Threshold MLO Prep NMLS SAFE MLO Test Prep

Privacy, Credit Reporting, AML & Other Federal Law: practice questions

Module 05 of 15 · Federal mortgage-related laws (24% of the NMLS SAFE MLO Test)
Content last updated 23 September 2026

About this module

NMLS weights federal mortgage-related laws at 24% of the 115 scored questions. NMLS does not publish weights below that level, so our exam-length mix gives this module 8 of the 115, in proportion to its share of the outline topics in that area (outline section 1.E-F).

The full bank holds 42 questions for this module, each with a written explanation that cites its source. Below are the 8 free questions for this module, with answers.

Key sources

The law and guidance the questions in this module cite most often.

Free Privacy, Credit Reporting, AML & Other Federal Law questions

A lender wants to sell customers' nonpublic personal information to an unaffiliated marketing firm. Under Regulation P, what must happen first?

  1. Written consent signed by every customer involved
  2. Approval of the sale by the lender's regulator
  3. Nothing, if the data exclude account numbers
  4. Notices, a chance to opt out, and no opt-out ✓

Why: 12 CFR 1016.10(a)(1) bars disclosing nonpublic personal information to a nonaffiliated third party unless the institution has given the initial notice and an opt-out notice, given a reasonable opportunity to opt out before disclosure, and the consumer has not opted out. It is an opt-out regime, not opt-in consent.

Source: 12 CFR 1016.10(a)(1)

A non-bank residential mortgage lender is a "loan or finance company" under FinCEN's rules. What must its anti-money laundering program be?

  1. Filed with FinCEN and approved by it before use
  2. Written and approved by senior management ✓
  3. Oral, provided every employee is trained in it
  4. Optional, if the company takes no cash payments

Why: 31 CFR 1029.210(a) requires each loan or finance company to develop and implement a written anti-money laundering program reasonably designed to prevent it being used to facilitate money laundering or terrorist financing, approved by senior management and available to FinCEN on request. The program is based on the company's own risk assessment (1029.210(b)(1)).

Source: 31 CFR 1029.210(a)

Which of these is one of the purposes of HMDA data as Regulation C states them?

  1. To help identify possible discriminatory lending patterns ✓
  2. To set the maximum rate a lender may charge in each census tract
  3. To tell lenders which census tracts they must lend in
  4. To give each applicant a free credit score after denial

Why: 12 CFR 1003.1(b)(1) says HMDA is intended to provide public loan data to help determine whether institutions are serving their communities' housing needs, to help public officials target public investment, and "to assist in identifying possible discriminatory lending patterns and enforcing antidiscrimination statutes". 1003.1(b)(2) adds that it is not intended to encourage unsound lending or the allocation of credit.

Source: 12 CFR 1003.1(b)

What does 12 U.S.C. 5511 give as the CFPB's purpose?

  1. Setting interest rates for all consumer mortgage loans
  2. Insuring deposits at banks and credit unions nationwide
  3. Licensing every mortgage loan originator in each of the states
  4. Consumer access to fair, transparent, competitive markets ✓

Why: 12 U.S.C. 5511(a) directs the Bureau to implement and enforce Federal consumer financial law consistently "for the purpose of ensuring that all consumers have access to markets for consumer financial products and services and that markets ... are fair, transparent, and competitive". States license originators under the SAFE Act.

Source: 12 U.S.C. 5511(a)

When must a mortgage lender give a new customer its initial privacy notice under Regulation P?

  1. Within 30 days after the loan has been closed
  2. No later than when the relationship begins ✓
  3. Only before it shares information with an affiliate
  4. Only if the customer asks for its privacy policy

Why: 12 CFR 1016.4(a)(1) requires a clear and conspicuous notice accurately reflecting the institution's privacy policies to an individual who becomes a customer, not later than when the customer relationship is established (subject to the exceptions in 1016.4(e)).

Source: 12 CFR 1016.4(a)(1)

Under the FTC Safeguards Rule, what is the first element of an information security program?

  1. Buying cyber insurance for customers' losses
  2. Designating a Qualified Individual ✓
  3. Encrypting every paper file kept in the office
  4. Registering the program with the FTC each year

Why: 16 CFR 314.4(a) requires designating a Qualified Individual responsible for overseeing, implementing and enforcing the information security program; the individual may be employed by the institution, an affiliate or a service provider, but the institution keeps responsibility for compliance.

Source: 16 CFR 314.4(a)

A mortgage ad uses a logo resembling a federal agency's seal and says the loan is "part of a government relief program", which it is not. How does Regulation N treat it?

  1. Lawful, provided the ad also carries the company's NMLS ID number
  2. Lawful, if the loan meets the agency's own guidelines
  3. A matter only for trademark law, not for Regulation N
  4. A prohibited misrepresentation of government affiliation ✓

Why: 12 CFR 1014.3(n) prohibits misrepresenting the association of a mortgage product or provider with any other person or program, including that the provider is affiliated with a governmental entity or that the product is a government benefit, "including ... through the use of formats, symbols, or logos that resemble those of such entity".

Source: 12 CFR 1014.3(n)

Under the FTC's Red Flags Rule, what must a creditor with covered accounts develop and implement?

  1. An annual audit of every customer's identity
  2. A fraud insurance policy for customer losses
  3. A written Identity Theft Prevention Program ✓
  4. A daily check of each borrower's credit file

Why: 16 CFR 681.1(d)(1) requires each financial institution or creditor offering or maintaining covered accounts to develop and implement a written Identity Theft Prevention Program designed to detect, prevent and mitigate identity theft in connection with opening or maintaining covered accounts, appropriate to its size and complexity.

Source: 16 CFR 681.1(d)(1)