Intervu is in beta — feedback welcome at support@intervu.io

Stripe Compliance / Risk Analyst Interview Questions

30 real practice questions for the mid-level Compliance / Risk Analyst role at Stripe (Fintech), spanning behavioral, problem solving, role knowledge, situational, and stakeholder. Assess regulatory, fraud, and trust risk: monitor patterns, investigate cases, and make defensible judgment calls. The first 3 questions below include what Stripe interviewers actually listen for, plus likely follow-ups.

Questions
30
Categories
Behavioral (6), Problem Solving (6), Role Knowledge (6), Situational (6), Stakeholder (6)
Difficulty mix
10 easy · 10 medium · 10 hard
Avg. answer time
~4 min

Behavioral Questions (6)

  1. 1.Tell me about a time you had to explain a compliance requirement — like KYC, AML, or sanctions screening — to a technical team building a product feature. How did you make sure they actually understood what mattered and why?

    easy~3 min

    What interviewers look for

    • Translated regulatory obligations into specific, actionable requirements that engineers could implement — not just policy language
    • Understood the technical constraints well enough to meet the engineer where they were, rather than just issuing a mandate
    • Followed up after the conversation to verify implementation matched intent, closing the loop on the communication

    Likely follow-ups

    • What was the most common misunderstanding you ran into, and how did you correct it?
    • If the engineers pushed back on the requirement as impractical, how did you handle that?

    Company context

    Stripe's primary users are developers, and its compliance team works directly alongside engineering to ship products like Stripe Radar and Stripe Connect. Stripe's 'Users Are Developers' principle means compliance analysts are expected to bridge regulatory language and technical implementation — not treat them as separate worlds. Analysts who can speak the language of engineers are far more effective at Stripe than those who simply issue policy memos.

  2. 2.Tell me about a time a regulator, auditor, or senior stakeholder asked you a question about a compliance or risk matter where you genuinely didn't know the answer. What did you say in the moment, and how did you follow up?

    easy~3 min

    What interviewers look for

    • Said 'I don't know' clearly and without deflection — did not bluff, speculate without flagging it as speculation, or deflect to process
    • Immediately offered a concrete plan for how they would find the answer — a specific source, person, or timeline
    • Followed through on the commitment and closed the loop with the original asker within the timeframe promised

    Likely follow-ups

    • Did you feel any pressure to give an answer anyway? How did you manage that?
    • What did you learn from the process of finding the answer that you didn't expect to learn?

    Company context

    Stripe's 'Intellectual Honesty' principle is one of the most culturally important at the company — interviewers are specifically trained to probe for reasoning, not just conclusions, and to reward candidates who say 'I don't know, but here's how I'd find out.' In compliance, where incorrect guidance can create regulatory exposure or financial risk, bluffing is a far worse outcome than admitting a gap. Stripe wants analysts who build trust through transparency, not confidence theater.

  3. 3.Describe a risk assessment or compliance review where you had to make a judgment call between doing it perfectly and doing it fast enough to keep a business decision moving. What did you do, and what would you do differently?

    medium~4 min

    What interviewers look for

    • Explicitly articulated the trade-off — named what completeness was sacrificed and why, rather than just defaulting to speed or defaulting to caution
    • Used a structured method to scope what was 'good enough' — e.g., risk tiering, materiality thresholds, or a documented assumption log
    • Reflected honestly on whether the call was right in hindsight, not just whether things turned out fine

    Likely follow-ups

    • What criteria did you use to decide which parts of the review could be deferred versus which were non-negotiable?
    • How did you communicate the residual risk to stakeholders who might not have known the review was incomplete?

    Company context

    Stripe's 'Rigor Without Rigidity' principle is central to how the compliance function operates at a company that ships fast and serves hundreds of thousands of developers. Stripe processes trillions in payments annually and can't afford compliance reviews that become blockers — but also can't afford ones that miss material risk. Mid-level analysts are expected to own the judgment call, not escalate every ambiguous trade-off upward.

  4. 4.Tell me about a time you wrote a compliance policy, risk memo, or regulatory guidance document that had to land with a non-compliance audience — maybe legal, product, or finance. How did you structure it, and how did you know it worked?

    medium~4 min
  5. 5.Walk me through a time you designed or significantly revised a compliance control or onboarding requirement that a developer or technical team had to implement. How did you balance what the regulation required with what was actually buildable?

    hard~5 min
  6. 6.Describe a situation where you were asked to do a thorough risk review — sanctions, credit, fraud, whatever — but the timeline or resources made that impossible. How did you scope it, and how did you defend what you left out?

    hard~5 min

Problem Solving Questions (6)

  1. 7.Estimate how many Stripe merchants you'd expect to have active sanctions exposure at any given time. Walk me through your assumptions.

    easy~3 min
  2. 8.Your chargeback data shows that merchants in a specific Stripe Connect vertical — say, online ticketing platforms — have a dispute rate three times the network average. How do you decide whether this is a fraud problem, a product problem, or a customer service problem?

    easy~3 min
  3. 9.Stripe is expanding a product into a market where your transaction monitoring system wasn't built — you're covering it manually with a two-person team and 90-day transaction data. The team flags 40 accounts a week for review but has capacity to fully investigate only 15. How do you decide which 15 to work?

    medium~4 min
  4. 10.A Stripe Radar rule you inherited from a prior analyst is suppressing around 8,000 transactions a month in a specific merchant category. No one has reviewed the rule in 14 months. How do you figure out whether it's still doing the right thing?

    medium~4 min
  5. 11.You're building the risk appetite framework for Stripe Treasury's end-user segment — the customers of platforms that have embedded Treasury accounts. Regulators are asking you to define acceptable risk thresholds before the product scales. Where do you start, and what does a finished framework actually look like?

    hard~5 min
  6. 12.A Connect platform with $200M in annualized GMV is failing a periodic review — their sub-merchant onboarding documentation is materially out of compliance, but off-boarding them would likely trigger a wave of sub-merchant chargebacks and news coverage. How do you make this call?

    hard~5 min

Role Knowledge Questions (6)

  1. 13.Walk me through how you'd investigate a spike in Stripe Radar false positives — say, a 15% jump in legitimate transactions being blocked. Where do you start?

    easy~3 min
  2. 14.How do you perform a risk-tiering exercise on a new merchant segment — say, platforms using Stripe Connect to onboard sub-merchants in a high-risk vertical like crypto or firearms? What factors drive your tier assignment?

    easy~3 min
  3. 15.Stripe Billing handles recurring revenue for thousands of SaaS and subscription businesses. How would you design a monitoring program to catch billing-related fraud or compliance violations at scale — and what metrics would you track to know the program is actually working?

    medium~4 min
  4. 16.You're doing enhanced due diligence on a business applying through Stripe Atlas. It's a Delaware C-corp, clean incorporation docs, but the beneficial owner's source-of-funds documentation is inconsistent — the stated capital is $500K but their supporting bank statements show a balance of $12K. How do you work this?

    medium~4 min
  5. 17.Stripe Treasury lets platforms offer banking-as-a-service to their own customers. If a Treasury partner's end users start showing patterns consistent with structuring — say, a cluster of $9,800 transfers over 90 days — how do you conduct that investigation and what's your decision framework for filing?

    hard~5 min
  6. 18.A product team wants to expand Stripe Payments into a new market where the local AML regime is materially weaker than FATF standards and there's no national beneficial ownership registry. You've been asked to write a market entry risk assessment. How do you structure it and what would need to be true for you to recommend against entry?

    hard~5 min

Situational Questions (6)

  1. 19.A small merchant on Stripe Payments calls in upset — their account was flagged and payouts are on hold. You pull the file and see it's a legitimate-looking e-commerce business, but there's a chargeback rate nudging 1.8% over the last 30 days. How do you handle it?

    easy~3 min
  2. 20.You're reviewing a batch of new Connect platform applications and you notice several are structurally similar — same registered agent, overlapping director names, slightly different business names. None of them individually trip your automated flags. What do you do?

    easy~3 min
  3. 21.A sales team lead pushes back hard on a KYB requirement you added to the Connect onboarding flow — they say it's killing conversion for a high-value platform prospect and want an exception for 30 days while the prospect 'sorts out their docs.' How do you respond?

    medium~4 min
  4. 22.You're reviewing Stripe Radar model outputs and notice a specific merchant category — online pharmacies — has an unusually high block rate for transactions that are later manually approved. Your fraud team says the model is working as intended. What do you do with that information?

    medium~4 min
  5. 23.A law enforcement agency sends Stripe a grand jury subpoena for transaction records on five merchants, with a non-disclosure order prohibiting you from telling the merchants. Two of the five are currently in active remediation conversations with your team — you were supposed to meet with them this week. What do you do?

    hard~5 min
  6. 24.You discover that a compliance control your team has been relying on for 18 months — a third-party sanctions screening vendor — has been running on a stale watchlist that was last updated four months ago. During that window, Stripe onboarded approximately 3,000 new merchants. What do you do in the next 24 hours?

    hard~5 min

Stakeholder Questions (6)

  1. 25.Tell me about a time a product or engineering team pushed back on a compliance requirement you owned. How did you get them to move without having any direct authority over them?

    easy~3 min
  2. 26.Walk me through a time you had to keep multiple stakeholders — say legal, product, and a business team — aligned on a compliance decision that kept evolving as new information came in. How did you manage the communication?

    easy~3 min
  3. 27.You're the compliance lead on a new Stripe product feature, and the launch is two weeks out. Legal says they need another week for their review. Product is telling you legal is being too slow and wants to know if compliance can sign off independently. How do you handle it?

    medium~4 min
  4. 28.Describe a time you had to present a compliance risk finding to a senior leader or executive who had a clear business interest in you reaching the opposite conclusion. How did you prepare, and how did the conversation go?

    medium~4 min
  5. 29.You're the compliance point of contact for a strategic Connect platform partner — a large marketplace — and their CEO emails your executive sponsor directly to complain that your due diligence process is too slow and threatening their launch. Your exec forwards it to you and says 'can you fix this.' What do you do?

    hard~5 min
  6. 30.You've been running a cross-functional working group — compliance, product, finance, and legal — to overhaul Stripe's risk appetite framework for a specific merchant vertical. Six weeks in, the group is stuck: product wants higher risk tolerance to capture market share, finance is worried about loss reserves, and legal is noncommittal. You have no authority to force a decision. How do you break the deadlock?

    hard~5 min

More Stripe interview questions