Swift Risk Assessment & Management 5 ā Questions and Answers
Question 1: Which SWIFT security incident led to major reforms in the Customer Security Programme and mandatory control attestation requirements?
- The Lehman Brothers collapse in 2008
- The Bangladesh Bank heist of 2016 (Correct answer)
- The 2013 Target retail data breach
- The 2010 Greek sovereign debt crisis
Correct answer: The Bangladesh Bank heist of 2016
The 2016 Bangladesh Bank heist, where $81 million was stolen via fraudulent SWIFT messages, directly prompted SWIFT to launch the CSP with mandatory security controls.
Question 2: In risk management, what does 'de-risking' in correspondent banking primarily refer to?
- Hedging currency exposure using derivatives
- Banks exiting high-risk correspondent relationships instead of managing the risk (Correct answer)
- Reducing capital requirements through risk transfer
- Implementing two-factor authentication on payment systems
Correct answer: Banks exiting high-risk correspondent relationships instead of managing the risk
De-risking refers to the practice of banks terminating or restricting correspondent relationships with higher-risk customers or jurisdictions rather than applying risk-based mitigation.
Question 3: Under the SWIFT CSP framework, how frequently must member institutions submit their security attestation?
- Every two years
- Quarterly
- Annually (Correct answer)
- Upon each major system upgrade
Correct answer: Annually
The CSP requires all SWIFT users to self-attest their compliance with mandatory controls on an annual basis through the KYC Security Attestation (KYC-SA) application.
Question 4: A bank processes a payment for a customer that later turns out to be a sanctioned entity not yet on its screening list. Which type of risk has materialized?
- Regulatory/compliance risk (Correct answer)
- Pure market risk
- Strategic risk
- Basis risk
Correct answer: Regulatory/compliance risk
Processing a payment for a sanctioned entity exposes the bank to regulatory penalties, fines, and reputational damageācore manifestations of compliance risk.
Question 5: What is the role of a 'cover payment' (MT 202 COV) in cross-border transactions, and what risk does it create?
- It insures the payment against FX losses; risk is currency mismatch
- It moves funds between correspondent banks to cover an MT 103; risk is reduced AML transparency in the interbank leg (Correct answer)
- It confirms receipt of funds; risk is duplicate settlement
- It converts currency automatically; risk is execution slippage
Correct answer: It moves funds between correspondent banks to cover an MT 103; risk is reduced AML transparency in the interbank leg
The MT 202 COV is the interbank funding message accompanying an MT 103, but historically the cover leg lacked originator details, creating AML transparency gaps now addressed by FATF standards.
Question 6: Which approach to correspondent banking risk management does FATF recommend over wholesale de-risking?
- Immediate account closure for any high-risk jurisdiction
- Risk-based approach with enhanced due diligence for higher-risk relationships (Correct answer)
- Mandatory government guarantees for all correspondent accounts
- Limiting correspondent banking to G20 members only
Correct answer: Risk-based approach with enhanced due diligence for higher-risk relationships
FATF advocates a risk-based approach where banks apply proportionate controlsāincluding enhanced due diligenceārather than exiting all high-risk relationships.
Question 7: A bank implements a daily payment cap on its SWIFT outbound messages. Which category of risk control is this?
- Detective control
- Corrective control
- Preventive control (Correct answer)
- Compensating control
Correct answer: Preventive control
A payment cap prevents excessive or unauthorized transactions from occurring in the first place, making it a preventive control.
Which SWIFT security incident led to major reforms in the Customer Security Programme and mandatory control attestation requirements?