customer Due Diligence (CDD) rule's requirement to identify and verify the beneficial owners of legal entity customers is to:
- Prevent the use of anonymous shell companies to obscure the identities of individuals engaged in money laundering or terrorist financing. (Correct answer)
- Ensure the legal entity has sufficient capital to maintain a banking relationship.
- Determine the appropriate credit risk rating for the legal entity.
- Fulfill information-sharing requests from other financial institutions under Section 314(b) of the USA PATRIOT Act.
Correct answer: Prevent the use of anonymous shell companies to obscure the identities of individuals engaged in money laundering or terrorist financing.
The FinCEN CDD Final Rule was explicitly designed to enhance financial transparency and combat the misuse of legal entities. By requiring the identification of natural persons who own or control legal entities, the rule aims to make it more difficult for criminals and other illicit actors to hide their identities behind corporate structures.
Question 5: An auditor reviews a customer's account activity and notes a pattern of five separate cash deposits of $9,000 on five consecutive days at different branches. While no Currency Transaction Report (CTR) was triggered, this activity is a significant red flag. The bank's primary regulatory responsibility in this situation is to:
- File a CTR for the aggregated amount of $45,000.
- Immediately close the customer's account.
- Evaluate the activity for suspicion of structuring and file a Suspicious Activity Report (SAR) if deemed necessary. (Correct answer)
- Contact the customer and obtain a written explanation for the transactions.
Correct answer: Evaluate the activity for suspicion of structuring and file a Suspicious Activity Report (SAR) if deemed necessary.
This pattern is a classic example of structuring—designing transactions to evade the CTR filing requirement. While no individual transaction met the >$10,000 threshold for a CTR, the bank is required to file a SAR if it knows, suspects, or has reason to suspect that the transactions were designed to evade BSA requirements.
Question 6: According to the FFIEC, which of the following is one of the five required pillars of a bank's BSA/AML compliance program?
- A board-approved list of high-risk countries.
- The use of automated transaction monitoring software.
- Designation of a qualified BSA Compliance Officer. (Correct answer)
- Quarterly reporting of all cash transactions to the board of directors.
Correct answer: Designation of a qualified BSA Compliance Officer.
The five pillars required by the Bank Secrecy Act for an effective AML program are: (1) a system of internal controls, (2) independent testing, (3) a designated BSA compliance officer, (4) training for appropriate personnel, and (5) customer due diligence (CDD). The designation of a qualified individual to be responsible for the program is a mandatory pillar.
An auditor reviewing a bank's marketing materials for a new credit card finds the headline "0% APR for One Year!" The disclosure that this rate only applies to balance transfers—and not to new purchases, which accrue interest at 24.99%—is located in a small-font footnote.
This practice is most likely a violation of which of the following?