Emerging Payment Risks Flashcards
7 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Emerging Payment Risks flashcards as text
Which emerging risk does 'ghost broking' represent in embedded insurance products bundled with payment cards?
Answer: Fraudulent intermediaries sell fake insurance policies funded by cardholder interchange
Ghost broking involves fraudulent intermediaries who collect premiums for insurance policies that are either fake or quickly cancelled after issuance, leaving victims uninsured.
In the context of AI-driven payment fraud detection, what is 'model drift' and why is it a risk?
Answer: Gradual degradation of model accuracy as fraudster behavior evolves away from training data patterns
Model drift occurs when fraud patterns in production diverge from the patterns the model was trained on, reducing detection accuracy as fraudsters adapt their tactics.
A gig economy platform processes instant earnings disbursements to workers via debit card push-to-card. Which risk framework most directly applies to this activity?
Answer: Mastercard Send and Visa Direct program rules governing push-to-card disbursements
Push-to-card disbursements via Visa Direct or Mastercard Send are governed by those networks' specific program rules, which set requirements for eligible card types, transaction limits, and originator obligations.
What is the primary compliance risk when a payment facilitator (PayFac) onboards sub-merchants without adequate underwriting?
Answer: The PayFac assumes liability for sub-merchant fraud and chargeback losses exceeding thresholds
PayFacs are contractually liable to their acquirer for all fraud, chargebacks, and compliance violations of their sub-merchants, making inadequate onboarding underwriting a direct financial and regulatory risk.
Which risk does 'SIM swapping' pose to multi-factor authentication used in mobile payment authorization?
Answer: Attackers gain control of the victim's phone number, intercepting SMS-based OTPs to authorize payments
SIM swapping transfers a victim's phone number to an attacker-controlled SIM, allowing interception of SMS one-time passwords used as a second authentication factor for payment apps.
An international remittance provider uses cryptocurrency rails to avoid correspondent banking fees. What is the primary OFAC compliance challenge?
Answer: Screening wallet addresses against OFAC's SDN list when blockchain addresses are pseudonymous and change frequently
OFAC requires screening against its SDN list, but blockchain's pseudonymous wallet addresses can obscure sanctioned parties, and wallet addresses used by sanctioned entities may not be published promptly.
What operational risk does 'banking-as-a-service' (BaaS) model concentration represent for fintechs?
Answer: Reliance on a single sponsor bank whose regulatory enforcement action could immediately halt all fintech operations
Fintechs using BaaS depend entirely on their sponsor bank's charter and regulatory standing; consent orders, license revocations, or bank failures directly interrupt the fintech's payment operations.