APRP Quality & Compliance Flashcards
7 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 APRP Quality & Compliance flashcards as text
What is the key difference between 'first-party fraud' and 'third-party fraud' in payments?
Answer: First-party fraud is committed by the account holder themselves; third-party fraud is committed by an external criminal
First-party fraud is perpetrated by the legitimate account holder (e.g., bust-out, friendly fraud), while third-party fraud involves an external actor using stolen credentials.
Under NACHA Operating Rules, an Originating Depository Financial Institution (ODFI) that originates ACH entries bears primary responsibility for:
Answer: Ensuring originators comply with NACHA rules and warranting the entries
ODFIs warrant each ACH entry they originate and are responsible for ensuring that originators comply with NACHA Operating Rules.
A payments firm's governance committee receives a risk report showing that inherent risk is high but residual risk is low. What does this indicate?
Answer: Effective controls are successfully reducing the impact of a high-risk environment
Residual risk equals inherent risk minus the effect of controls; a low residual risk despite high inherent risk indicates that controls are working effectively.
Which card network rule requires acquirers to ensure that merchants do not surcharge debit card transactions while allowing surcharges on credit cards?
Answer: No-Surcharge rule (Visa/MC settlement)
The 2013 merchant settlement agreement allows credit card surcharging under specific conditions but prohibits applying those surcharges to debit card transactions.
An APRP exam scenario presents a processor that stores full PANs in application logs 'for debugging purposes.' Which PCI DSS requirement is most directly violated?
Answer: Requirement 3 โ Protect stored account data
PCI DSS Requirement 3 prohibits storing sensitive cardholder data (including full PANs without proper masking or encryption) beyond what is necessary, regardless of the stated purpose.
A compliance team conducts a 'gap analysis' before a PCI DSS assessment. What is the PRIMARY goal of this activity?
Answer: To identify controls that are missing or inadequate relative to PCI DSS requirements
A gap analysis compares the current state of controls against PCI DSS requirements to identify deficiencies that must be remediated before the formal assessment.
What is the purpose of the 'return rate' monitoring requirement under NACHA rules for ACH originators?
Answer: To identify originators with unusually high rates of unauthorized or incorrect ACH entries
NACHA monitors return rates to detect originators whose high rates of returned entries may signal poor data quality, unauthorized debits, or fraud.