Swift Regulatory Frameworks & Compliance 2 — Questions and Answers
Question 1: Which international body oversees SWIFT's compliance with global financial messaging standards?
- The Financial Action Task Force (FATF) (Correct answer)
- The Bank for International Settlements (BIS)
- The International Monetary Fund (IMF)
- The World Bank
Correct answer: The Financial Action Task Force (FATF)
FATF sets the global standards for anti-money laundering and counter-terrorist financing that SWIFT members must follow.
Question 2: What is the primary purpose of SWIFT's Customer Security Programme (CSP)?
- To expand SWIFT's market share
- To enforce baseline security controls on member institutions (Correct answer)
- To replace national banking regulations
- To standardize SWIFT message fees
Correct answer: To enforce baseline security controls on member institutions
The CSP mandates that all SWIFT users implement a set of mandatory and advisory security controls to protect the global financial network.
Question 3: Under the EU's DORA regulation, how does SWIFT network connectivity affect a financial institution's obligations?
- SWIFT use exempts firms from DORA
- Firms must include SWIFT connectivity in their ICT risk management frameworks (Correct answer)
- DORA applies only to payment processors, not SWIFT users
- SWIFT itself bears all DORA compliance obligations
Correct answer: Firms must include SWIFT connectivity in their ICT risk management frameworks
DORA requires EU financial entities to manage ICT risks holistically, which includes third-party services like SWIFT connectivity.
Question 4: What does a SWIFT BIC (Business Identifier Code) uniquely identify?
- An individual bank customer
- A specific financial institution and its location (Correct answer)
- A single SWIFT transaction
- A country's central bank only
Correct answer: A specific financial institution and its location
A BIC identifies a specific financial institution, its country, location, and optionally its branch.
Question 5: Which regulation requires US banks to screen SWIFT payment messages against OFAC's SDN list?
- Bank Secrecy Act (BSA)
- Office of Foreign Assets Control (OFAC) regulations under IEEPA/TWEA (Correct answer)
- Dodd-Frank Act
- Gramm-Leach-Bliley Act
Correct answer: Office of Foreign Assets Control (OFAC) regulations under IEEPA/TWEA
OFAC regulations require US persons and financial institutions to block or reject transactions involving sanctioned parties listed on the SDN list.
Question 6: What is the SWIFT CSCF (Customer Security Controls Framework)?
- A framework for SWIFT fee calculation
- The technical and operational security baseline that all SWIFT users must self-attest to annually (Correct answer)
- A customer onboarding checklist
- A framework for resolving SWIFT message disputes
Correct answer: The technical and operational security baseline that all SWIFT users must self-attest to annually
The CSCF defines mandatory and advisory security controls and requires annual self-attestation by all SWIFT network participants.
Question 7: Under the Wolfsberg Group principles, which due diligence standard applies when a correspondent bank cannot adequately assess the AML risks of its respondent bank?
- Enhanced Due Diligence (EDD) (Correct answer)
- Simplified Due Diligence (SDD)
- Periodic Review
- Transaction Monitoring only
Correct answer: Enhanced Due Diligence (EDD)
Enhanced Due Diligence is required when standard KYB measures are insufficient to assess risks posed by a respondent bank relationship.
Which international body oversees SWIFT's compliance with global financial messaging standards?