BSACS (questions well answered to
pass) graded A+
As part of 314(a), CUs must conduct..... - correct answer ✔✔a one-time search of its records to identify
accounts or transactions of a named suspect. Unless otherwise instructed by an information request,
search records for: current accounts; accounts maintained during the preceding 12 months; and
transactions conducted outside of an account by or on behalf of a named suspect during the preceding
six months.
Bank Secrecy Act/Anti-Money Laundering (BSA/AML) regulations require credit unions' BSA/AML
Compliance Programs to include, at a minimum: - correct answer ✔✔1. A qualified BSA compliance
officer; 2. A system of internal controls; 3. Independent testing; 4. Training for all appropriate personnel;
and 5. Ongoing member due diligence.
Credit unions' compliance programs must be: - correct answer ✔✔• in writing, • approved by the credit
union's board of directors, and • reflected in the minutes of the board meeting.
A "system of internal controls" refers to... - correct answer ✔✔the policies and procedures the credit
union puts in place to limit and control risks associated with BSA/AML.
The level of sophistication of the credit union's internal controls will be... - correct answer
✔✔commensurate with the size, structure, risks, and complexity of the credit union.
The BSA Officer is responsible for... - correct answer ✔✔coordinating and monitoring day-to-day
BSA/AML compliance.
The BSA Officer is expected to... - correct answer ✔✔be fully knowledgeable of the Bank Secrecy Act and
all related regulations, as well as understand the money laundering and terrorist financing risks
associated with each of the credit union's products, services, members, and geographic locations.
An audit of the BSA/AML compliance program should be conducted by... - correct answer ✔✔the
internal audit department, outside auditors, consultants, or other qualified independent parties.
,While the auditor must be qualified to test BSA compliance, he or she may not... - correct answer ✔✔be
involved in the function being tested, or audited.
The recommended frequency of the required independent testing... - correct answer ✔✔every 12-18
months, depending on the credit union's risk profile.
At a minimum, the credit union's BSA/AML training program must provide training for... - correct answer
✔✔all personnel whose duties require knowledge of the BSA.
The CU's BSA/AML training should be... - correct answer ✔✔tailored to the person's specific
responsibilites.
While the board of directors (BOD) may not require the same degree of training as the credit union's
operations personnel, the BOD must understand... - correct answer ✔✔the importance of BSA
regulatory requirements, the ramifications of noncompliance, and the risks posed to the credit union.
Who is ultimately responsible for the CU's BSA/AML compliance? - correct answer ✔✔The Board of
Directors
NCUA recommends that BSA training be done... It should also be... - correct answer ✔✔every 12 to 18
months. It should also be ongoing and incorporate current developments and changes.
CUs are required to have appropriate ___ procedures for conducting ongoing member due diligence. -
correct answer ✔✔risk-based
Before a CU may create appropriate MDD procedures, it must first... - correct answer ✔✔develop a
member risk profile.
Developing a member risk profile means/requires... - correct answer ✔✔understanding the nature and
purpose of each member relationship as well as expected transaction activity, in order to provide a
baseline against which your member's activity is assessed for suspicious activity reporting.
,Establishing a member risk profile may include... - correct answer ✔✔1. self evident information (such as
type of member, acct, service, or product)
2. ongoing monitoring to identify changes (ex: member activity changes)
Activity changes (such as transaction activity or beneficial ownerships) could impact... - correct answer
✔✔the member's risk profile.
On what basis must CUs maintain and update member information? - correct answer ✔✔on a risk-basis.
On what basis are CUs not required to update member information? - correct answer ✔✔on a
continuous or periodic basis.
The member information updating requirement is ____ driven and only occurs as a result of what? -
correct answer ✔✔1. Event
2. detecting unusual activity through normal monitoring.
Ongoing due diligence monitoring applies to... - correct answer ✔✔ALL of your members
Ongoing due diligence monitoring helps you.... - correct answer ✔✔determine whether a member is or
isn't "higher risk".
When identifying members as higher-risk, CUs may not... - correct answer ✔✔label any particular
category of businesses as "high-risk"
The level of risk for each individual account must be determined by... - correct answer ✔✔performing a
risk assessment unique to each account.
If the credit union determines that a member or account presents a higher risk, the credit union must
perform... - correct answer ✔✔enhanced due diligence for this account.
The CU's BSA/AML Compliance Program must include a CIP/MIP to... - correct answer ✔✔effectively
identify and verify the identity of every member and customer opening an account.
, The CU's MIP/CIP requires the CU to identify and verify the identity of who? - correct answer ✔✔every
member/customer opening an account.
Every part of the BSA/AML Compliance Program (including the BSA/AML policies & procedures) must
correspond with... - correct answer ✔✔the unique risk profile of the specific credit union.
The development of the credit union's BSA/AML risk assessment generally involves... - correct answer
✔✔1. the identification of specific risk categories unique to the CU
2. an analysis of the information identified to better assess the risks within these specific risk categories.
The identification of risk categories is credit union-specific, and a conclusion regarding the risk categories
should be based on the consideration of... - correct answer ✔✔all pertinent information.
(T/F) The required risk-categories include: products, services, members, and geographic locations of each
of the CU's offices. - correct answer ✔✔False. There are no required risk categories.
The number and detail of a CU's risk-categories will vary based on... - correct answer ✔✔the CU's size or
complexity, and organizational structure.
T/F: The existence of a single indicator can determine the existence of lower or higher risk. - correct
answer ✔✔False. Any single indicator does not necessarily determine the existence of lower or higher
risk.
The purpose of the Risk Assessment analysis is to assess... in order to... - correct answer ✔✔1. Money
Laundering/Terrorist Financing (ML/TF) and other illicit financial activity risks
2. develop appropriate internal controls to mitigate overall risk.
The credit union's risk assessment must be... - correct answer ✔✔1. Very comprehensive,
2. in writing
3. Provided to all business lines across the credit union.
pass) graded A+
As part of 314(a), CUs must conduct..... - correct answer ✔✔a one-time search of its records to identify
accounts or transactions of a named suspect. Unless otherwise instructed by an information request,
search records for: current accounts; accounts maintained during the preceding 12 months; and
transactions conducted outside of an account by or on behalf of a named suspect during the preceding
six months.
Bank Secrecy Act/Anti-Money Laundering (BSA/AML) regulations require credit unions' BSA/AML
Compliance Programs to include, at a minimum: - correct answer ✔✔1. A qualified BSA compliance
officer; 2. A system of internal controls; 3. Independent testing; 4. Training for all appropriate personnel;
and 5. Ongoing member due diligence.
Credit unions' compliance programs must be: - correct answer ✔✔• in writing, • approved by the credit
union's board of directors, and • reflected in the minutes of the board meeting.
A "system of internal controls" refers to... - correct answer ✔✔the policies and procedures the credit
union puts in place to limit and control risks associated with BSA/AML.
The level of sophistication of the credit union's internal controls will be... - correct answer
✔✔commensurate with the size, structure, risks, and complexity of the credit union.
The BSA Officer is responsible for... - correct answer ✔✔coordinating and monitoring day-to-day
BSA/AML compliance.
The BSA Officer is expected to... - correct answer ✔✔be fully knowledgeable of the Bank Secrecy Act and
all related regulations, as well as understand the money laundering and terrorist financing risks
associated with each of the credit union's products, services, members, and geographic locations.
An audit of the BSA/AML compliance program should be conducted by... - correct answer ✔✔the
internal audit department, outside auditors, consultants, or other qualified independent parties.
,While the auditor must be qualified to test BSA compliance, he or she may not... - correct answer ✔✔be
involved in the function being tested, or audited.
The recommended frequency of the required independent testing... - correct answer ✔✔every 12-18
months, depending on the credit union's risk profile.
At a minimum, the credit union's BSA/AML training program must provide training for... - correct answer
✔✔all personnel whose duties require knowledge of the BSA.
The CU's BSA/AML training should be... - correct answer ✔✔tailored to the person's specific
responsibilites.
While the board of directors (BOD) may not require the same degree of training as the credit union's
operations personnel, the BOD must understand... - correct answer ✔✔the importance of BSA
regulatory requirements, the ramifications of noncompliance, and the risks posed to the credit union.
Who is ultimately responsible for the CU's BSA/AML compliance? - correct answer ✔✔The Board of
Directors
NCUA recommends that BSA training be done... It should also be... - correct answer ✔✔every 12 to 18
months. It should also be ongoing and incorporate current developments and changes.
CUs are required to have appropriate ___ procedures for conducting ongoing member due diligence. -
correct answer ✔✔risk-based
Before a CU may create appropriate MDD procedures, it must first... - correct answer ✔✔develop a
member risk profile.
Developing a member risk profile means/requires... - correct answer ✔✔understanding the nature and
purpose of each member relationship as well as expected transaction activity, in order to provide a
baseline against which your member's activity is assessed for suspicious activity reporting.
,Establishing a member risk profile may include... - correct answer ✔✔1. self evident information (such as
type of member, acct, service, or product)
2. ongoing monitoring to identify changes (ex: member activity changes)
Activity changes (such as transaction activity or beneficial ownerships) could impact... - correct answer
✔✔the member's risk profile.
On what basis must CUs maintain and update member information? - correct answer ✔✔on a risk-basis.
On what basis are CUs not required to update member information? - correct answer ✔✔on a
continuous or periodic basis.
The member information updating requirement is ____ driven and only occurs as a result of what? -
correct answer ✔✔1. Event
2. detecting unusual activity through normal monitoring.
Ongoing due diligence monitoring applies to... - correct answer ✔✔ALL of your members
Ongoing due diligence monitoring helps you.... - correct answer ✔✔determine whether a member is or
isn't "higher risk".
When identifying members as higher-risk, CUs may not... - correct answer ✔✔label any particular
category of businesses as "high-risk"
The level of risk for each individual account must be determined by... - correct answer ✔✔performing a
risk assessment unique to each account.
If the credit union determines that a member or account presents a higher risk, the credit union must
perform... - correct answer ✔✔enhanced due diligence for this account.
The CU's BSA/AML Compliance Program must include a CIP/MIP to... - correct answer ✔✔effectively
identify and verify the identity of every member and customer opening an account.
, The CU's MIP/CIP requires the CU to identify and verify the identity of who? - correct answer ✔✔every
member/customer opening an account.
Every part of the BSA/AML Compliance Program (including the BSA/AML policies & procedures) must
correspond with... - correct answer ✔✔the unique risk profile of the specific credit union.
The development of the credit union's BSA/AML risk assessment generally involves... - correct answer
✔✔1. the identification of specific risk categories unique to the CU
2. an analysis of the information identified to better assess the risks within these specific risk categories.
The identification of risk categories is credit union-specific, and a conclusion regarding the risk categories
should be based on the consideration of... - correct answer ✔✔all pertinent information.
(T/F) The required risk-categories include: products, services, members, and geographic locations of each
of the CU's offices. - correct answer ✔✔False. There are no required risk categories.
The number and detail of a CU's risk-categories will vary based on... - correct answer ✔✔the CU's size or
complexity, and organizational structure.
T/F: The existence of a single indicator can determine the existence of lower or higher risk. - correct
answer ✔✔False. Any single indicator does not necessarily determine the existence of lower or higher
risk.
The purpose of the Risk Assessment analysis is to assess... in order to... - correct answer ✔✔1. Money
Laundering/Terrorist Financing (ML/TF) and other illicit financial activity risks
2. develop appropriate internal controls to mitigate overall risk.
The credit union's risk assessment must be... - correct answer ✔✔1. Very comprehensive,
2. in writing
3. Provided to all business lines across the credit union.