Voice ID & Primary Methods
Verbal Passwords, KBQs & OOW
Voice ID & Primary Methods
Internal & Client Communications
100

What is the main purpose of client authentication?

To determine whether we are speaking with the actual client and to help prevent fraud.

100

If all accounts have the same verbal password, what must you ask for?

The verbal password

100

What team must remediate a locked Voice ID before assisting the client?

CSaP

100

When should the Word of the Day be given?

Only if asked, and only in appropriate internal caller authentication situations.

200

What must be verified at the beginning of the call before moving forward?

The client’s first and last name

200

How many KBQ responses are required to pass authentication?

Two correct List A verifiers and one correct List B verifier.

200

If a client is not "person known to me" authenticated, what step comes next?

Verbal Password

200

What should happen if NPI is sent through the wrong channel or to the wrong client?

Immediately report it via the Data Incident Reporting Tool and notify a supervisor.

300

What should you do if Business Judgment creates uncertainty about the caller’s identity?

Revoke authentication and continue with appropriate authentication or escalation steps.

300

What is the expected range for the Approximate Account Value List B verifier?

Within 10% of the actual account value.

300

Which primary method sends a push notification to the Schwab mobile app?

Mobile Notification

300

What must be done before beginning a co-browse session?

Authenticate the client and ensure the session is for Schwab-related business only.

400

Name one situation where authentication is not required.

General, non-specific information; or view-only roles obtaining information about the account.

400

When should LexisNexis Out-of-Wallet be used?

When callers cannot verify with primary authentication and there are no significant red flags.

400

Before sending SMS verification, what must the client provide?

The full phone number on file; we should not confirm the number we have on file.

400

Name one thing employees should NOT include in their email signature.

The Own Your Tomorrow tagline, customized font/color, the Charles Schwab logo or other images, or stylized company name.

500

For High Risk Fraud Flags, how many forms of authentication are required? And what are they?

Two forms of authentication.

500

If a caller fails one factor on a High Risk Fraud Flag, what must be done?

Add an OA lock, submit an incident report, require a branch visit or NLOA, and add a permanent note.

500

What are the two authentication buckets used for high-risk situations?

Something they have and something they know.

500

When asking Steve for an exception should you give it to him in ET or MST?

No one knows 

M
e
n
u