Regulatory Compliance Flashcards
7 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Regulatory Compliance flashcards as text
Under the NACHA Operating Rules, what is the maximum return rate threshold for unauthorized debit entries (Return Code R10) before NACHA may investigate an originator?
Answer: 0.5%
NACHA's unauthorized return rate threshold is 0.5%; exceeding it triggers monitoring and potential suspension of the originator.
The EU's revised Payment Services Directive (PSD2) introduced which major security requirement for electronic payments?
Answer: Strong Customer Authentication (SCA)
PSD2 mandated Strong Customer Authentication requiring at least two of three factors: knowledge, possession, and inherence.
Which compliance concept requires a payments company to verify that a third-party processor complies with applicable rules before onboarding them?
Answer: Third-party due diligence
Third-party due diligence requires assessing a vendor's or partner's compliance posture before entering into a business relationship.
What is 'structuring' in the context of BSA/AML compliance?
Answer: Breaking up large transactions to evade CTR reporting thresholds
Structuring (also known as 'smurfing') is the illegal practice of breaking transactions into smaller amounts to avoid BSA reporting thresholds.
Under Regulation E, within how many business days must a financial institution provisionally credit a consumer's account after receiving notice of an unauthorized EFT error?
Answer: 10 business days
Under Reg E, if an institution cannot complete its investigation within 10 business days, it must provisionally credit the consumer's account.
Which organization publishes the Payment Card Industry Data Security Standard (PCI DSS)?
Answer: PCI Security Standards Council
The PCI Security Standards Council, founded by the major card brands, publishes and maintains PCI DSS.
A payment processor knowingly facilitates transactions for an OFAC-sanctioned entity. Under U.S. law, what is the nature of this liability?
Answer: Strict liability, regardless of knowledge
OFAC sanctions violations are strict liability offenses, meaning knowledge or intent is not required for civil penalties to apply.