Law: Finance
I asked ChatGPT to summarize these for my own notes.
Usually have to go through these during the first week of onboarding.
AML: Anti-Money Laundering
Purpose: Prevent criminals from using financial institutions to disguise illegally obtained money.
- Requires monitoring for suspicious transactions.
- Financial institutions must establish AML programs.
- Suspicious Activity Reports (SARs) are filed with FinCEN.
- Customer due diligence helps identify money laundering risks.
Interview takeaway: Detect and report suspicious financial activity, not simply block every unusual transaction.
KYC: Know Your Customer
Purpose: Verify customer identity and understand who is using financial services.
- Identity verification.
- Customer risk assessment.
- Understanding beneficial ownership and customer relationships.
- Ongoing monitoring and updates.
Interview takeaway: KYC establishes who the customer is and helps assess risk.
CDD vs. EDD
| Role/Item | Verb | Item |
|---|---|---|
| CDD | assesses | customer risk through standard due diligence |
| EDD | applies | additional scrutiny to higher-risk customers |
| Beneficial Owner | identifies | the individual(s) who ultimately own or control a legal entity |
BSA: Bank Secrecy Act
Purpose: Establish United States requirements for financial recordkeeping and reporting to combat financial crime.
Key requirements include:
- AML programs.
- Currency Transaction Reports (CTRs).
- Suspicious Activity Reports (SARs).
- Recordkeeping and customer identification requirements.
Interview takeaway: The BSA is a foundational United States AML and financial transparency law.
OFAC: Sanctions Compliance
Purpose: Enforce United States economic sanctions against designated individuals, organizations, countries, and other targets.
- Screening customers and transactions against applicable sanctions lists.
- Blocking or rejecting transactions when legally required.
- Maintaining sanctions compliance controls.
Interview takeaway: A transaction can be legitimate from an AML perspective but still violate sanctions requirements.
GLBA: Gramm-Leach-Bliley Act
Purpose: Protect consumers' nonpublic personal financial information.
Key components:
- Privacy Rule: Requirements concerning disclosure of customer information.
- Safeguards Rule: Security safeguards for customer information.
- Restrictions and requirements surrounding information sharing.
Interview takeaway: Financial institutions must protect customer financial data and implement appropriate safeguards.
FCRA: Fair Credit Reporting Act
Purpose: Regulate consumer credit reporting and the use of consumer reports.
- Accuracy of credit information.
- Consumer access to credit reports.
- Permissible purposes for accessing reports.
- Dispute and correction procedures.
Interview takeaway: Relevant to credit checks, lending platforms, and systems processing consumer credit data.
ECOA: Regulation B
Purpose: Prohibit discrimination in credit transactions.
The Equal Credit Opportunity Act addresses discrimination based on protected characteristics, including race, religion, national origin, sex, marital status, and age, subject to statutory provisions.
Interview takeaway: Lending and credit decision systems need appropriate fair lending controls.
TILA: Truth in Lending Act
Purpose: Promote informed consumer credit decisions through disclosure requirements.
- Interest rates and financing costs.
- APR disclosures.
- Credit terms and costs.
- Certain consumer credit protections.
Interview takeaway: Consumers must receive required information about borrowing costs.
EFTA Regulation E
Purpose: Protect consumers in electronic fund transfers.
Covers areas such as:
- Debit card transactions.
- Electronic transfers.
- Certain error resolution procedures.
- Consumer liability for unauthorized transactions, subject to applicable rules.
Interview takeaway: Important for payment processing, fraud detection, and transaction dispute systems.
UDAAP: Unfair, Deceptive, or Abusive Acts or Practices
Purpose: Protect consumers from prohibited conduct in financial products and services.
- Unfair practices.
- Deceptive representations or omissions.
- Abusive practices under applicable consumer financial protection law.
Interview takeaway: Product design, disclosures, and customer communications can create regulatory risk.
Dodd-Frank Act
Purpose: Major United States financial reform legislation following the 2008 financial crisis.
Key elements include:
- Creation of the Consumer Financial Protection Bureau (CFPB).
- Enhanced financial stability and oversight mechanisms.
- Consumer protection provisions.
- Regulation of certain financial markets and institutions.
Interview takeaway: Broad financial regulatory reform, not a single compliance requirement.
Basel III
Purpose: International banking standards for capital adequacy, liquidity, and risk management.
- Capital requirements.
- Liquidity standards.
- Leverage constraints.
- Risk management expectations.
Interview takeaway: Banks must maintain financial resilience against losses and liquidity stress. Specific implementation depends on jurisdiction and institution.
SOX: Sarbanes-Oxley Act
Purpose: Improve corporate financial reporting integrity and internal controls.
Particularly relevant to publicly traded companies.
- Internal controls over financial reporting.
- Audit requirements.
- Management accountability.
- Record integrity.
Interview takeaway: IT systems supporting financial reporting need access controls, audit trails, and change management.
PCI DSS: Payment Card Industry Data Security Standard
Purpose: Protect payment card data.
Technically, PCI DSS is an industry security standard, not a federal statute.
Key concepts:
- Secure cardholder data.
- Restrict access.
- Network security.
- Logging and monitoring.
- Vulnerability management.
- Encryption and tokenization where appropriate.
Interview takeaway: Relevant when designing systems that store, process, or transmit payment card information.
OCC / FDIC / Federal Reserve: Institutional Roles
| Role/Item | Verb | Item |
|---|---|---|
| OCC | supervises and regulates | national banks and federal savings associations |
| FDIC | provides | deposit insurance and supervision of certain financial institutions |
| Federal Reserve | oversees | monetary policy, bank supervision, and financial stability |
| FinCEN | administers | financial intelligence and AML-related programs |
| CFPB | protects and supervises | consumers in the financial marketplace within its authority |
| SEC | regulates | securities markets and investor protection |
| FINRA | oversees | broker-dealers under its authority |
Misc.
- Metro 2®: Standardized format for furnishing consumer credit account data to credit bureaus.
- FINRA: Self-regulatory organization overseeing member broker-dealers and associated persons.
- SIE: Foundational securities industry knowledge exam; does not itself grant registration.
- Series 7: General securities representative qualification.
- Series 63: State securities agent law qualification.
- Series 65: Investment adviser representative qualification.
- Series 66: Combined state securities agent and investment adviser law qualification.
- SEC: Federal securities market regulator.
- Securities Act of 1933: Securities offerings and disclosure requirements.
- Securities Exchange Act of 1934: Securities markets, trading, and reporting.
- Regulation NMS: National market system rules for United States equity markets.
- Regulation SHO: Short sale regulation.
- Regulation T: Broker-dealer credit and margin requirements.
- SAFE Act: Mortgage loan originator licensing and registration framework.
- NMLS: Nationwide Multistate Licensing System for mortgage licensing and registration.
- RESPA / Regulation X: Real estate settlement procedures and mortgage servicing requirements.
- TRID: Integrated mortgage disclosures under TILA and RESPA.
- HMDA: Mortgage lending data collection and reporting.
- HOEPA: Requirements and protections for certain high-cost mortgages.
- OCC: Supervises national banks and federal savings associations.
- FDIC: Deposit insurance and supervision of certain financial institutions.
- Federal Reserve: Monetary policy, bank supervision, and financial stability.
- FinCEN: Financial intelligence and AML-related administration.
- CFPB: Consumer financial protection and supervision within its authority.
Quick Memorization Table
| Role/Item | Verb | Item |
|---|---|---|
| AML | addresses | Anti-Money Laundering |
| KYC | addresses | Know Your Customer |
| BSA | governs | financial crime reporting and recordkeeping |
| OFAC | governs | sanctions |
| GLBA | governs | financial privacy and safeguards |
| FCRA | governs | the Fair Credit Reporting Act |
| ECOA | governs | fair lending |
| TILA | requires | credit cost disclosures |
| EFTA | governs | electronic fund transfers |
| UDAAP | prohibits | unfair, deceptive, or abusive acts and practices |
| Dodd-Frank | establishes | financial reform requirements |
| Basel III | establishes | capital and liquidity requirements |
| SOX | requires | financial reporting controls |
| PCI DSS | protects | cardholder data security |
Financial Regulations for Cloud Engineers
Recommended by ChatGPT.
One-Minute Interview Summary
- AML / KYC: Prevent financial crime and identify customers.
- Metro 2: Report credit account data consistently to bureaus.
- FINRA: Securities industry oversight, registration, and conduct.
- Series 7: General securities representative qualification.
- Series 63 / 65 / 66: State securities and investment adviser qualifications.
- SAFE Act / NMLS: Mortgage originator licensing and registration.
- RESPA / TILA / TRID: Mortgage disclosures and settlement requirements.
- HMDA: Mortgage lending data collection.
- SEC: Federal securities regulation.
- SOX: Financial reporting controls.
- PCI DSS: Payment card data security.
Cloud engineering connection: Your infrastructure should support least privilege, encryption, audit logs, data retention, access reviews, regulatory reporting pipelines, and disaster recovery.
The specific legal and regulatory requirements depend on the institution and business activity.
Note: These are United States-focused interview-level summaries, not a complete legal compliance guide.