Swift Regulatory Frameworks & Compliance 5 — Questions and Answers
Question 1: What was the primary compliance lesson from the 2016 Bangladesh Bank SWIFT heist?
- SWIFT's central servers were compromised
- Weak internal controls at member institutions, not the SWIFT network itself, enabled fraudulent messages to be sent (Correct answer)
- ISO 20022 migration was delayed
- Correspondent banking should be eliminated
Correct answer: Weak internal controls at member institutions, not the SWIFT network itself, enabled fraudulent messages to be sent
Attackers compromised Bangladesh Bank's local SWIFT environment and submitted fraudulent MT 103 messages, exposing gaps in endpoint security and internal controls.
Question 2: How does PSD2 (EU Payment Services Directive 2) affect SWIFT-connected banks operating in Europe?
- PSD2 prohibits SWIFT use for retail payments
- PSD2 introduces open banking obligations and strong customer authentication requirements that overlay existing SWIFT compliance frameworks (Correct answer)
- PSD2 applies only to cryptocurrency transactions
- PSD2 replaces SWIFT with a government-run EU payment network
Correct answer: PSD2 introduces open banking obligations and strong customer authentication requirements that overlay existing SWIFT compliance frameworks
PSD2 mandates strong customer authentication and open APIs, which must be reconciled with existing SWIFT-based payment processes and compliance controls.
Question 3: What is 'nested correspondent banking' and why is it a compliance concern?
- Using two SWIFT messages instead of one
- When a respondent bank allows its own downstream clients to access the correspondent's services indirectly, obscuring transaction originators (Correct answer)
- Encrypting SWIFT messages at multiple layers
- When a bank has correspondent relationships in more than ten countries
Correct answer: When a respondent bank allows its own downstream clients to access the correspondent's services indirectly, obscuring transaction originators
Nested correspondent banking creates layers that make it difficult for the upstream correspondent to identify who is actually initiating transactions.
Question 4: Which provision of the USA PATRIOT Act specifically addresses due diligence requirements for US banks maintaining correspondent accounts for foreign institutions?
- Section 311
- Section 312 (Correct answer)
- Section 314
- Section 326
Correct answer: Section 312
Section 312 of the USA PATRIOT Act requires US banks to establish due diligence programs for foreign correspondent accounts, with enhanced due diligence for high-risk jurisdictions.
Question 5: What is the function of a SWIFT Relationship Management Application (RMA) from a security and compliance perspective?
- It manages customer KYC documents
- It controls which counterparties a SWIFT user authorizes to send them messages, preventing unauthorized message receipt (Correct answer)
- It processes SWIFT payment instructions automatically
- It calculates SWIFT membership fees
Correct answer: It controls which counterparties a SWIFT user authorizes to send them messages, preventing unauthorized message receipt
RMA ensures a bank only receives messages from counterparties it has explicitly authorized, reducing the risk of receiving fraudulent or unsolicited SWIFT messages.
Question 6: When assessing sanctions risk in cross-border SWIFT payments, which screening approach is considered best practice by OFAC?
- Screen only the direct counterparty bank
- Screen all parties referenced in the payment message including intermediaries, originator, and beneficiary against all applicable sanctions lists (Correct answer)
- Screen only payments above $10,000
- Screen only outbound payments
Correct answer: Screen all parties referenced in the payment message including intermediaries, originator, and beneficiary against all applicable sanctions lists
OFAC expects a risk-based approach that screens all parties in the payment chain against relevant sanctions lists, not just the direct counterparty.
Question 7: What does SWIFT's 'closed user group' feature enable from a regulatory standpoint?
- It allows banks to send unencrypted messages
- It permits regulators or groups of institutions to create restricted messaging environments with defined membership and rules (Correct answer)
- It eliminates the need for BIC codes
- It bypasses standard SWIFT fee structures
Correct answer: It permits regulators or groups of institutions to create restricted messaging environments with defined membership and rules
Closed user groups allow specific communities, such as regulated market infrastructures, to exchange messages within a controlled, defined membership boundary on the SWIFT network.
What was the primary compliance lesson from the 2016 Bangladesh Bank SWIFT heist?