What is the main purpose of client authentication?
To determine whether we are speaking with the actual client and to help prevent fraud.
If all accounts have the same verbal password, what must you ask for?
The verbal password
What team must remediate a locked Voice ID before assisting the client?
CSaP
When should the Word of the Day be given?
Only if asked, and only in appropriate internal caller authentication situations.
What must be verified at the beginning of the call before moving forward?
The client’s first and last name
How many KBQ responses are required to pass authentication?
Two correct List A verifiers and one correct List B verifier.
If a client is not "person known to me" authenticated, what step comes next?
Verbal Password
What should happen if NPI is sent through the wrong channel or to the wrong client?
Immediately report it via the Data Incident Reporting Tool and notify a supervisor.
What should you do if Business Judgment creates uncertainty about the caller’s identity?
Revoke authentication and continue with appropriate authentication or escalation steps.
What is the expected range for the Approximate Account Value List B verifier?
Within 10% of the actual account value.
Which primary method sends a push notification to the Schwab mobile app?
Mobile Notification
What must be done before beginning a co-browse session?
Authenticate the client and ensure the session is for Schwab-related business only.
Name one situation where authentication is not required.
General, non-specific information; or view-only roles obtaining information about the account.
When should LexisNexis Out-of-Wallet be used?
When callers cannot verify with primary authentication and there are no significant red flags.
Before sending SMS verification, what must the client provide?
The full phone number on file; we should not confirm the number we have on file.
Name one thing employees should NOT include in their email signature.
The Own Your Tomorrow tagline, customized font/color, the Charles Schwab logo or other images, or stylized company name.
For High Risk Fraud Flags, how many forms of authentication are required? And what are they?
Two forms of authentication.
If a caller fails one factor on a High Risk Fraud Flag, what must be done?
Add an OA lock, submit an incident report, require a branch visit or NLOA, and add a permanent note.
What are the two authentication buckets used for high-risk situations?
Something they have and something they know.
When asking Steve for an exception should you give it to him in ET or MST?
No one knows