Swift Risk Assessment & Management 3 — Questions and Answers
Question 1: Which SWIFT tool provides real-time tracking of payment status and improves transparency in correspondent banking chains?
- SWIFT Alliance Gateway
- SWIFT gpi Tracker (Correct answer)
- SWIFTRef
- SWIFT Compliance Analytics
Correct answer: SWIFT gpi Tracker
The SWIFT gpi Tracker gives all banks in a payment chain end-to-end visibility of payment status, fees, and FX rates in real time.
Question 2: A bank's risk team identifies that a respondent bank processes high volumes of transactions from jurisdictions on the FATF blacklist. This is an example of which risk?
- Market risk
- Nested correspondent banking risk (Correct answer)
- Interest rate risk
- Currency conversion risk
Correct answer: Nested correspondent banking risk
Nested correspondent banking occurs when a respondent bank processes transactions on behalf of other banks, obscuring the ultimate originator and raising AML risk.
Question 3: Which SWIFT CSP advisory control is considered an advanced practice for detecting anomalous messaging patterns?
- Two-factor authentication on SWIFT terminals
- Payment controls software (anomaly detection) (Correct answer)
- Mandatory firewall segmentation
- Quarterly password rotation
Correct answer: Payment controls software (anomaly detection)
Payment controls software that flags unusual transaction patterns is listed as an advisory (recommended but not mandatory) control in the CSP framework.
Question 4: Under Wolfsberg Correspondent Banking Principles, what due diligence is required before establishing a new correspondent relationship?
- Only name screening against sanctions lists
- Comprehensive KYC/AML due diligence on the respondent bank (Correct answer)
- Approval from the local central bank only
- A SWIFT audit of the respondent's messaging infrastructure
Correct answer: Comprehensive KYC/AML due diligence on the respondent bank
The Wolfsberg Principles require thorough KYC/AML due diligence covering ownership, business model, AML controls, and jurisdiction risk before opening accounts.
Question 5: What does the SWIFT Compliance Analytics tool (formerly called Transaction Pattern Analysis) primarily help institutions do?
- Detect and report cybersecurity breaches in real time
- Benchmark their transaction patterns against peers to identify anomalies (Correct answer)
- Automate SEPA payment routing
- Calculate capital requirements under Basel III
Correct answer: Benchmark their transaction patterns against peers to identify anomalies
SWIFT Compliance Analytics lets banks compare their traffic patterns against community norms to spot suspicious flows that may indicate AML risk.
Question 6: A fraudster gains access to an operator's SWIFT credentials and sends unauthorized MT 202 COV messages. Which control layer would most directly prevent message transmission?
- IP whitelisting of back-office systems
- Four-eyes principle (dual authorization) on payment release (Correct answer)
- Monthly credential rotation policy
- Network-level TLS encryption
Correct answer: Four-eyes principle (dual authorization) on payment release
A dual-authorization (four-eyes) requirement means no single operator can release a payment alone, directly blocking unauthorized single-person transmission.
Question 7: Which settlement risk concept describes the danger that one party delivers assets but the counterparty defaults before delivering its side in a foreign exchange transaction?
- Replacement cost risk
- Herstatt risk (principal risk) (Correct answer)
- Liquidity gap risk
- Roll-over risk
Correct answer: Herstatt risk (principal risk)
Herstatt risk (principal risk) occurs in FX when one leg of the trade is settled but the counterparty fails before completing the other, named after Bankhaus Herstatt's 1974 collapse.
Which SWIFT tool provides real-time tracking of payment status and improves transparency in correspondent banking chains?