Study Guide 2023+

law

Warning: These notes are partial, ongoing, incomplete, and may contain typos/inaccuracies. (They are kept factually accurate, time permitting.)

They are being united from many disparate notes created in the past and the layout/organization will gradually improve with time!

Please view them on a computer as they are not optimized for mobile (although you can still view them on Mobile along with the Flashcards at your own risk)!

Topics and code examples are lazy-loaded and may require two-clicks from the TOC to correctly calculate the updated x,y coordinates (after rendering). Thanks!

Law: Finance

I asked ChatGPT to summarize these for my own notes.

Usually have to go through these during the first week of onboarding.

AML: Anti-Money Laundering

Purpose: Prevent criminals from using financial institutions to disguise illegally obtained money.

Interview takeaway: Detect and report suspicious financial activity, not simply block every unusual transaction.

KYC: Know Your Customer

Purpose: Verify customer identity and understand who is using financial services.

Interview takeaway: KYC establishes who the customer is and helps assess risk.

CDD vs. EDD

Role/Item Verb Item
CDD assesses customer risk through standard due diligence
EDD applies additional scrutiny to higher-risk customers
Beneficial Owner identifies the individual(s) who ultimately own or control a legal entity

BSA: Bank Secrecy Act

Purpose: Establish United States requirements for financial recordkeeping and reporting to combat financial crime.

Key requirements include:

Interview takeaway: The BSA is a foundational United States AML and financial transparency law.

OFAC: Sanctions Compliance

Purpose: Enforce United States economic sanctions against designated individuals, organizations, countries, and other targets.

Interview takeaway: A transaction can be legitimate from an AML perspective but still violate sanctions requirements.

GLBA: Gramm-Leach-Bliley Act

Purpose: Protect consumers' nonpublic personal financial information.

Key components:

Interview takeaway: Financial institutions must protect customer financial data and implement appropriate safeguards.

FCRA: Fair Credit Reporting Act

Purpose: Regulate consumer credit reporting and the use of consumer reports.

Interview takeaway: Relevant to credit checks, lending platforms, and systems processing consumer credit data.

ECOA: Regulation B

Purpose: Prohibit discrimination in credit transactions.

The Equal Credit Opportunity Act addresses discrimination based on protected characteristics, including race, religion, national origin, sex, marital status, and age, subject to statutory provisions.

Interview takeaway: Lending and credit decision systems need appropriate fair lending controls.

TILA: Truth in Lending Act

Purpose: Promote informed consumer credit decisions through disclosure requirements.

Interview takeaway: Consumers must receive required information about borrowing costs.

EFTA Regulation E

Purpose: Protect consumers in electronic fund transfers.

Covers areas such as:

Interview takeaway: Important for payment processing, fraud detection, and transaction dispute systems.

UDAAP: Unfair, Deceptive, or Abusive Acts or Practices

Purpose: Protect consumers from prohibited conduct in financial products and services.

Interview takeaway: Product design, disclosures, and customer communications can create regulatory risk.

Dodd-Frank Act

Purpose: Major United States financial reform legislation following the 2008 financial crisis.

Key elements include:

Interview takeaway: Broad financial regulatory reform, not a single compliance requirement.

Basel III

Purpose: International banking standards for capital adequacy, liquidity, and risk management.

Interview takeaway: Banks must maintain financial resilience against losses and liquidity stress. Specific implementation depends on jurisdiction and institution.

SOX: Sarbanes-Oxley Act

Purpose: Improve corporate financial reporting integrity and internal controls.

Particularly relevant to publicly traded companies.

Interview takeaway: IT systems supporting financial reporting need access controls, audit trails, and change management.

PCI DSS: Payment Card Industry Data Security Standard

Purpose: Protect payment card data.

Technically, PCI DSS is an industry security standard, not a federal statute.

Key concepts:

Interview takeaway: Relevant when designing systems that store, process, or transmit payment card information.

OCC / FDIC / Federal Reserve: Institutional Roles

Role/Item Verb Item
OCC supervises and regulates national banks and federal savings associations
FDIC provides deposit insurance and supervision of certain financial institutions
Federal Reserve oversees monetary policy, bank supervision, and financial stability
FinCEN administers financial intelligence and AML-related programs
CFPB protects and supervises consumers in the financial marketplace within its authority
SEC regulates securities markets and investor protection
FINRA oversees broker-dealers under its authority

Misc.

Quick Memorization Table

Role/Item Verb Item
AML addresses Anti-Money Laundering
KYC addresses Know Your Customer
BSA governs financial crime reporting and recordkeeping
OFAC governs sanctions
GLBA governs financial privacy and safeguards
FCRA governs the Fair Credit Reporting Act
ECOA governs fair lending
TILA requires credit cost disclosures
EFTA governs electronic fund transfers
UDAAP prohibits unfair, deceptive, or abusive acts and practices
Dodd-Frank establishes financial reform requirements
Basel III establishes capital and liquidity requirements
SOX requires financial reporting controls
PCI DSS protects cardholder data security

Financial Regulations for Cloud Engineers

Recommended by ChatGPT.

One-Minute Interview Summary

Cloud engineering connection: Your infrastructure should support least privilege, encryption, audit logs, data retention, access reviews, regulatory reporting pipelines, and disaster recovery.

The specific legal and regulatory requirements depend on the institution and business activity.

Note: These are United States-focused interview-level summaries, not a complete legal compliance guide.