Swift Professional Standards & Competencies 5 — Questions and Answers
Question 1: What distinguishes an MT 202 from an MT 202 COV in the Swift messaging standard?
- MT 202 COV is used for higher-value transactions above $1 million
- MT 202 COV includes underlying customer credit transfer details for cover payment transparency (Correct answer)
- MT 202 COV requires dual authorization while MT 202 requires single authorization
- MT 202 COV is encrypted end-to-end while MT 202 uses standard Swift encryption
Correct answer: MT 202 COV includes underlying customer credit transfer details for cover payment transparency
MT 202 COV was introduced to carry information about the underlying customer payment (MT 103) it covers, improving transparency for correspondent banks.
Question 2: A Swift professional working in correspondent banking is asked to maintain records of all Swift messages. What is the minimum retention period per Swift Operating Rules?
- 1 year
- 3 years
- 5 years (Correct answer)
- 10 years
Correct answer: 5 years
Swift Operating Rules require members to retain message records for a minimum of 5 years, though local regulations may require longer periods.
Question 3: When a Swift user's infrastructure is compromised in a cyber attack, what is the first mandatory action per Swift's CSP incident response requirements?
- Restore all systems from backup before notifying anyone
- Notify Swift immediately and isolate affected systems (Correct answer)
- Issue a press release within 24 hours describing the breach
- Wait for a full internal investigation before reporting externally
Correct answer: Notify Swift immediately and isolate affected systems
CSP requires immediate notification to Swift upon discovering a cyber incident involving Swift infrastructure, along with isolating affected components.
Question 4: Which statement best describes the professional standard for handling a customer's request to conduct a 'wash trade' through Swift-connected accounts?
- Process it if the customer provides written authorization
- Refuse, as wash trading is a form of market manipulation that professionals must not facilitate (Correct answer)
- Process it only if the amounts are below regulatory reporting thresholds
- Seek a second opinion before deciding whether to comply
Correct answer: Refuse, as wash trading is a form of market manipulation that professionals must not facilitate
Wash trading is illegal market manipulation; professional standards and legal obligations require refusal regardless of customer instructions or transaction size.
Question 5: In Swift's gpi (Global Payments Innovation) service, what does the unique end-to-end transaction reference (UETR) enable?
- Automatic currency conversion at the best available rate
- Real-time tracking of a payment's status across all correspondent banks in the chain (Correct answer)
- Priority routing of high-value transactions through the Swift network
- Automated reconciliation between MT and ISO 20022 message formats
Correct answer: Real-time tracking of a payment's status across all correspondent banks in the chain
The UETR is a unique identifier assigned at payment initiation that allows all banks in the payment chain to track and report the payment's progress in real time via gpi.
Question 6: A junior colleague asks you to approve their access to Swift messaging systems while their own credentials are being reset. What is the correct professional response?
- Approve temporary shared access as a courtesy while credentials are restored
- Deny access and direct them to follow the formal access restoration process (Correct answer)
- Allow view-only access until their credentials are restored
- Escalate to IT and allow access pending their response
Correct answer: Deny access and direct them to follow the formal access restoration process
Sharing credentials or granting unauthorized access violates CSP mandatory controls and individual accountability principles; formal access processes must be followed.
Question 7: What is the professional obligation of a Swift practitioner who identifies a potential gap between their institution's implemented controls and the current CSCF version?
- Wait until the next annual self-attestation cycle to address the gap
- Immediately document the gap, assess the risk, and initiate a remediation plan (Correct answer)
- Report the gap externally to regulators before addressing it internally
- Classify it as low risk if no incidents have occurred and take no action
Correct answer: Immediately document the gap, assess the risk, and initiate a remediation plan
Professional competency requires proactive identification and remediation of control gaps, including documentation and risk assessment, not deferral to annual cycles.
What distinguishes an MT 202 from an MT 202 COV in the Swift messaging standard?