โ† All CCB Flashcard Decks

Compliance Technology & RegTech Flashcards

7 cards from real CCB practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Compliance Technology & RegTech flashcards as text
  1. A firm implements a graph database to map relationships between clients, accounts, and transactions for AML purposes. What compliance capability does this PRIMARILY enhance?

    Answer: Network analysis to detect complex money laundering typologies involving multiple entities

    Graph databases excel at revealing hidden connections and relationships across entities, enabling detection of sophisticated layering and structuring schemes in AML investigations.

  2. Which principle from the BCBS 239 guidelines is MOST directly supported by RegTech data management solutions?

    Answer: Accuracy and integrity of risk data aggregation and reporting

    BCBS 239 requires banks to have strong risk data aggregation capabilities; RegTech data management solutions directly support accuracy, completeness, and timeliness of risk data.

  3. When deploying a cloud-based RegTech solution, which legal concept determines which country's data protection laws apply to customer data stored in that cloud?

    Answer: Data residency and data sovereignty requirements

    Data residency and sovereignty rules determine the geographic location where data must be stored and which nation's laws govern its protection and access.

  4. A RegTech system flags a customer as high-risk based on an algorithmic score. The compliance officer disagrees. What governance principle requires documentation of this override?

    Answer: Human-in-the-loop accountability and audit trail requirements

    When humans override automated compliance decisions, accountability frameworks require documenting the rationale to maintain a complete and auditable record of compliance judgments.

  5. What is the main advantage of using synthetic data for testing compliance monitoring systems?

    Answer: It allows testing with realistic patterns without exposing actual customer data and its associated privacy risks

    Synthetic data mimics real transaction patterns while containing no actual customer information, enabling thorough system testing without violating data privacy regulations.

  6. Under the FFIEC's cybersecurity assessment framework, which domain specifically addresses the integration of cybersecurity with compliance and risk management processes?

    Answer: Cyber Risk Management and Oversight

    The Cyber Risk Management and Oversight domain of the FFIEC Cybersecurity Assessment Tool covers governance, risk management culture, and board-level accountability for cyber risks.

  7. A compliance officer is assessing a new AI-powered sanctions screening tool. Which evaluation factor is UNIQUE to AI-based tools compared to traditional rule-based systems?

    Answer: Explainability of match decisions and ongoing model drift monitoring

    AI tools require ongoing monitoring for model drift and must provide explainable outputs, unlike rule-based systems where the decision logic is transparent and static.