โ† All CCB Flashcard Decks

Compliance Technology & RegTech Flashcards

7 cards from real CCB practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Compliance Technology & RegTech flashcards as text
  1. A compliance team is evaluating whether to build or buy a RegTech solution. Which factor most strongly favors a 'buy' decision?

    Answer: A mature vendor solution already addresses the firm's needs with proven regulatory acceptance

    When a proven commercial solution meets the firm's needs and is already accepted by regulators, buying is typically faster and less risky than building a custom solution.

  2. Which technology is BEST suited for creating an immutable audit trail for compliance purposes?

    Answer: Distributed ledger / blockchain technology

    Blockchain's immutable, append-only distributed ledger creates tamper-evident records that are ideal for compliance audit trails.

  3. Under the EU AI Act, compliance AI systems classified as 'high-risk' are required to have which of the following?

    Answer: Human oversight mechanisms and detailed documentation

    The EU AI Act mandates that high-risk AI systems include human oversight mechanisms, maintain detailed technical documentation, and undergo conformity assessments.

  4. A RegTech vendor claims their AML screening tool uses machine learning to reduce false positives by 60%. What should a compliance officer do BEFORE deploying it?

    Answer: Validate the claim using the firm's own data in a controlled pilot

    Vendor claims must be independently validated using the firm's own data and transaction patterns before relying on the tool for compliance purposes.

  5. What is the primary purpose of an API gateway in a financial institution's RegTech architecture?

    Answer: To manage, secure, and route data flows between compliance systems and external services

    An API gateway acts as a central control point that manages authentication, authorization, and data routing between internal systems and external RegTech services.

  6. Which compliance challenge does 'federated learning' help address in financial services?

    Answer: Training AI models on sensitive data across institutions without sharing raw data

    Federated learning allows AI models to be trained across multiple institutions using distributed data without centralizing or sharing the underlying sensitive data.

  7. A firm's compliance monitoring system generates 10,000 alerts monthly but investigators can only review 1,000. What is this situation called?

    Answer: Alert fatigue and capacity mismatch

    Alert fatigue occurs when the volume of alerts exceeds investigative capacity, leading to prioritization challenges and risk of missed genuine suspicious activity.