CRA Regulatory and Compliance Standards 2 — Questions and Answers
Question 1: Under the Basel III framework, the Liquidity Coverage Ratio (LCR) requires banks to hold sufficient high-quality liquid assets to cover net cash outflows over what time period?
- 7 days
- 30 days (Correct answer)
- 60 days
- 90 days
Correct answer: 30 days
Basel III's LCR requires banks to maintain enough HQLA to survive a 30-day stress scenario of significant liquidity outflows.
Question 2: Which regulation established the Volcker Rule, which restricts proprietary trading by U.S. banking entities?
- Gramm-Leach-Bliley Act
- Dodd-Frank Wall Street Reform Act (Correct answer)
- Glass-Steagall Act
- Sarbanes-Oxley Act
Correct answer: Dodd-Frank Wall Street Reform Act
Section 619 of the Dodd-Frank Act contains the Volcker Rule, prohibiting banks from engaging in short-term proprietary trading of securities.
Question 3: The EU's General Data Protection Regulation (GDPR) imposes a maximum fine for serious violations of up to what percentage of a company's global annual turnover?
- 2%
- 4% (Correct answer)
- 6%
- 10%
Correct answer: 4%
GDPR's highest tier of fines can reach 4% of total global annual turnover or €20 million, whichever is greater.
Question 4: Which U.S. federal law primarily governs anti-money laundering (AML) obligations for financial institutions by requiring Suspicious Activity Reports (SARs)?
- USA PATRIOT Act
- Bank Secrecy Act (Correct answer)
- Foreign Corrupt Practices Act
- Fair Credit Reporting Act
Correct answer: Bank Secrecy Act
The Bank Secrecy Act (BSA) of 1970 established the core AML framework, including requirements to file SARs and Currency Transaction Reports.
Question 5: Under NIST SP 800-53, which control family specifically addresses personnel security risks such as background screening and employee termination procedures?
- Access Control (AC)
- Personnel Security (PS) (Correct answer)
- Incident Response (IR)
- Awareness and Training (AT)
Correct answer: Personnel Security (PS)
The PS (Personnel Security) control family covers screening, onboarding, and separation procedures to mitigate insider threats.
Question 6: Which compliance framework is specifically designed for securing payment card data and is mandatory for any organization that stores, processes, or transmits cardholder data?
- ISO 27001
- SOC 2 Type II
- PCI DSS (Correct answer)
- HIPAA Security Rule
Correct answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) is the mandatory standard for protecting cardholder data across all entities in the payment ecosystem.
Question 7: A risk architect reviewing a bank's capital adequacy under Basel III would use the Capital Conservation Buffer (CCB) as an add-on above the minimum CET1 ratio. What is the size of the CCB?
- 1.5%
- 2.0%
- 2.5% (Correct answer)
- 3.5%
Correct answer: 2.5%
Basel III requires a Capital Conservation Buffer of 2.5% of risk-weighted assets above the 4.5% CET1 minimum, bringing the effective minimum to 7%.
Under the Basel III framework, the Liquidity Coverage Ratio (LCR) requires banks to hold sufficient high-quality liquid assets to cover net cash outflows over what time period?