AAP Compliance and Audit 2 — Questions and Answers
Question 1: The unauthorized entry return rate threshold (using codes R05, R07, R10, R29, R51) that triggers NACHA scrutiny is:
- 0.5% of debit entries originated (Correct answer)
- 1.0% of debit entries originated
- 3.0% of debit entries originated
- 15.0% of debit entries originated
Correct answer: 0.5% of debit entries originated
The unauthorized return rate threshold is 0.5%—much stricter than the 15% overall threshold—because unauthorized entries indicate serious authorization failures.
Question 2: Regulation E primarily protects:
- Consumers from unauthorized electronic fund transfers (Correct answer)
- Businesses from ACH fraud and unauthorized debits
- ODFIs from Originator liability for unauthorized entries
- ACH Operators from network disruptions caused by fraud
Correct answer: Consumers from unauthorized electronic fund transfers
Regulation E (Electronic Fund Transfer Act) establishes the rights of consumers and the responsibilities of financial institutions regarding unauthorized electronic fund transfers.
Question 3: Under Regulation E, a consumer must report an unauthorized transaction within what timeframe to receive maximum protection?
- 2 business days of learning of the loss or theft of an access device (Correct answer)
- 60 days from the date of the account statement
- 30 calendar days of the transaction date
- Same day the unauthorized transaction is discovered
Correct answer: 2 business days of learning of the loss or theft of an access device
Reporting within 2 business days of learning of a lost or stolen access device limits consumer liability to $50; waiting longer increases potential liability.
Question 4: BSA/AML requirements that apply to ACH transactions include:
- Monitoring for suspicious activity and filing SARs when warranted (Correct answer)
- Filing a CTR for every ACH transaction exceeding $10,000
- Reporting all ACH entries to FinCEN on a daily basis
- Obtaining NACHA approval for all high-value ACH entries
Correct answer: Monitoring for suspicious activity and filing SARs when warranted
Financial institutions must monitor ACH transactions for suspicious activity patterns and file Suspicious Activity Reports (SARs) with FinCEN when warranted under BSA requirements.
Question 5: OFAC compliance in ACH processing requires financial institutions to:
- Screen transactions against the SDN list and block or reject prohibited transactions (Correct answer)
- Report all international ACH transactions to OFAC before processing
- Obtain OFAC pre-approval for every IAT entry originated
- File a SAR with FinCEN for every IAT entry received
Correct answer: Screen transactions against the SDN list and block or reject prohibited transactions
Financial institutions must screen ACH transaction parties against OFAC's Specially Designated Nationals (SDN) list and block or reject any transactions involving prohibited parties.
Question 6: The ACH audit requirement under NACHA rules applies to:
- ODFIs, RDFIs, Third-Party Senders, and Third-Party Processors participating in the ACH network (Correct answer)
- Only ODFIs and RDFIs that are direct NACHA members
- NACHA member financial institutions only, excluding processors
- Federal Reserve member banks exclusively
Correct answer: ODFIs, RDFIs, Third-Party Senders, and Third-Party Processors participating in the ACH network
The annual ACH audit requirement applies broadly to all participants in the ACH network, including ODFIs, RDFIs, Third-Party Senders, and Third-Party Processors.
The unauthorized entry return rate threshold (using codes R05, R07, R10, R29, R51) that triggers NACHA scrutiny is: