Risk Management Flashcards
20%
What is compliance risk?
Risk that occurs when a party to a transaction fails to comply, either knowingly or inadvertently, with payment system rules, policies, regulations, and applicable U.S. and state law.
What is credit risk?
Risk that a party to a transaction will not be able to provide the necessary funds, as contracted for settlement to take place.
What is cross-channel risk?
Risk that occurs when the movement of fraudulent or illegal payment transactions from one payments channel to another is met with inconsistent risk management practices and lack of information sharing across payment channels about fraud.
What is Direct Access risk?
Risk specific to the ACH Network that occurs when an Originator or third party transmits Files (transactions) directly to an ACH Operator using a financial institution’s routing and transit number and settlement account.
What is fraud risk?
Risk that occurs when a payment transaction is initiated or altered by any party to the transaction in an attempt to misdirect or misappropriate funds with fraudulent intent.
What is operational risk?
Risk that occurs when a transaction is altered or delayed due to an unintentional error.
What is reputation risk?
Risk that occurs when negative publicity regarding an organization’s business practices leads to a loss of revenue or results in litigation.
What is systemic risk?
Risk that occurs when one funds transfer system participant is unable to settle its commitments causing other participants to be unable to settle their commitments.
What is third-party risk?
Risk that occurs when Organizations rely on outside parties to perform services on their behalf and experience inferior performance by the third party or manage the relationship poorly.
All financial institutions participating in the ACH Network must provide information to reach their ACH operations department and ACH risk/fraud department where?
ACH Contact Registry in the Nacha Risk Management Portal
ODFIs must complete this database registration if they any of their Originators, Third-Party Service Providers, or Third-Party Senders Transmit Files directly to an ACH Operator.
Direct Access Registration Database
ODFIs must complete this database registration if have an agreement with a type of Third-Party Service Provider but do not have an Origination Agreement with the TPSP’s Originators.
Third-Party Sender Registration Database
What are administrative controls?
Procedures and practices used to manage risk, ensure compliance, and safeguard sensitive data.
What is excused delay?
Permissible delay by a Participating DFI or ACH Operator in the performance of its obligations under the Rules beyond the required time limits provided the delay was:
1. Caused by the interruption of communication or computer facilities; and
2. Beyond the reasonable control of the Participating DFI or ACH Operator
What is a contingency plan?
Steps taken to prepare for, respond to, and recover from disruptions to operations.
What is the deadline to report a possible ACH Rules violation?
Within 90 days of the occurrence
What is the length of time a financial institution has to respond to a written request from Nacha regarding an Originator’s or TPS’s Unauthorized Entry Return Rate?
10 Banking Days
Who must conduct an ACH risk assessment?
Participating DFIs and TPSs
What are four components of multifactor authentication?
- Something the Receiver knows (ie: password)
- Something the Receiver has (ie: computer)
- Something the Receiver is (ie: voice or fingerprint)
- Some place the Receiver is (ie: geolocation)
What is multifactor authentication?
Use of 2 or more factors to determine a Receiver’s identity