APRP Regulatory Compliance 3 — Questions and Answers
Question 1: Under the NACHA Operating Rules, what is the maximum return rate threshold for unauthorized debit entries (Return Code R10) before NACHA may investigate an originator?
- 0.5% (Correct answer)
- 1.0%
- 2.0%
- 3.0%
Correct answer: 0.5%
NACHA's unauthorized return rate threshold is 0.5%; exceeding it triggers monitoring and potential suspension of the originator.
Question 2: The EU's revised Payment Services Directive (PSD2) introduced which major security requirement for electronic payments?
- Single-factor authentication for all transactions
- Strong Customer Authentication (SCA) (Correct answer)
- Mandatory use of EMV chip technology
- Prohibition of card-not-present transactions
Correct answer: Strong Customer Authentication (SCA)
PSD2 mandated Strong Customer Authentication requiring at least two of three factors: knowledge, possession, and inherence.
Question 3: Which compliance concept requires a payments company to verify that a third-party processor complies with applicable rules before onboarding them?
- Subprocessor indemnification
- Third-party due diligence (Correct answer)
- Downstream monitoring
- Correspondent banking review
Correct answer: Third-party due diligence
Third-party due diligence requires assessing a vendor's or partner's compliance posture before entering into a business relationship.
Question 4: What is 'structuring' in the context of BSA/AML compliance?
- Organizing transactions by merchant category code
- Breaking up large transactions to evade CTR reporting thresholds (Correct answer)
- Creating tiered KYC requirements by risk level
- Segmenting customer portfolios by transaction volume
Correct answer: Breaking up large transactions to evade CTR reporting thresholds
Structuring (also known as 'smurfing') is the illegal practice of breaking transactions into smaller amounts to avoid BSA reporting thresholds.
Question 5: Under Regulation E, within how many business days must a financial institution provisionally credit a consumer's account after receiving notice of an unauthorized EFT error?
- 3 business days
- 5 business days
- 10 business days (Correct answer)
- 20 business days
Correct answer: 10 business days
Under Reg E, if an institution cannot complete its investigation within 10 business days, it must provisionally credit the consumer's account.
Question 6: Which organization publishes the Payment Card Industry Data Security Standard (PCI DSS)?
- Federal Reserve
- PCI Security Standards Council (Correct answer)
- NACHA
- FFIEC
Correct answer: PCI Security Standards Council
The PCI Security Standards Council, founded by the major card brands, publishes and maintains PCI DSS.
Question 7: A payment processor knowingly facilitates transactions for an OFAC-sanctioned entity. Under U.S. law, what is the nature of this liability?
- Civil liability only, capped at transaction value
- Strict liability, regardless of knowledge (Correct answer)
- Criminal liability only if intent is proven beyond reasonable doubt
- No liability if the processor relied on customer representations
Correct answer: Strict liability, regardless of knowledge
OFAC sanctions violations are strict liability offenses, meaning knowledge or intent is not required for civil penalties to apply.
Under the NACHA Operating Rules, what is the maximum return rate threshold for unauthorized debit entries (Return Code R10) before NACHA may investigate an originator?