Intervu is in beta — feedback welcome at support@intervu.io

Meta Compliance / Risk Analyst Interview Questions

30 real practice questions for the mid-level Compliance / Risk Analyst role at Meta (Technology), spanning behavioral, problem solving, role knowledge, situational, and stakeholder. Assess regulatory, fraud, and trust risk: monitor patterns, investigate cases, and make defensible judgment calls. The first 3 questions below include what Meta interviewers actually listen for, plus likely follow-ups.

Questions
30
Categories
Behavioral (6), Problem Solving (6), Role Knowledge (6), Situational (6), Stakeholder (6)
Difficulty mix
10 easy · 10 medium · 10 hard
Avg. answer time
~4 min

Behavioral Questions (6)

  1. 1.Tell me about a compliance control or risk framework you had to stand up quickly — maybe under regulatory pressure or ahead of a product launch. How did you ship it and what did you fix afterward?

    easy~3 min

    What interviewers look for

    • Candidate shipped a working MVP of the control or framework rather than waiting for a perfect solution — shows Move Fast instinct in a compliance context
    • Candidate identified specific gaps after go-live and iterated with a defined v2 plan, not just vague promises to improve
    • Candidate proactively communicated the known limitations of the initial version to stakeholders so decisions were made with full context

    Likely follow-ups

    • What corners did you consciously cut in v1, and how did you decide those were acceptable risks?
    • How did the feedback loop work — who flagged the gaps and how quickly did you act on them?

    Company context

    Meta's Move Fast principle is not just an engineering value — it applies directly to Compliance and Risk, where teams must build guardrails that keep pace with rapid product launches across Facebook, Instagram, and WhatsApp. A mid-level Compliance Analyst who defaults to slow, exhaustive frameworks before shipping anything will become a bottleneck. Meta wants to see evidence that candidates can deliver a functional control quickly, communicate its limitations openly, and improve iteratively.

  2. 2.Tell me about a time you delivered feedback to a business partner — maybe a product or engineering team — that they didn't want to hear. How did you handle it, and what was the outcome?

    easy~3 min

    What interviewers look for

    • Candidate delivered the difficult finding directly and in a timely way — did not soften it to the point of losing the core message
    • Candidate framed the feedback in terms of risk impact and business consequences, not just compliance rules, so the partner understood why it mattered
    • Candidate followed up after delivery to make sure the message landed and the partner had what they needed to act on it

    Likely follow-ups

    • How did you decide the right moment and channel to deliver the feedback — email, in-person, in a group review?
    • If the partner pushed back and said your finding was wrong, how did you respond?

    Company context

    Meta's Be Open principle holds that informed people make better decisions — and in compliance, that means business partners need to hear hard findings clearly, not buried in qualifications. A mid-level Compliance Analyst at Meta regularly interfaces with product, engineering, and policy teams building products like Facebook and Instagram at scale. The ability to deliver uncomfortable risk findings directly — without hedging them into uselessness — is core to the job and to Meta's culture of transparency.

  3. 3.Tell me about a time you pushed for a risk or compliance approach that your manager or legal team pushed back on. What made you confident enough to advocate for it, and what happened?

    medium~4 min

    What interviewers look for

    • Candidate had a clear, data-backed rationale for their position — not just intuition — and was willing to defend it even against authority
    • Candidate distinguished between principled disagreement and stubbornness — they either won the argument with evidence or updated their view based on new information
    • Candidate framed their bold position in terms of long-term risk reduction or business impact, not personal preference
    • Candidate shows comfort with the outcome even if it did not go their way, because they advocated clearly and transparently

    Likely follow-ups

    • At what point did you decide the pushback was legitimate and you should update your view versus hold your ground?
    • How did the relationship with that manager or legal team evolve after the disagreement?

    Company context

    Meta's Be Bold principle explicitly states that the biggest risk is taking no risk. In a Compliance and Risk function, the temptation is to default to the most conservative possible position to avoid any accountability. Meta needs analysts who will take a principled stand on risk posture — recommending a more nuanced or novel approach when the evidence supports it — even when institutional inertia or senior stakeholders resist. This question separates candidates who have genuine conviction from those who comply reflexively.

  4. 4.You've got a backlog of compliance projects and you can only move meaningfully on two of them this quarter. Walk me through how you decide which two.

    medium~4 min
  5. 5.Walk me through a compliance or risk project where you had to weigh the regulatory requirement against potential harm to users or communities — not just the company. How did you navigate that tension?

    hard~5 min
  6. 6.Describe a situation where you identified a compliance risk mid-way through a product launch and had 48 hours to resolve it. What did you do and what trade-offs did you make?

    hard~5 min

Problem Solving Questions (6)

  1. 7.Estimate how many advertiser accounts on Meta's platforms might realistically require enhanced due diligence reviews in a given year. Walk me through your assumptions.

    easy~3 min
  2. 8.A key compliance metric — say, the percentage of open policy violations closed within SLA — drops from 87% to 71% in a single quarter. Nothing obvious changed. How do you diagnose it?

    easy~3 min
  3. 9.Meta is considering whether to adopt a single global compliance risk appetite statement or maintain region-specific ones. What are the core trade-offs, and how would you recommend framing the decision?

    medium~4 min
  4. 10.Facebook's fraud detection model flags 2% of accounts as high-risk each month — that's roughly 60 million accounts globally. Walk me through how you'd evaluate whether that 2% threshold is set at the right level.

    medium~4 min
  5. 11.Meta is considering acquiring a fintech company that processes payments in 12 markets, including three where Meta has no existing regulatory presence. How do you structure the compliance due diligence?

    hard~5 min
  6. 12.Meta's data privacy team and the Instagram growth team have both escalated to you a dispute about whether a new re-engagement feature requires explicit user consent under applicable law. Each team has outside counsel that disagrees with the other. You have to make a call by end of week. How do you proceed?

    hard~5 min

Role Knowledge Questions (6)

  1. 13.Walk me through how you'd assess the compliance risk profile of a new ad targeting feature before it ships on Instagram or Facebook.

    easy~3 min
  2. 14.How do you monitor ongoing compliance of a control you've already implemented — what does your steady-state testing and reporting look like?

    easy~3 min
  3. 15.WhatsApp is expanding a payments feature into a new market. How would you build out the regulatory compliance mapping for that launch, and which jurisdictions would worry you most?

    medium~4 min
  4. 16.You're asked to rate the residual risk on a control that looks solid on paper but that you personally don't trust. How do you defend a rating that's higher than what the documentation suggests?

    medium~4 min
  5. 17.Meta is under a regulatory inquiry and the agency has issued a document preservation hold. Walk me through exactly how you'd execute that — what you do in the first 48 hours and what can go wrong.

    hard~5 min
  6. 18.You're analyzing Meta's third-party risk program and you notice a critical vendor — one that processes data for Instagram — hasn't had a compliance assessment in 18 months and has recently had a publicized data breach at another client. How do you triage and respond?

    hard~5 min

Situational Questions (6)

  1. 19.A product team asks you to sign off on a minor UX change to Facebook's data settings page before their sprint closes tomorrow. You have 30 minutes to review it. What do you do?

    easy~3 min
  2. 20.You're doing routine monitoring and you notice that an internal team has been sharing a sensitive compliance report — one that includes open regulatory findings — in a broad Workplace group instead of a restricted channel. It's been up for two weeks. How do you handle it?

    easy~3 min
  3. 21.Meta's ads team is about to launch a new automated bidding feature that uses inferred demographic signals. Legal says it's fine. Your read of the fair lending and civil rights advertising consent decrees suggests there's a real residual risk they may be underweighting. How do you proceed?

    medium~4 min
  4. 22.You're supporting a cross-functional review of Meta's AI-driven content moderation system and you're asked to assess its compliance risk profile. The engineering team says the model outputs are 'probabilistic' and therefore can't be mapped to specific regulatory obligations. How do you respond?

    medium~4 min
  5. 23.A country manager in a Southeast Asian market tells you that local regulators are informally requesting access to WhatsApp user message metadata — not content — and that refusing will likely result in Meta losing its operating license in that country. No formal legal process has been issued. How do you handle it?

    hard~5 min
  6. 24.During a routine audit you discover that a Meta business unit has been self-certifying a key internal control as 'effective' for three consecutive quarters, but the underlying test evidence is missing for two of those periods. The control covers financial data used in external disclosures. What do you do?

    hard~5 min

Stakeholder Questions (6)

  1. 25.Tell me about a time a sales or business team wanted to move faster on a deal or launch than your compliance review allowed. How did you keep the relationship intact while holding the line?

    easy~3 min
  2. 26.Give me an example of a time you had to explain a complex compliance or regulatory requirement to a non-legal, non-compliance audience — maybe a product manager or an engineer. How did you make it land?

    easy~3 min
  3. 27.Tell me about a time you were the only person in the room — or on the thread — who thought a particular risk was real, and you had to convince a group of skeptics. How did you build the case?

    medium~4 min
  4. 28.Describe a time you had to align two internal teams — say legal and a product or engineering group — who had genuinely different interpretations of the same compliance requirement. How did you get them to a shared position?

    medium~4 min
  5. 29.Tell me about the most senior stakeholder you've had to push back on — someone who had real authority over your work or your team's roadmap. How did you frame the pushback, and what happened?

    hard~5 min
  6. 30.You discover that a business partner — say a monetization team running Facebook or Instagram ad products — has been consistently interpreting a privacy or data-use policy in a way that minimizes compliance burden but that you believe is wrong. They've been operating this way for over a year and it's baked into how their products work. How do you handle it?

    hard~5 min

More Meta interview questions