Compliance Technology & RegTech Flashcards
7 cards from real CCB practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Compliance Technology & RegTech flashcards as text
Which approach does SupTech (Supervisory Technology) represent from a regulator's perspective?
Answer: Technology used by regulators to supervise financial institutions more efficiently
SupTech refers to technology adopted by regulators and supervisory authorities to enhance their ability to monitor, analyze, and enforce compliance across regulated entities.
A compliance officer must ensure third-party RegTech vendors meet the firm's data security standards. What document BEST formalizes these requirements?
Answer: A vendor due diligence questionnaire and contractual data processing agreement
A vendor due diligence questionnaire assesses security capabilities while a data processing agreement legally obligates the vendor to meet required security standards.
What is 'model risk' in the context of RegTech compliance systems?
Answer: The risk that a model produces inaccurate outputs that lead to incorrect compliance decisions or missed violations
Model risk is the potential for adverse outcomes resulting from errors in model design, assumptions, data, or use that cause incorrect compliance decisions.
Under SR 11-7, which US federal guidance governs the management of model risk at banks, what are the two key elements of effective model risk management?
Answer: Robust model development and validation, plus sound model governance
SR 11-7 requires effective model risk management through rigorous development and validation processes combined with strong governance policies and controls.
Which scenario BEST illustrates the concept of 'compliance by design' using RegTech?
Answer: Embedding automated compliance controls and limits directly into a product's technology architecture from inception
Compliance by design integrates regulatory requirements into the technical architecture of a product or process from the start, preventing violations rather than detecting them later.
A compliance officer reviews a vendor's SOC 2 Type II report. What does this report specifically attest to?
Answer: The operating effectiveness of the vendor's controls over a defined period, typically 6-12 months
A SOC 2 Type II report provides independent attestation that a vendor's security, availability, and confidentiality controls operated effectively over a sustained review period.
What is 'regulatory reporting automation' and what risk does it primarily mitigate?
Answer: Automated generation and submission of required regulatory reports; mitigates manual errors and late filing penalties
Regulatory reporting automation uses technology to extract, validate, and submit required reports to regulators, reducing human error and ensuring timely, accurate filings.