← All CFP Flashcard Decks

Regulatory Compliance & Risk Management Flashcards

7 cards from real CFP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Regulatory Compliance & Risk Management flashcards as text
  1. Which approach to compliance risk management involves embedding compliance controls directly into product design and technology workflows?

    Answer: Compliance by design (RegTech integration)

    Compliance by design integrates regulatory requirements into product architecture and automated workflows from the outset, reducing manual oversight needs.

  2. Under US sanctions law administered by OFAC, which action is required when a fintech company identifies a match on the SDN (Specially Designated Nationals) list?

    Answer: Block the transaction and report to OFAC within 10 business days

    OFAC requires that a blocked transaction be reported to OFAC within 10 business days and the blocked funds held in an interest-bearing account.

  3. What is 'liquidity risk' specifically in the context of a buy-now-pay-later (BNPL) fintech provider?

    Answer: The risk that the provider cannot fund new loans due to insufficient short-term capital

    Liquidity risk for a BNPL provider is the inability to access sufficient funding to originate new loans when capital is tied up in outstanding receivables.

  4. A fintech operating across multiple states discovers it needs a Money Transmitter License (MTL) in each state. What is this licensing requirement commonly called?

    Answer: State-by-state licensing patchwork

    Unlike some countries with federal-level licensing, US money transmission requires individual state licenses in most states where the company operates, often called the licensing patchwork.

  5. Which risk control technique involves transferring a specific operational risk to a third party through contract?

    Answer: Risk transfer

    Risk transfer shifts the financial consequences of a risk to another party, most commonly through insurance policies or contractual indemnification clauses.

  6. Under the Fair Credit Reporting Act (FCRA), if a fintech company takes an adverse action based on a credit report, what must it provide to the consumer?

    Answer: An adverse action notice including the CRA name and consumer's right to a free report

    FCRA requires creditors to send an adverse action notice identifying the credit reporting agency used and informing the consumer of their right to obtain a free copy of their report.

  7. What is the primary regulatory concern with fintech companies using large language models (LLMs) for credit underwriting decisions?

    Answer: Explainability and potential for discriminatory bias in automated decisions

    Regulators require that credit decisions be explainable and non-discriminatory; LLMs' 'black box' nature makes it difficult to demonstrate compliance with fair lending laws.