APRP COMPREHENSIVE TEST QUESTIONS AND SOLUTIONS
✔✔Compliance Risk - ✔✔Party to a transaction fails to comply, either knowingly or
inadvertently with payment system rules and policies, regulations and applicable U.S.
and state law
✔✔Compliance risk management - ✔✔Be aware of all payment system rules, policies,
regulations and applicable U.S. and state law
✔✔Contactless cards - ✔✔Have an embedded computer chip with financial and
personal information used for payment transactions, and they employ RFID technology
for payment transmission. They include a microcontroller (or equivalent intelligence) and
internal memory and have the ability to secure, store, and provide access to data on the
card.
✔✔Control Activities - ✔✔Include the policies & procedures institutions establish to
manage risks and ensure predefined control objectives are met. Should cover all key
areas of an organization and address items such as organizational structures,
committee compositions and authority levels, officer approval levels, access controls
(physical and electronic), audit programs, monitoring procedures, remedial actions, and
reporting mechanisms.
✔✔Control Environment - ✔✔Begins with a bank's BOD & senior management, who are
responsible for developing effective internal control systems and ensuring all personnel
understand and respect the importance of internal controls. Control systems should be
designed to provide reasonable assurance that appropriately implemented internal
controls will prevent or detect: Materially inaccurate, incomplete, or unauthorized
transactions; Deficiencies in the safeguarding of assets; Unreliable financial and
regulatory reporting; Deviations from laws, regulations, and internal policies
✔✔COSO - ✔✔Committee Of Sponsoring Organizations Of Treadway Commission
✔✔Credit Analysis Techniques - ✔✔"There are several techniques that can be used
when performing credit analysis of a business or organization, including: Credit Policy;
Risk Rating; Ongoing Monitoring and Review; Cross-Channel; Prohibited/Restricted
Businesses"
✔✔Credit Policy - ✔✔Establishing this policy is just one part of the credit analysis
techniques used by financial institutions
✔✔Credit Risk - ✔✔Also known as exposure or temporal risk. Arises when a party to a
transaction is unable to provide the necessary funds, for settlement to take place on the
scheduled date. Especially evident in ACH, Merchant Card and RDC. As well as,
, returns, as evident with all other retail payment systems, including checks and direct
debit.
✔✔Cross Channel Risk - ✔✔When movement of fraudulent or illegal payment
transactions from one payments channel to another is met with inconsistent risk
management practices and lack of information sharing across payment channels about
fraud
✔✔Cross channel risk monitoring - ✔✔Management should develop an enterprise wide
view of retail payment activities due to cross-channel risk as part of a credit analysis
technique as credit risk can be increased by the overall relationship the financial
Institution has with a customer
✔✔CTR/ SAR - ✔✔Currency Transaction Report / Suspicious Activity Report
✔✔Data Integrity - ✔✔"Maintaining and assuring the accuracy and completeness of
data over its life-cycle. This means that data cannot be modified in an unauthorized or
undetected manner"
✔✔Daylight Overdraft - ✔✔Also called intraday overdraft, is a system in which "allows
qualifying banks to overdraw on their Federal Reserve accounts in order to make
payments via Fedwire. By the end of that particular day, Bank A has an obligation to
pay back the Federal Reserve.
✔✔Decoupled Debit Cards - ✔✔"Permit a financial institution to issue a debit card to
consumers regardless of where their demand deposits or other transaction accounts are
held"
✔✔Device Identification - ✔✔A cookie loaded on the customer's PC to confirm that it is
the same PC that was enrolled by the customer and matches the logon ID and
password that is being provided. Can also mean the use of "one-time" cookies and
creates a more complex digital "fingerprint" by looking at a number of characteristics
including PC configuration, Internet protocol address, geo-location, and other factors
✔✔Direct Access Risk - ✔✔A situation in which an Originator, Third-Party Sender or
Third-Party Service Provider transmits ACH files directly to an ACH Operator using the
ODFI's routing number and settlement account and involves a separation of control and
responsibility
✔✔Distributed Ledger Technology (DLT) - ✔✔A type of asset database that is shared
across nodes in a network across sites, geographies or institutions
✔✔Dual controls - ✔✔Making more than one employee approve the transaction before
authorizing the transaction
✔✔Compliance Risk - ✔✔Party to a transaction fails to comply, either knowingly or
inadvertently with payment system rules and policies, regulations and applicable U.S.
and state law
✔✔Compliance risk management - ✔✔Be aware of all payment system rules, policies,
regulations and applicable U.S. and state law
✔✔Contactless cards - ✔✔Have an embedded computer chip with financial and
personal information used for payment transactions, and they employ RFID technology
for payment transmission. They include a microcontroller (or equivalent intelligence) and
internal memory and have the ability to secure, store, and provide access to data on the
card.
✔✔Control Activities - ✔✔Include the policies & procedures institutions establish to
manage risks and ensure predefined control objectives are met. Should cover all key
areas of an organization and address items such as organizational structures,
committee compositions and authority levels, officer approval levels, access controls
(physical and electronic), audit programs, monitoring procedures, remedial actions, and
reporting mechanisms.
✔✔Control Environment - ✔✔Begins with a bank's BOD & senior management, who are
responsible for developing effective internal control systems and ensuring all personnel
understand and respect the importance of internal controls. Control systems should be
designed to provide reasonable assurance that appropriately implemented internal
controls will prevent or detect: Materially inaccurate, incomplete, or unauthorized
transactions; Deficiencies in the safeguarding of assets; Unreliable financial and
regulatory reporting; Deviations from laws, regulations, and internal policies
✔✔COSO - ✔✔Committee Of Sponsoring Organizations Of Treadway Commission
✔✔Credit Analysis Techniques - ✔✔"There are several techniques that can be used
when performing credit analysis of a business or organization, including: Credit Policy;
Risk Rating; Ongoing Monitoring and Review; Cross-Channel; Prohibited/Restricted
Businesses"
✔✔Credit Policy - ✔✔Establishing this policy is just one part of the credit analysis
techniques used by financial institutions
✔✔Credit Risk - ✔✔Also known as exposure or temporal risk. Arises when a party to a
transaction is unable to provide the necessary funds, for settlement to take place on the
scheduled date. Especially evident in ACH, Merchant Card and RDC. As well as,
, returns, as evident with all other retail payment systems, including checks and direct
debit.
✔✔Cross Channel Risk - ✔✔When movement of fraudulent or illegal payment
transactions from one payments channel to another is met with inconsistent risk
management practices and lack of information sharing across payment channels about
fraud
✔✔Cross channel risk monitoring - ✔✔Management should develop an enterprise wide
view of retail payment activities due to cross-channel risk as part of a credit analysis
technique as credit risk can be increased by the overall relationship the financial
Institution has with a customer
✔✔CTR/ SAR - ✔✔Currency Transaction Report / Suspicious Activity Report
✔✔Data Integrity - ✔✔"Maintaining and assuring the accuracy and completeness of
data over its life-cycle. This means that data cannot be modified in an unauthorized or
undetected manner"
✔✔Daylight Overdraft - ✔✔Also called intraday overdraft, is a system in which "allows
qualifying banks to overdraw on their Federal Reserve accounts in order to make
payments via Fedwire. By the end of that particular day, Bank A has an obligation to
pay back the Federal Reserve.
✔✔Decoupled Debit Cards - ✔✔"Permit a financial institution to issue a debit card to
consumers regardless of where their demand deposits or other transaction accounts are
held"
✔✔Device Identification - ✔✔A cookie loaded on the customer's PC to confirm that it is
the same PC that was enrolled by the customer and matches the logon ID and
password that is being provided. Can also mean the use of "one-time" cookies and
creates a more complex digital "fingerprint" by looking at a number of characteristics
including PC configuration, Internet protocol address, geo-location, and other factors
✔✔Direct Access Risk - ✔✔A situation in which an Originator, Third-Party Sender or
Third-Party Service Provider transmits ACH files directly to an ACH Operator using the
ODFI's routing number and settlement account and involves a separation of control and
responsibility
✔✔Distributed Ledger Technology (DLT) - ✔✔A type of asset database that is shared
across nodes in a network across sites, geographies or institutions
✔✔Dual controls - ✔✔Making more than one employee approve the transaction before
authorizing the transaction