Swift Risk Assessment & Management 2 — Questions and Answers
Question 1: Which SWIFT service allows banks to confirm whether a beneficiary account is active and matches the expected name before sending a payment?
- SWIFT gpi
- Pre-validation (Correct answer)
- SWIFT KYC Registry
- Sanctions Screening
Correct answer: Pre-validation
Pre-validation lets sending banks verify account details before initiating a payment, reducing failed transactions and fraud risk.
Question 2: Under the SWIFT Customer Security Programme (CSP), what happens if a member institution fails its mandatory attestation?
- Immediate network disconnection
- Reduced transaction limits only
- Supervisory reporting and possible access restrictions (Correct answer)
- No consequence; attestation is voluntary
Correct answer: Supervisory reporting and possible access restrictions
Non-attesting institutions face supervisory notification and may have access controls applied, though not automatic disconnection.
Question 3: A bank receives an MT 199 free-format message requesting an urgent wire. Which risk is most prominent in this scenario?
- Liquidity risk
- Social engineering / BEC fraud (Correct answer)
- Counterparty credit risk
- Nostro reconciliation risk
Correct answer: Social engineering / BEC fraud
Free-format messages are commonly exploited in business email compromise and social engineering schemes to initiate unauthorized transfers.
Question 4: What is the primary purpose of SWIFT's Mandatory Customer Security Controls (MCSCs)?
- Define messaging standards for cross-border payments
- Establish a baseline of cybersecurity controls all users must implement (Correct answer)
- Set liquidity requirements for correspondent banks
- Govern KYC documentation standards
Correct answer: Establish a baseline of cybersecurity controls all users must implement
MCSCs define the minimum cybersecurity baseline every SWIFT user must implement and attest to annually under the CSP.
Question 5: Which risk category best describes the exposure a bank faces when a correspondent bank in a foreign country fails due to sovereign default?
- Operational risk
- Country/sovereign risk (Correct answer)
- Settlement risk
- Reputational risk
Correct answer: Country/sovereign risk
Country or sovereign risk arises when a foreign government's actions or default impair the ability of counterparties in that jurisdiction to fulfill obligations.
Question 6: In SWIFT messaging, what control helps detect whether an MT 103 payment instruction has been tampered with in transit?
- Message sequencing
- LAU (Local Authentication) (Correct answer)
- RMA (Relationship Management Application)
- Bilateral Key Exchange (BKE)
Correct answer: LAU (Local Authentication)
LAU (Local Authentication) applies a cryptographic signature to outbound messages, allowing the receiver to verify integrity and authenticity.
Question 7: A compliance officer discovers that a counterparty bank has been removed from the SWIFT network. What is the most immediate operational risk?
- All past messages with that bank are invalidated
- In-flight payments may fail to settle, creating pending liabilities (Correct answer)
- The bank's currency becomes non-convertible
- Correspondent accounts are automatically frozen by SWIFT
Correct answer: In-flight payments may fail to settle, creating pending liabilities
When a bank is disconnected, messages in transit may not be delivered, leaving funds in an unresolved state and creating settlement exposure.
Which SWIFT service allows banks to confirm whether a beneficiary account is active and matches the expected name before sending a payment?