Spotlights
A series of spotlights into ongoing best practices, guidance, laws, and regulations across the globe on key risk and compliance matters and how to keep pace in your business model
Featured Spotlight on Third-Party Senders
NACHA OPERATING RULES
Nacha Operating Rules and Audit Guidelines
for Third-Party Senders
Third-Party Sender (TPS) is defined under the Nacha Operating Rules as a type of Third-Party Service Provider (TPSP) that acts as an intermediary in transmitting entries between an Originator and an Originating Depository Financial Institution (ODFI). The Nacha Operating Rules require a TPS to conduct an annual audit of their ACH compliance by December 31st each year to ensure adherence to Nacha’s ACH transaction guidelines.
Separately, outside of the annual Nacha audit requirement, typically, a Banking as a Service (BaaS) or For Benefit Of (FBO) master services agreement between a technology platform company and a regulated financial institution will require the submission of the audit to maintain compliance with the agreement.
CYBERSECURITY
Strengthening Cybersecurity in the European Union through Digital Operational Resilience
A Spotlight on the Implementation and Requirements of the Digital Operational Resilience Act (DORA)
DATA PRIVACY
Handling and Protecting Personal Sensitive Information
A Spotlight on the Global Regulatory Emergence of Consumer Privacy
KNOW YOUR CUSTOMER
Knowing Your Customer Data Journey
A Spotlight on Standards for Know Your Customer (KYC) Framework and Procedures
Featured Spotlight on Corporate Transparency
CORPORATE TRANSPARENCY
Decoding US Beneficial Ownership
Reporting Rules
Following the Financial Action Task Force’s (FATF) enhancements to Recommendations 24 and 25 regarding the transparency and beneficial ownership of legal persons and arrangements, the US introduced significant changes with required Beneficial Ownership Information (BOI) reporting, effective from January 1, 2024. The initiative aims to increase corporate transparency and prevent financial crimes.
SANCTIONS
Geolocation is More Than Just a Postcode
A Spotlight on Geolocation and IP Address Screening to Maintain Compliance with the Office of Foreign Assets Control (OFAC)
CYBERSECURITY
The Understanding and Defending Against Social Engineering Attacks
A Spotlight on How You Can Protect Your Organization From Social Engineering Attacks
CYBERSECURITY
The Rise of Advanced Passwordless Authentication
A Spotlight on the Transition from Traditional Authentication to Passwordless Authentication Methods
Featured Spotlight on Token Due Diligence
DIGITAL ASSETS
The Key Aspects of Conducting Token Due Diligence
Conducting thorough token due diligence (TDD) involves a deep dive beyond just analyzing historical data or predictions. Rather, it means exploring the intricacies of technology, evaluating security measures, understanding liquidity factors, navigating complex regulations, and more. Moreover, TDD encompasses a range of factors, including regulatory compliance, technological stability, and market behavior, to ensure that the token aligns with legal and financial standards.
The Howey Test, established by the US Supreme Court, is crucial in determining whether a digital asset qualifies as a security. This test is essential for TDD as it helps identify the regulatory requirements applicable to the digital asset, influencing how it can be legally offered and sold.
415.352.1060 2193 Fillmore Street, Suite 1
San Francisco, CA 94115
RISK | STRATEGY | CYBER COMPLIANCE MANAGEMENT
© 2024 Stratis Advisory LLC. All Rights Reserved.
Terms of Use | Privacy Policy