Block Compliance / Risk Analyst Interview Questions
30 real practice questions for the mid-level Compliance / Risk Analyst role at Block (Fintech/Payments), spanning behavioral, problem solving, role knowledge, situational, and stakeholder. Assess regulatory, fraud, and trust risk: monitor patterns, investigate cases, and make defensible judgment calls. The first 3 questions below include what Block interviewers actually listen for, plus likely follow-ups.
- Questions
- 30
- Categories
- Behavioral (6), Problem Solving (6), Role Knowledge (6), Situational (6), Stakeholder (6)
- Difficulty mix
- 10 easy · 10 medium · 10 hard
- Avg. answer time
- ~4 min
Behavioral Questions (6)
1.Square serves both the seller running a food truck and the customer tapping their card to pay. Tell me about a compliance rule or policy you enforced that protected one side of that equation — and how you made sure it didn't create an unfair burden on the other.
easy~3 minWhat interviewers look for
- Candidate explicitly named who bore the cost of the compliance requirement — the seller, the consumer, or both — and showed awareness of that tension rather than treating compliance as a one-sided obligation.
- Candidate adjusted how the policy was communicated or implemented to reduce friction for the disadvantaged party, not just checked a legal box.
- Candidate referenced any data, feedback, or signal they used to validate that the adjustment actually worked for both sides.
Likely follow-ups
- If you had to quantify the burden your enforcement created for sellers or consumers, what would that number be and how did you arrive at it?
- Did anyone — a seller, a product team, a consumer advocate — push back on your call? How did you handle that?
Company context
Block's Square ecosystem is a two-sided marketplace: sellers need frictionless tools to run their businesses, and consumers need to trust that the platform protects them from fraud and misuse. A Compliance Analyst at Block must hold both populations in mind simultaneously, which directly reflects Block's Seller and Consumer Reasoning leadership principle. Analysts who only enforce rules without modeling second-order effects on the other side create churn or liability.
2.Walk me through a time you caught a financial discrepancy or reconciliation error in a payments or ledger context. How did you identify the root cause and what did you do to make sure it couldn't happen again?
easy~3 minWhat interviewers look for
- Candidate describes a specific, real discrepancy — not a vague 'balancing issue' — including the dollar magnitude or transaction volume affected, showing they understand the stakes of money-movement correctness.
- Candidate explains how they traced the error to its origin, distinguishing between a data issue, a process gap, or a system failure rather than treating all three identically.
- Candidate proposed or implemented a durable fix — a control, an alert, a reconciliation check — rather than just correcting the one instance.
- Candidate flagged the issue proactively to relevant stakeholders rather than waiting to be asked.
Likely follow-ups
- How long did the discrepancy exist before you found it, and what does that tell you about the monitoring in place at the time?
- If the same error pattern occurred across thousands of transactions simultaneously — as it might at Cash App's transaction volume — how would your investigation approach change?
Company context
Block moves billions of dollars daily across Square, Cash App, and Square Banking. Money Movement Correctness is a foundational leadership principle at Block: errors in ledger entries, duplicate charges, or unreconciled float are not just operational problems — they erode trust with sellers and consumers and can trigger regulatory scrutiny. A Compliance Analyst must treat every discrepancy as a signal worth investigating fully, not just correcting.
3.Crypto and Bitcoin regulations have shifted dramatically — FinCEN guidance, travel rule implementation, shifting state-level MSB requirements. Tell me about a time you had to update a compliance framework or policy because the regulatory ground moved under you. What broke first, and how did you adapt?
medium~4 minWhat interviewers look for
- Candidate identifies the specific regulatory change — not just 'regulations changed' — and explains how they learned about it before or after it affected operations, signaling how they monitor evolving standards.
- Candidate describes what part of their existing framework was rendered incomplete or non-compliant first, showing they understand the structure of their own controls well enough to diagnose breakage.
- Candidate explains how they communicated urgency and scope of the change to product, legal, or engineering stakeholders — not just updated a policy document in isolation.
- Candidate reflects on what monitoring or early-warning mechanism they put in place afterward so the next regulatory shift would be detected earlier.
Likely follow-ups
- When you briefed leadership on the gap, what did you recommend as the risk-acceptable interim state while the full fix was built?
- Block's Cash App touches Bitcoin transactions at scale — if a new FinCEN rule required real-time transaction monitoring for crypto transfers above a threshold, where would you start scoping the compliance impact?
Company context
Block's vision explicitly includes Bitcoin and open financial protocols, and Cash App is one of the largest retail Bitcoin platforms in the US. Block's Bitcoin and Open Protocols principle means that compliance analysts working at Block must be comfortable reasoning about evolving, sometimes ambiguous regulatory frameworks — not just stable, codified rules. The travel rule, blockchain analytics requirements, and shifting MSB licensing are live compliance challenges at Block today.
4.Square's hardware — Readers, Terminals, Registers — sits in merchants' stores processing real transactions. If you were reviewing a compliance risk scenario where a firmware vulnerability in Square Reader could expose cardholder data, how would you approach the risk assessment, and who would you loop in first?
medium~4 min5.Cash App's customer base skews younger and includes a lot of people who are new to formal banking. Tell me about a time you pushed back on a product or policy decision because you believed it would create compliance risk for a customer segment that lacked the financial literacy to protect themselves.
hard~5 min6.Square Banking offers loans and instant transfers to sellers based on their sales history. Tell me about the hardest compliance or risk call you've made when a financial product's eligibility rules were leaving out a segment of legitimate users — and what you did about it.
hard~5 min
Problem Solving Questions (6)
7.Square processes payments for hundreds of thousands of small businesses. If you had to estimate the annual dollar value of chargebacks Block absorbs across the Square seller ecosystem, how would you approach that?
easy~3 min8.Cash App has tens of millions of active users. Walk me through how you'd estimate the number of Cash App accounts that should be flagged for enhanced due diligence under BSA rules at any given time.
easy~3 min9.Square launched a buy-now-pay-later product called Afterpay. Walk me through how you'd assess the incremental compliance risk that BNPL adds to Square's existing merchant compliance program.
medium~4 min10.You're reviewing Cash App's peer-to-peer transaction data and you notice that a cohort of accounts shows a sudden 300% increase in inbound transaction volume over a 10-day window, all from accounts that were created within the last 30 days. The aggregate dollar amount is significant but each individual transaction is under $200. How do you analyze this and decide what to do?
medium~5 min11.Square is entering the restaurant payroll space — helping sellers pay employees directly through Square Banking. A civil rights organization sends Block a letter claiming that Square's payroll product underserves tipped workers, who are disproportionately workers of color, because the product doesn't support tip pooling arrangements that comply with state law variations. The letter doesn't allege a specific legal violation but signals they're watching. How do you respond and what do you investigate?
hard~5 min12.Block is exploring a partnership with a large international remittance corridor — say, U.S. to Nigeria — that would route transfers through Cash App. The business case is strong and the partnership team has been working it for six months. You're brought in at the term sheet stage and immediately see that Nigeria is on FinCEN's list of jurisdictions with significant AML deficiencies. How do you proceed, and what does your risk assessment actually look like?
hard~5 min
Role Knowledge Questions (6)
13.Walk me through how you conduct a BSA/AML transaction monitoring review. What thresholds or patterns are you tuning for, and how do you decide when something warrants a SAR?
easy~3 min14.You're onboarding a new category of seller onto Square — say, cannabis-adjacent businesses like CBD retailers. How do you assess the compliance risk, and what does your merchant underwriting checklist look like?
easy~3 min15.Cash App had to deal with significant scrutiny over peer-to-peer payment fraud and account takeover. If you inherited a P2P fraud risk program that was catching 60% of fraud losses but generating a 40% false positive rate on legitimate users, where would you start to improve it?
medium~4 min16.Square Banking extends credit to sellers based on their payment processing history. Tell me how you'd build a risk-tiering model for a loan product that needs to comply with fair lending laws — specifically, how do you test it for disparate impact?
medium~5 min17.OFAC sanctions screening in a real-time P2P payment product like Cash App is genuinely hard — you have milliseconds to screen against a list that changes daily. Walk me through how you'd design a sanctions compliance program for a product at that scale, and where the failure modes are.
hard~5 min18.You discover that Cash App's KYC verification rates differ significantly by geography — users in certain zip codes are failing identity verification at 3x the baseline rate. Regulators haven't flagged it yet, but you think it's a problem. How do you investigate it and what do you do if the data confirms it's a real disparity?
hard~5 min
Situational Questions (6)
19.A small business owner using Square Point of Sale calls your compliance hotline frustrated — their account was flagged and funds held because our automated system misidentified their landscaping business as high-risk. They have payroll due tomorrow. How do you handle it?
easy~3 min20.You're reviewing Cash App's monthly transaction monitoring reports and notice a spike in structuring patterns — multiple users splitting deposits just under $10,000 across a two-week window. The volume is high enough that manually reviewing every account isn't realistic. How do you prioritize?
easy~3 min21.You're three weeks from launching a new Cash App feature that lets users send money internationally to Mexico and the Philippines. Legal has signed off, but you've just identified that your third-party identity verification vendor doesn't support document types commonly used by immigrant users from those regions. The product team says slipping the launch isn't an option. What do you do?
medium~4 min22.Square is expanding into a new vertical — short-term vacation rental operators who use Square to collect payments from guests. Your data shows this merchant category has a 4x higher chargeback rate than average, but it's also one of Square's fastest-growing segments. How do you build the risk framework for onboarding and ongoing monitoring?
medium~4 min23.A state financial regulator sends Square a formal examination request covering the last 18 months of merchant dispute resolution records. Two days in, you discover that a reporting process change six months ago accidentally excluded a category of dispute resolutions from the records you've already submitted. What do you do?
hard~5 min24.Cash App is piloting a feature that uses behavioral biometrics — typing cadence, scroll patterns — to flag potentially compromised accounts in real time. The data science team says it reduces account takeover by 35%, but your review shows the model's false positive rate is significantly higher for users with motor disabilities or older users unfamiliar with smartphone interfaces. The pilot is a week from going company-wide. What do you do?
hard~5 min
Stakeholder Questions (6)
25.Tell me about a time you had to explain a compliance requirement to a sales or business development team that pushed back hard. How did you hold the line without killing the relationship?
easy~3 min26.Describe a time you were the only person in the room — or on a project — who actually understood the compliance angle. How did you make sure the right people got the right information without overwhelming them?
easy~3 min27.Tell me about a time you disagreed with a legal or senior compliance colleague on how to handle a regulatory risk — and you turned out to be right, or at least made a strong enough case that it changed the outcome.
medium~4 min28.You've completed a risk assessment that recommends pulling back on a feature that a VP is publicly championing. Your manager supports your finding but doesn't want to be the one to deliver it. How do you handle it?
medium~4 min29.A product team is three sprints into building a new Square Banking feature and just looped you in for the first time. You immediately spot two significant compliance gaps that will require redesign. The PM says rework at this stage isn't in the plan. Walk me through exactly what you do in the next 48 hours.
hard~5 min30.Tell me about a time you were working on a compliance or risk issue that touched multiple teams — legal, finance, product, operations — and those teams had genuinely different views on what the right answer was. How did you drive to a decision?
hard~5 min
More Block interview questions
- Account Executive30 questions
- Customer Success Manager30 questions
- Data Scientist15 questions
- DevOps / SRE15 questions
- Engineering Manager15 questions
- Financial Analyst30 questions
- Marketing Manager30 questions
- Product Manager15 questions
- Program / Project Manager30 questions
- Recruiter30 questions
- Sales Development Representative (SDR/BDR)30 questions
- Senior Software Engineer15 questions
- Software Engineer15 questions
- Staff Software Engineer15 questions