ACAMS CAMS Certification Exam — Questions and Answers
Question 1: Which document provides the most authoritative assessment of a country's AML/CFT regime for use in geographic risk assessments?
- The CIA World Factbook
- FATF Mutual Evaluation Reports (MERs) (Correct answer)
- The Transparency International Corruption Perceptions Index
- The World Bank Doing Business report
Correct answer: FATF Mutual Evaluation Reports (MERs)
FATF Mutual Evaluation Reports provide the most comprehensive, authoritative assessment of a country's AML/CFT legal framework, institutional effectiveness, and compliance with FATF standards.
Question 2: What role does 'adverse media screening' play in an AML investigation?
- It screens marketing materials for compliance with advertising regulations
- It searches news databases and other public sources for negative information about a customer that may indicate financial crime, corruption, or sanctions exposure (Correct answer)
- It monitors social media for customer complaints about banking services
- It is used to identify positive press coverage about customers
Correct answer: It searches news databases and other public sources for negative information about a customer that may indicate financial crime, corruption, or sanctions exposure
Adverse media screening (also called negative news screening) searches public sources — news articles, court records, regulatory actions — for information that might indicate a customer poses elevated AML, sanctions, or reputational risk.
Question 3: What is the EU's Anti-Money Laundering Directive framework and what does the Sixth Anti-Money Laundering Directive (6AMLD) add?
- 6AMLD created the EU AML Authority (AMLA) to directly supervise financial institutions
- The EU AMLD framework is a voluntary guideline; 6AMLD made AML mandatory for EU members for the first time
- The EU AML Directives are binding regulations that EU member states must implement into national law; 6AMLD (2019) harmonized the definition of money laundering, created 22 predicate offenses, and introduced criminal liability for legal persons and stronger sanctions (Correct answer)
- The EU AMLD framework only applies to banks; 6AMLD extended it to DNFBPs for the first time
Correct answer: The EU AML Directives are binding regulations that EU member states must implement into national law; 6AMLD (2019) harmonized the definition of money laundering, created 22 predicate offenses, and introduced criminal liability for legal persons and stronger sanctions
The EU AML Directives are binding legal instruments requiring national implementation; 6AMLD harmonized the definition of ML across member states, established 22 standardized predicate offenses (including cybercrime and environmental crime), and introduced criminal liability for legal persons along with stronger sanctions including imprisonment.
Question 4: A bank determines that a new customer relationship presents a low risk of money laundering or terrorist financing. Under a risk-based approach, which level of due diligence would be most appropriate to apply at the start of the relationship?
- No due diligence is required for low-risk customers.
- Simplified Due Diligence (SDD) (Correct answer)
- Standard Customer Due Diligence (CDD)
- Enhanced Due Diligence (EDD)
Correct answer: Simplified Due Diligence (SDD)
Simplified Due Diligence (SDD) is a streamlined approach to CDD that is permitted when the risk of money laundering or terrorist financing is assessed as low. It allows for less intensive verification and monitoring measures but still requires the core components of CDD to be met. Standard CDD is for normal-risk customers, and Enhanced Due Diligence (EDD) is for high-risk customers.
Question 5: How should a financial institution adjust its risk assessment when onboarding a new product line involving cryptocurrency?
- Risk assessments only need updating every five years under BSA rules
- The risk assessment should be updated to reflect the new risks associated with cryptocurrency, including anonymity, transaction speed, and cross-border movement (Correct answer)
- No adjustment needed since cryptocurrency is regulated the same as cash
- The institution should simply add all crypto customers to low-risk tiers
Correct answer: The risk assessment should be updated to reflect the new risks associated with cryptocurrency, including anonymity, transaction speed, and cross-border movement
Adding cryptocurrency services introduces new and unique AML risks — including enhanced anonymity through mixing services, rapid cross-border value transfer, and the complexity of blockchain forensics — requiring an updated risk assessment.
Question 6: How does 'machine learning' differ from rule-based transaction monitoring in detecting suspicious activity?
- Machine learning is less accurate than rules-based monitoring and is not used in AML
- Machine learning models can identify complex, non-linear patterns and previously unknown suspicious behaviors that may not be captured by predefined rules, using historical data to train models that evolve as patterns change (Correct answer)
- Machine learning eliminates the need for human review of transaction monitoring alerts
- Machine learning is only effective for detecting sanctions violations, not money laundering
Correct answer: Machine learning models can identify complex, non-linear patterns and previously unknown suspicious behaviors that may not be captured by predefined rules, using historical data to train models that evolve as patterns change
Machine learning can detect novel and complex patterns across large datasets that rule-based systems miss — learning from historical suspicious activity to identify similar but previously unknown behaviors, and adapting as criminal typologies evolve.
Question 7: An accounting company created a bank account that would serve as the business's operating account. After a few months, a thorough evaluation of the account was initiated owing to unexpected activities. Which most likely prompted the review?
- The account gets international wire transfers from corporations in the Middle East, where the accounting company has many offices.
- The account makes monthly payments to many organizations that serve the same neighborhoods as the accounting company. (Correct answer)
- Every day, the account gets various payments from consumers in a variety of businesses.
- The account gets overseas payments that are significantly greater than the customary fees.
Correct answer: The account makes monthly payments to many organizations that serve the same neighborhoods as the accounting company.
An accounting company's operating account making monthly payments to many organizations serving the same neighborhoods is highly unusual and a significant red flag. An operating account should primarily handle the company's own expenses and income, not disburse funds to numerous third-party organizations in a potentially unrelated manner. This pattern could indicate the account is being used for layering or integration of illicit funds, acting as a pass-through for money laundering.
Question 8: What are the 'five pillars' of an effective BSA/AML compliance program under U.S. federal requirements?
- Board oversight, senior management accountability, technology systems, legal review, and regulatory liaison
- Internal controls, a designated compliance officer, employee training, independent testing, and customer due diligence (Correct answer)
- Policies, procedures, internal controls, risk assessment, and training
- SAR filing, CTR filing, record retention, risk assessment, and OFAC screening
Correct answer: Internal controls, a designated compliance officer, employee training, independent testing, and customer due diligence
FinCEN and banking regulators require BSA/AML programs to have five pillars: (1) internal controls, (2) a designated BSA/AML compliance officer, (3) ongoing employee training, (4) independent testing/audit, and (5) customer due diligence (added as the fifth pillar by FinCEN's 2016 CDD Rule).
Question 9: What is 'behavioral analytics' in the context of AML transaction monitoring and how does it complement rule-based detection?
- Monitoring customer behavior on digital banking platforms to prevent account takeover fraud only
- Analyzing competitor bank behaviors to benchmark monitoring effectiveness
- Establishing baseline transaction profiles for individual customers or peer groups, then detecting deviations from those baselines that may indicate suspicious activity — complementing rules by catching gradual behavioral shifts that fall below fixed alert thresholds (Correct answer)
- Analyzing employee behavior to detect internal fraud by compliance staff
Correct answer: Establishing baseline transaction profiles for individual customers or peer groups, then detecting deviations from those baselines that may indicate suspicious activity — complementing rules by catching gradual behavioral shifts that fall below fixed alert thresholds
Behavioral analytics establishes normal transaction patterns for each customer or peer group and alerts on deviations — catching gradual escalations, low-and-slow structuring, and behavioral shifts that fixed-threshold rules may miss.
Question 10: What is the role of a Financial Intelligence Unit (FIU) in the national AML framework?
- FIUs receive, process, analyze, and disseminate financial intelligence (including SAR/STR reports) to competent authorities to support AML/CFT investigations and prosecutions (Correct answer)
- FIUs are law enforcement agencies that conduct criminal investigations and make arrests
- FIUs set national AML policy and issue binding regulations on financial institutions
- FIUs are regulatory bodies that license and supervise financial institutions
Correct answer: FIUs receive, process, analyze, and disseminate financial intelligence (including SAR/STR reports) to competent authorities to support AML/CFT investigations and prosecutions
Financial Intelligence Units are national agencies that collect financial intelligence (SAR/STR filings), analyze it for patterns and connections, and disseminate actionable intelligence to law enforcement, prosecutors, and foreign FIUs to support AML/CFT investigations.
Question 11: What is 'kidnapping for ransom' (KFR) as a terrorist financing method and what are its financial indicators?
- A method only used in Latin America by drug trafficking organizations
- A rare and easily detectable form of TF involving large wire transfers
- A financial crime limited to criminal gangs rather than terrorist organizations
- The practice by which terrorist groups (al-Qaeda, IS, Boko Haram) abduct individuals or groups and demand payment for their release, generating significant TF funds through direct cash payments or wire transfers to intermediaries in high-risk jurisdictions (Correct answer)
Correct answer: The practice by which terrorist groups (al-Qaeda, IS, Boko Haram) abduct individuals or groups and demand payment for their release, generating significant TF funds through direct cash payments or wire transfers to intermediaries in high-risk jurisdictions
Kidnapping for ransom is a major TF revenue source for groups like al-Qaeda and IS, generating hundreds of millions in ransom payments. Financial indicators include large unexplained transfers to high-risk jurisdictions, cash deliveries to intermediaries, and payments coded as consulting or services to obscure their purpose.
Question 12: A 'shell company' is most accurately described as which of the following?
- A legal entity with no significant assets or operations used to obscure ownership (Correct answer)
- A holding company that owns multiple operating subsidiaries
- A company registered in a foreign country for legitimate tax efficiency
- A company that manufactures and sells petroleum products
Correct answer: A legal entity with no significant assets or operations used to obscure ownership
Shell companies often have no real business activity and are used to layer ownership and obscure the true beneficial owner of assets.
Question 13: At the conclusion of a complex money laundering investigation, the compliance officer has determined that a SAR must be filed. The investigation revealed a sophisticated network of shell companies moving funds. Which of the following is the most important element to include in the SAR narrative?
- A chronological and detailed description of the suspicious activity, covering the 'who, what, where, when, and why'. (Correct answer)
- A recommendation to law enforcement on which specific statutes may have been violated.
- An exhaustive list of every non-suspicious transaction in the account during the review period.
- The personal opinion of the investigator on the customer's character.
Correct answer: A chronological and detailed description of the suspicious activity, covering the 'who, what, where, when, and why'.
The primary purpose of the SAR narrative is to provide a clear, concise, and comprehensive account of the suspicious activity for law enforcement. Covering the 'who, what, where, when, why, and how' provides law enforcement with the actionable intelligence they need. Personal opinions are unprofessional, legal conclusions are the responsibility of law enforcement, and including non-suspicious activity clutters the report and obscures the key facts.
Question 14: Which of the following is considered a core requirement of a Customer Due Diligence (CDD) program according to the FinCEN CDD Final Rule?
- Processing all customer transactions within 24 hours.
- Reporting all cash transactions exceeding $5,000 to the board of directors.
- Conducting ongoing monitoring to identify and report suspicious transactions. (Correct answer)
- Obtaining a credit report for every new customer.
Correct answer: Conducting ongoing monitoring to identify and report suspicious transactions.
The FinCEN CDD Final Rule explicitly outlines four core requirements for CDD programs. These are: 1) identifying and verifying the identity of customers; 2) identifying and verifying the identity of beneficial owners of legal entity customers; 3) understanding the nature and purpose of customer relationships to develop a customer risk profile; and 4) conducting ongoing monitoring to identify and report suspicious transactions and, on a risk basis, to maintain and update customer information.
Question 15: When a legal entity customer is a publicly traded company on a US exchange, how does FinCEN's CDD Rule treat beneficial ownership requirements?
- The exchange provides all required beneficial ownership data
- Only the CEO must be identified
- Full beneficial ownership documentation is still required
- Covered financial institutions may exclude these entities from beneficial ownership identification requirements (Correct answer)
Correct answer: Covered financial institutions may exclude these entities from beneficial ownership identification requirements
FinCEN's CDD Rule provides exclusions for certain regulated entities, including companies listed on US stock exchanges, because their ownership is already subject to SEC disclosure requirements.
Question 16: What is the role of the 'BSA Officer' (BSAO) in an AML investigation?
- The BSAO is responsible only for employee AML training programs
- The BSAO only files CTRs and has no role in investigations
- The BSAO only communicates with regulators and has no operational investigation role
- The BSAO oversees the AML compliance program and typically makes or approves final SAR filing decisions, ensuring investigations are thorough and documented (Correct answer)
Correct answer: The BSAO oversees the AML compliance program and typically makes or approves final SAR filing decisions, ensuring investigations are thorough and documented
The BSA Officer (also called the AML Compliance Officer) is responsible for overseeing the AML program, which includes ensuring investigations are properly conducted, documented, and that SAR filing decisions are sound and well-supported.
Question 17: What is a 'trigger event' in the context of CDD ongoing monitoring, and can you provide three examples?
- A system alert requiring immediate account freeze; examples: OFAC match, court order, law enforcement request
- An event requiring a financial institution to review and potentially update a customer's CDD information; examples: significant changes in transaction patterns, adverse media, or customer-initiated changes to account information (Correct answer)
- An indicator that a customer is about to close their account; examples: declining balance, reduced transaction frequency, competitor promotional offers
- A transaction that triggers an automatic SAR filing; examples: transactions over $10K, foreign wire transfers, cash deposits
Correct answer: An event requiring a financial institution to review and potentially update a customer's CDD information; examples: significant changes in transaction patterns, adverse media, or customer-initiated changes to account information
Trigger events are circumstances that prompt a review and potential update of a customer's CDD file. Examples include significant changes in transaction activity, adverse media hits, changes to beneficial ownership, or requests for new high-risk products.
Question 18: What is the difference between 'primary sanctions' and 'secondary sanctions' in the U.S. sanctions framework?
- Primary sanctions require congressional approval; secondary sanctions can be imposed by executive order
- Primary sanctions apply to U.S. persons and transactions in U.S. jurisdiction; secondary sanctions target non-U.S. persons conducting significant transactions with sanctioned parties even without U.S. nexus (Correct answer)
- Primary sanctions apply to criminal violations; secondary sanctions apply to civil violations
- Primary sanctions are imposed by the UN Security Council; secondary sanctions are unilateral U.S. measures
Correct answer: Primary sanctions apply to U.S. persons and transactions in U.S. jurisdiction; secondary sanctions target non-U.S. persons conducting significant transactions with sanctioned parties even without U.S. nexus
Primary sanctions prohibit U.S. persons and U.S.-nexus transactions from dealing with sanctioned parties. Secondary sanctions target non-U.S. persons who conduct significant business with sanctioned countries or entities, threatening them with exclusion from the U.S. financial system.
Question 19: A mid-sized bank has recently expanded its services to include international wire transfers to several new countries. According to the risk-based approach, what is the MOST appropriate next step for the bank's AML compliance officer?
- Implement a mandatory in-person training session for all 5,000 bank employees within one week.
- Hire a third-party vendor to monitor all transactions, regardless of risk level.
- Immediately file suspicious activity reports on the first ten transfers to the new countries.
- Conduct an updated enterprise-wide risk assessment to evaluate the new products, services, and geographic exposures. (Correct answer)
Correct answer: Conduct an updated enterprise-wide risk assessment to evaluate the new products, services, and geographic exposures.
The risk-based approach requires financial institutions to identify, assess, and understand the money laundering risks they face and apply proportionate controls. When a bank introduces new products or expands into new geographic areas, it must update its risk assessment to identify new potential vulnerabilities and ensure its controls are adequate to mitigate those risks.
Question 20: Which TBML technique involves exporting goods and invoicing them at a price higher than the true market value?
- Multiple invoicing
- Under-invoicing
- Phantom shipment
- Over-invoicing (Correct answer)
Correct answer: Over-invoicing
Over-invoicing allows the exporter to receive more funds than the goods are worth, effectively transferring value from the importing country to the exporting country.
Question 21: Which red flag is most associated with trade-based money laundering (TBML)?
- A customer requesting a wire transfer to a FATF-compliant jurisdiction
- Requesting online banking access for a new business account
- A business customer depositing revenue consistent with its industry
- Over- or under-invoicing of goods and services in international trade transactions (Correct answer)
Correct answer: Over- or under-invoicing of goods and services in international trade transactions
TBML often involves manipulating trade invoice values to transfer value across borders, making over- or under-invoicing a key red flag.
Question 22: What is the primary purpose of ongoing monitoring within a Customer Due Diligence (CDD) program?
- To detect transactions that are inconsistent with the customer's known profile and report suspicious activity. (Correct answer)
- To ensure all customer data is encrypted.
- To conduct annual performance reviews of compliance staff.
- To market new financial products to existing customers.
Correct answer: To detect transactions that are inconsistent with the customer's known profile and report suspicious activity.
Ongoing monitoring is a critical pillar of CDD. Its primary purpose is to scrutinize transactions to ensure they are consistent with the institution's knowledge of the customer, their business, and their risk profile. This allows the institution to identify potentially suspicious activity that may be indicative of money laundering or other financial crimes and report it as required.
Question 23: What is 'round-tripping' in the context of TBML?
- Shipping goods from a country and returning them to the same country as different goods
- Issuing multiple invoices for one shipment
- A customs process for inspecting returned goods
- Sending funds overseas and repatriating them as foreign investment or trade proceeds (Correct answer)
Correct answer: Sending funds overseas and repatriating them as foreign investment or trade proceeds
Round-tripping involves moving money out of a country and bringing it back disguised as legitimate foreign investment or export proceeds to give illicit funds a lawful appearance.
Question 24: After filing a SAR on a customer, what is the most appropriate next step for the financial institution regarding the customer's account?
- Continue to monitor the account, potentially under enhanced due diligence, and report any further suspicious activity. (Correct answer)
- Cease all monitoring of the account as the responsibility has been transferred to the FIU.
- Inform the customer that a SAR has been filed to maintain transparency.
- Immediately freeze all assets in the account pending law enforcement action.
Correct answer: Continue to monitor the account, potentially under enhanced due diligence, and report any further suspicious activity.
Filing a SAR does not end the institution's AML obligations. The institution must not 'tip off' the customer about the SAR filing. It should continue to monitor the customer's activity, applying enhanced due diligence as appropriate, and file supplemental SARs for any new suspicious transactions. Account closure decisions should be made based on the institution's risk appetite and policies, but monitoring must continue as long as the account is open.
Question 25: Which of the following is NOT considered a Politically Exposed Person (PEP) under FATF guidance?
- A head of state
- A mid-level tax administrator with no policy-making authority (Correct answer)
- A senior military official
- A senior executive of a state-owned enterprise
Correct answer: A mid-level tax administrator with no policy-making authority
FATF defines PEPs as individuals entrusted with prominent public functions; a mid-level tax administrator without policy-making authority does not meet this elevated risk threshold.
Question 26: What does a 'risk-based approach' to AML allow financial institutions to do that a purely rule-based approach does not?
- Allocate compliance resources proportional to the level of money laundering risk, applying more scrutiny where risk is higher (Correct answer)
- Eliminate all AML controls for low-risk customers
- Set their own SAR filing thresholds
- Exempt themselves from BSA reporting requirements
Correct answer: Allocate compliance resources proportional to the level of money laundering risk, applying more scrutiny where risk is higher
The risk-based approach allows institutions to concentrate their AML resources where money laundering risk is highest, rather than applying identical controls to all customers and transactions regardless of risk level.
Question 27: An investigator is analyzing an alert on a customer's account involving structured cash deposits followed by an outgoing wire transfer. The investigator has reviewed account opening documents, transaction history, and notes from the relationship manager. Which of the following represents the next logical step of gathering *external* information?
- Interviewing the teller who accepted the cash deposits.
- Checking the institution's central database for other accounts linked to the customer.
- Performing a public internet search on the beneficiary of the wire transfer. (Correct answer)
- Reviewing security camera footage of the deposits being made.
Correct answer: Performing a public internet search on the beneficiary of the wire transfer.
Options A, C, and D all represent the gathering of *internal* information that is already within the financial institution's possession or accessible through its staff and systems. Performing a public internet search on the wire beneficiary is a classic example of using external, open-source intelligence (OSINT) to add context to the investigation, such as verifying the beneficiary's business or looking for adverse information.
Question 28: A financial institution receives a grand jury subpoena for the financial records of one of its customers. What is the most critical action the institution must take upon receipt?
- Comply with the subpoena's request for information while maintaining strict confidentiality about its existence. (Correct answer)
- Immediately notify the customer that law enforcement has requested their records.
- Conduct an internal investigation and file a SAR on the customer before responding.
- Freeze all transactions on the account until the subpoena has been fulfilled.
Correct answer: Comply with the subpoena's request for information while maintaining strict confidentiality about its existence.
A grand jury subpoena is a formal legal order that must be complied with. A critical aspect of such subpoenas is the requirement for secrecy to avoid compromising the investigation. Notifying the customer could be considered obstruction of justice. While the receipt of a subpoena should prompt a review of the customer's activity to determine if a SAR is warranted, it does not automatically require one to be filed. Freezing the account is not typically required by a subpoena alone and should only be done with a specific court order, such as a seizure warrant.
Question 29: What is the '60-day rule' for SAR filing?
- Institutions must retain SAR documentation for at least 60 days after filing
- SARs must be filed no later than 60 days after the date the financial institution initially detected the suspicious activity, with an option for an additional 30 days if needed to identify a subject (Correct answer)
- Law enforcement has 60 days to respond to a filed SAR before an institution may close the account
- SARs must be filed within 60 days of account opening for all high-risk customers
Correct answer: SARs must be filed no later than 60 days after the date the financial institution initially detected the suspicious activity, with an option for an additional 30 days if needed to identify a subject
Under BSA regulations, SARs must generally be filed within 30 days of initial detection of suspicious activity. If additional time is needed to identify the subject involved, an extension of up to 60 days from initial detection is permitted, for a maximum of 60 days total.
Question 30: Under OFAC regulations, what does 'blocking' a transaction mean?
- Delaying a transaction pending additional customer documentation
- Returning funds to the originating party without processing
- Freezing assets or funds associated with sanctioned parties so they cannot be moved (Correct answer)
- Reporting the transaction to the IRS for tax investigation
Correct answer: Freezing assets or funds associated with sanctioned parties so they cannot be moved
Blocking under OFAC means freezing assets or transactions involving sanctioned persons or entities so they cannot be transferred, withdrawn, or used.
Question 31: Under FinCEN's Customer Due Diligence (CDD) Rule, what is the beneficial ownership threshold that triggers identification requirements for legal entity customers?
- 25% or more ownership (Correct answer)
- 20% or more ownership
- 10% or more ownership
- 51% or more ownership
Correct answer: 25% or more ownership
The CDD Rule requires identification of any natural person owning 25% or more of a legal entity, plus one control person.
Question 32: What is a critical component of Know Your Customer (KYC) requirements, according to the Basel Committee's Customer Due Diligence for Banks paper?
- All completed KYC documentation must be evaluated by a senior manager that was not engaged in the account opening process
- A policy on customer acceptance (Correct answer)
- Annual staff training
- KYC criteria must be the same in all circumstances
Correct answer: A policy on customer acceptance
According to the Basel Committee's Customer Due Diligence for Banks paper, a policy on customer acceptance is a critical component of KYC. This policy establishes clear criteria for deciding which customers a bank will accept, ensuring that the institution understands and manages the risks associated with its client base from the outset. It helps prevent high-risk individuals or entities from entering the financial system.
Question 33: A key element of developing a customer risk profile as part of the CDD process involves:
- Understanding the customer's political affiliation.
- Understanding the nature and purpose of the customer relationship. (Correct answer)
- Limiting the number of transactions the customer can perform.
- Requiring the customer to maintain a minimum account balance.
Correct answer: Understanding the nature and purpose of the customer relationship.
A fundamental component of Customer Due Diligence is understanding the nature and purpose of the customer relationship. This allows the financial institution to develop a customer risk profile and anticipate the types of transactions the customer is likely to conduct. This baseline is essential for ongoing monitoring to detect activity that is unusual or inconsistent with the customer's profile.
Question 34: For PEP relationships, FATF Recommendation 12 requires which specific additional measure beyond standard CDD?
- Obtaining government approval to maintain the account
- Limiting PEP accounts to domestic transactions only
- Senior management approval for establishing or continuing the business relationship (Correct answer)
- Reporting all PEP transactions to financial intelligence units
Correct answer: Senior management approval for establishing or continuing the business relationship
FATF Recommendation 12 requires senior management approval for establishing or continuing business relationships with PEPs, in addition to enhanced due diligence measures.
Question 35: What is the Egmont Group and how does it support international AML efforts?
- A global network of Financial Intelligence Units (FIUs) that facilitates the secure exchange of financial intelligence information between member country FIUs to support AML/CFT investigations (Correct answer)
- A FATF working group focused on assessing developing country compliance
- A UN body that coordinates economic sanctions against money laundering havens
- An international association of AML compliance officers providing professional certification
Correct answer: A global network of Financial Intelligence Units (FIUs) that facilitates the secure exchange of financial intelligence information between member country FIUs to support AML/CFT investigations
The Egmont Group is a network of over 160 Financial Intelligence Units that enables secure, confidential sharing of financial intelligence between member FIUs — critical for investigating cross-border money laundering and terrorist financing.
Question 36: What are 'virtual assets' (VA) and 'virtual asset service providers' (VASPs) under FATF standards, and what AML obligations apply?
- VA are in-game currencies exempt from AML; VASPs are mobile payment apps subject to standard MSB rules
- VA are only cryptocurrency; VASPs are only large exchanges like Coinbase and Binance subject to SEC regulation
- VA are foreign currencies held electronically; VASPs are foreign banks exempt from U.S. AML requirements
- VA are digital representations of value that can be transferred or traded digitally; VASPs (exchanges, custodians, wallet providers) must register/license with competent authorities and apply AML/CFT measures including CDD, transaction monitoring, and the Travel Rule for VA transfers (Correct answer)
Correct answer: VA are digital representations of value that can be transferred or traded digitally; VASPs (exchanges, custodians, wallet providers) must register/license with competent authorities and apply AML/CFT measures including CDD, transaction monitoring, and the Travel Rule for VA transfers
FATF's updated Recommendation 15 (2019) defines virtual assets broadly and requires VASPs — exchanges, custodians, and wallet providers — to be registered or licensed and to apply full AML/CFT obligations including the Travel Rule for VA transfers above threshold.
Question 37: An AML investigator is reviewing a corporate account for a company that imports electronics. The account shows several large, round-figure wire transfers to a new supplier in a high-risk jurisdiction, which is inconsistent with the company's established payment patterns. The investigator has already reviewed all internal customer due diligence (CDD) information. What is the most appropriate next step to gather more context?
- Close the account immediately to mitigate the financial institution's risk.
- Immediately file a Suspicious Activity Report (SAR) based on the red flags.
- Conduct open-source intelligence (OSINT) research on the new supplier and review public records. (Correct answer)
- Contact the customer directly to inquire about the purpose of the new payments.
Correct answer: Conduct open-source intelligence (OSINT) research on the new supplier and review public records.
The most appropriate next step is to gather more information discreetly. Open-source intelligence (OSINT) allows the investigator to research the new supplier, check for adverse media, verify its business legitimacy, and look for any connections to sanctioned or high-risk entities without alerting the customer. Filing a SAR may be premature without further context. Contacting the customer could lead to tipping off, and closing the account is an action taken after a risk decision is made, not typically as an investigative step.
Question 38: Which international body has issued guidance specifically addressing TBML typologies and red flags?
- World Customs Organization (WCO) alone
- International Monetary Fund (IMF)
- Financial Action Task Force (FATF) (Correct answer)
- World Trade Organization (WTO)
Correct answer: Financial Action Task Force (FATF)
FATF issued a landmark report on TBML in 2006 and subsequent guidance identifying key typologies, red flags, and recommended controls.
Question 39: What is a 'pre-implementation review' in the context of new products or services?
- A regulatory pre-approval process for all new financial products
- An AML/CFT risk assessment conducted before a new product, service, or technology is launched to identify potential money laundering risks and ensure adequate controls are in place prior to launch (Correct answer)
- A customer focus group conducted before launching a new product
- A review of competitor products to ensure the institution's offering is competitive
Correct answer: An AML/CFT risk assessment conducted before a new product, service, or technology is launched to identify potential money laundering risks and ensure adequate controls are in place prior to launch
A pre-implementation risk review requires the AML compliance function to assess ML/TF risks of new products or services before launch, ensuring controls are designed and implemented proactively rather than retroactively discovering AML gaps after the product is live.
Question 40: An AML investigator is reviewing an alert for a customer's account. Which of the following is the most crucial first step in the investigation process?
- Review the customer's profile and historical transactions to understand the baseline activity. (Correct answer)
- Contact the customer to inquire about the unusual activity.
- Immediately file a Suspicious Activity Report (SAR).
- Close the account to mitigate any potential risk.
Correct answer: Review the customer's profile and historical transactions to understand the baseline activity.
Before determining if an activity is truly suspicious, an investigator must understand the customer's profile, risk rating, and normal transaction history. This provides the necessary context to assess whether the flagged activity is a deviation from the norm or within the expected pattern of behavior for that specific customer. Filing a SAR prematurely, tipping off the customer, or closing the account without proper investigation are all inappropriate actions.
Question 41: How should financial institutions handle CDD for customers who claim to be acting on behalf of an undisclosed principal?
- Treat this as a significant red flag, attempt to identify and verify the undisclosed principal, and consider whether to file a SAR if the principal cannot be identified (Correct answer)
- Require the undisclosed principal to appear in person before any account activity
- Accept the claim and proceed with only the agent's identification
- Refuse all such customers without exception as they pose automatic ML risk
Correct answer: Treat this as a significant red flag, attempt to identify and verify the undisclosed principal, and consider whether to file a SAR if the principal cannot be identified
Customers acting for undisclosed principals raise significant AML concerns because the true beneficial owner is hidden. Institutions should attempt to identify the principal, treat the opacity as a high-risk indicator, and consider whether suspicious activity reporting is warranted.
Question 42: What is the difference between a 'voluntary SAR' and a 'mandatory SAR'?
- Mandatory SARs require law enforcement approval; voluntary SARs can be filed without review
- Voluntary SARs are filed with FinCEN; mandatory SARs are filed with the relevant bank regulator
- All SAR filings by covered financial institutions are mandatory when the filing threshold is met; 'voluntary' SARs refer to filings below the mandatory threshold or by non-covered entities filing on a discretionary basis (Correct answer)
- Voluntary SARs are filed at the institution's discretion for any suspicious activity; mandatory SARs are required only for transactions over $10,000
Correct answer: All SAR filings by covered financial institutions are mandatory when the filing threshold is met; 'voluntary' SARs refer to filings below the mandatory threshold or by non-covered entities filing on a discretionary basis
Covered financial institutions are required to file SARs when the mandatory filing threshold and criteria are met. 'Voluntary' SARs are filed at an institution's discretion — either below the mandatory dollar threshold or by entities not legally required to file — as a good-faith disclosure of suspicious activity.
Question 43: What are the four pillars of a BSA/AML compliance program as required by U.S. regulators?
- KYC, transaction monitoring, SAR filing, and customer segmentation
- Policies, training, auditing, and customer service
- Board oversight, legal review, IT systems, and staff certification
- Internal controls, a designated compliance officer, training, and independent testing (Correct answer)
Correct answer: Internal controls, a designated compliance officer, training, and independent testing
U.S. regulators require AML programs to have written internal controls, a BSA/AML officer, ongoing training, and independent audits.
Question 44: What is the purpose of an 'exit interview' when closing an account due to suspicious activity?
- To warn the customer that a SAR has been filed so they can seek legal counsel
- To negotiate repayment of any outstanding loan balances
- There should be no exit interview — institutions should close the account without indicating that suspicious activity concerns are the reason, to avoid tipping off the customer (Correct answer)
- To provide the customer with documentation of all transactions flagged as suspicious
Correct answer: There should be no exit interview — institutions should close the account without indicating that suspicious activity concerns are the reason, to avoid tipping off the customer
Institutions closing accounts due to suspicious activity must not reveal that AML concerns are the reason, as this would constitute tipping off under 31 USC 5318(g)(2). Account closures are typically handled without detailed explanation to avoid alerting the subject.
Question 45: Under FinCEN guidance, a business that exchanges virtual currency for fiat currency on behalf of customers is generally classified as which type of regulated entity?
- A broker-dealer subject to SEC oversight
- A money services business (MSB) subject to Bank Secrecy Act requirements (Correct answer)
- A non-bank financial institution exempt from AML requirements
- A commodity pool operator regulated by the CFTC
Correct answer: A money services business (MSB) subject to Bank Secrecy Act requirements
FinCEN guidance (2013 and subsequent) classifies virtual currency exchangers and administrators as money services businesses (MSBs) under the Bank Secrecy Act, requiring them to register, maintain AML programs, and file SARs and CTRs.
Question 46: What specific information should be included in a SAR narrative to maximize its utility to law enforcement?
- Only the account number, transaction dates, and total suspicious dollar amount
- The full context of the suspicious activity including who, what, when, where, why it is suspicious, how the scheme operates, all involved parties and accounts, prior SAR history, and any law enforcement contacts or legal process received (Correct answer)
- A brief description of the activity and a reference to the transaction monitoring scenario that triggered the alert
- The account holder's credit score and employment history
Correct answer: The full context of the suspicious activity including who, what, when, where, why it is suspicious, how the scheme operates, all involved parties and accounts, prior SAR history, and any law enforcement contacts or legal process received
An effective SAR narrative answers the five W's plus how: who is involved (all parties and entities), what activity occurred (specific transactions), when (dates and timeline), where (accounts, locations), why it is suspicious (specific reasons), and how the scheme works — providing law enforcement with a complete, actionable intelligence report.
Question 47: Which of the following best describes the primary objective of an AML/CFT risk assessment?
- To satisfy regulators by completing a mandatory annual exercise.
- To eliminate all potential exposure to money laundering and terrorist financing.
- To enable the institution to understand its risk profile and apply appropriate mitigating controls. (Correct answer)
- To create a definitive list of high-risk customers for account closure.
Correct answer: To enable the institution to understand its risk profile and apply appropriate mitigating controls.
The core purpose of a risk assessment is to identify and understand the specific ML/TF risks an institution faces so it can implement a tailored, risk-based AML/CFT program. The goal is not to eliminate risk entirely, which is impossible, but to manage it effectively by applying controls proportionate to the identified risks.
Question 48: What is the purpose of a 'compliance testing' function within an AML program, distinct from audit?
- Compliance testing is only required after a regulatory examination finds deficiencies
- Compliance testing reviews individual employee performance for disciplinary purposes
- Compliance testing and AML audit are identical functions that should be combined
- Compliance testing is ongoing quality assurance conducted by the compliance function itself to identify and remediate control weaknesses before formal audit reviews, providing first-line feedback on program effectiveness (Correct answer)
Correct answer: Compliance testing is ongoing quality assurance conducted by the compliance function itself to identify and remediate control weaknesses before formal audit reviews, providing first-line feedback on program effectiveness
Compliance testing (also called compliance monitoring or quality assurance) is a second-line function that proactively tests whether AML controls are operating effectively, identifying weaknesses before formal audit and supporting continuous improvement.
Question 49: What is the 'knowledge standard' that determines whether a non-U.S. financial institution violates U.S. secondary sanctions?
- The knowledge standard requires proof of intent to evade sanctions for secondary sanctions to apply
- U.S. secondary sanctions generally apply when a non-U.S. institution engages in significant transactions with sanctioned parties, with 'knowledge' of the sanctions status being a relevant but not always required element depending on the sanctions program (Correct answer)
- Non-U.S. institutions are never liable for secondary sanctions violations
- Non-U.S. institutions are strictly liable regardless of knowledge
Correct answer: U.S. secondary sanctions generally apply when a non-U.S. institution engages in significant transactions with sanctioned parties, with 'knowledge' of the sanctions status being a relevant but not always required element depending on the sanctions program
Secondary sanctions vary by program — some apply strictly to 'significant transactions' regardless of knowledge, while others require knowing participation in prohibited transactions. Non-U.S. institutions face the risk of OFAC designation or loss of U.S. market access for significant dealings with sanctioned parties.
Question 50: Which of the following is considered a primary risk associated with correspondent banking relationships for AML/CFT purposes?
- Limited visibility into the respondent bank's customers and their transactions. (Correct answer)
- The high volume of domestic transactions processed through the accounts.
- The respondent bank being subject to different data privacy regulations.
- The correspondent bank's inability to offer competitive interest rates.
Correct answer: Limited visibility into the respondent bank's customers and their transactions.
A major risk in correspondent banking is that the correspondent bank processes transactions for the customers of another bank (the respondent bank) without having a direct relationship with them. This creates a risk because it can be difficult to conduct due diligence on the respondent bank's customers, making it harder to identify and report suspicious activity.
Question 51: A customer frequently exchanges small-denomination bills for large-denomination bills at a bank branch with no apparent business reason. This behavior most likely indicates which money laundering stage?
- Structuring of clean funds
- Layering
- Placement (Correct answer)
- Integration
Correct answer: Placement
Exchanging small bills for large denominations is a classic placement technique used to consolidate physically bulky criminal cash proceeds.
Question 52: What is a 'look-back review' in the AML context?
- A regulatory exam of a bank's last five years of SAR filings
- An annual review of prior-year financial statements for accounting errors
- A retrospective analysis of historical transactions after a compliance gap is identified (Correct answer)
- A forward-looking risk assessment for new products or markets
Correct answer: A retrospective analysis of historical transactions after a compliance gap is identified
A look-back review examines past transaction activity—often mandated by regulators—to identify suspicious transactions that may have been missed.
Question 53: How should AML compliance programs be structured when an institution operates in multiple countries?
- Allow each country operation to establish entirely independent AML programs without headquarters oversight
- Establish a global minimum standard based on the most rigorous applicable requirements, with local country-specific additions to meet host country laws; coordinate global risk assessments while adapting controls for local market conditions (Correct answer)
- Only apply AML requirements in countries where FATF membership applies
- Apply only the home country's AML standards globally and ignore local requirements
Correct answer: Establish a global minimum standard based on the most rigorous applicable requirements, with local country-specific additions to meet host country laws; coordinate global risk assessments while adapting controls for local market conditions
Multinational institutions must meet the strictest applicable requirements across all jurisdictions — typically establishing a global minimum standard and layering local requirements on top — while maintaining enterprise-wide visibility through coordinated risk management.
Question 54: What is the primary definition of trade-based money laundering (TBML)?
- Using shell companies to conduct export business
- Moving cash across borders hidden in shipping containers
- Using trade transactions to move value and disguise criminal proceeds (Correct answer)
- Importing goods without paying customs duties
Correct answer: Using trade transactions to move value and disguise criminal proceeds
TBML involves manipulating trade transactions—through over/under-invoicing, multiple invoicing, or falsely described goods—to move value and legitimize illicit funds.
Question 55: A bank is onboarding a family trust as a new client. Who should be identified as the beneficial owner?
- The attorney who drafted the trust document
- The largest beneficiary only
- Only the trustee named on the trust document
- The settlor, trustee(s), protector (if any), beneficiaries, and any other natural person exercising ultimate effective control (Correct answer)
Correct answer: The settlor, trustee(s), protector (if any), beneficiaries, and any other natural person exercising ultimate effective control
For trusts, beneficial ownership extends to all parties exercising control or ownership over trust assets, including settlors, trustees, protectors, and beneficiaries, to ensure true ownership is transparent.
Question 56: What is the role of 'senior management' in BSA/AML compliance, distinct from the compliance officer and the board?
- Senior management has no defined AML role — all responsibility lies with the compliance officer
- Senior management is accountable for implementing the board-approved AML program within their business lines, ensuring adequate resources, and creating a culture of compliance that supports effective AML controls (Correct answer)
- Senior management's role is limited to approving the annual AML training curriculum
- Senior management only becomes involved when a SAR is filed against a customer
Correct answer: Senior management is accountable for implementing the board-approved AML program within their business lines, ensuring adequate resources, and creating a culture of compliance that supports effective AML controls
Senior management is responsible for implementing the AML program within their business lines, allocating necessary resources, supporting the compliance function's authority, and fostering a culture of compliance that makes AML effective in practice.
Question 57: What is a 'SAR waiver' and under what circumstances would law enforcement request one?
- A FinCEN exemption from SAR filing requirements for certain low-risk customer categories
- A board-approved exception allowing the compliance officer to determine that SAR filing is not required
- A formal request from law enforcement asking a financial institution to temporarily delay or refrain from filing a SAR on a specific account or individual so as not to compromise an active investigation (Correct answer)
- A waiver allowing the financial institution to file SARs after the 60-day deadline without penalty
Correct answer: A formal request from law enforcement asking a financial institution to temporarily delay or refrain from filing a SAR on a specific account or individual so as not to compromise an active investigation
Law enforcement may request that a financial institution delay or forego SAR filing on a specific account to protect an ongoing investigation — typically through official legal process — ensuring that SAR confidentiality provisions do not inadvertently reveal the investigation to the subject.
Question 58: How should an institution handle a FinCEN 314(a) inquiry for a customer who has a current SAR investigation open?
- Respond to the 314(a) inquiry as required (confirm or deny the match), continue the internal investigation, and ensure confidentiality is maintained for both the SAR and the 314(a) response (Correct answer)
- Halt the internal SAR investigation and wait for law enforcement to contact the institution directly
- Notify the customer that they have been identified in a law enforcement inquiry
- Immediately close the customer's account to avoid liability
Correct answer: Respond to the 314(a) inquiry as required (confirm or deny the match), continue the internal investigation, and ensure confidentiality is maintained for both the SAR and the 314(a) response
Institutions must respond to 314(a) inquiries confirming or denying whether the named individual has current accounts or conducted transactions, while simultaneously maintaining confidentiality of both the SAR investigation and the 314(a) response — they are separate, confidential processes.
Question 59: The Black Market Peso Exchange (BMPE) primarily originated from which illicit industry?
- Human smuggling
- Arms trafficking
- Cybercrime
- Drug trafficking (Correct answer)
Correct answer: Drug trafficking
BMPE originated as a method for Colombian drug traffickers to convert US dollar proceeds into Colombian pesos without moving currency across borders directly.
Question 60: Which organization jointly published the 2012 'Best Practices Paper on Trade-Based Money Laundering' with FATF?
- Wolfsberg Group
- Egmont Group
- Basel Committee
- Asia/Pacific Group on Money Laundering (APG) (Correct answer)
Correct answer: Asia/Pacific Group on Money Laundering (APG)
FATF and the APG jointly published the 2012 best practices paper on TBML, reflecting the significance of the Asia-Pacific region in global trade flows.
Question 61: Under FinCEN's Customer Due Diligence (CDD) Rule, what ownership threshold triggers beneficial ownership identification for legal entity customers?
- 10% or more
- 15% or more
- 25% or more (Correct answer)
- 51% or more
Correct answer: 25% or more
FinCEN's CDD Rule requires covered financial institutions to identify natural persons owning 25% or more of a legal entity customer and one person with significant managerial control.
Question 62: Which approach do blockchain analytics firms (e.g., Chainalysis, Elliptic) primarily use to link cryptocurrency wallet addresses to real-world entities?
- Accessing private keys stored on cryptocurrency exchanges
- Reviewing tax filings submitted by cryptocurrency holders
- Monitoring social media for public wallet address disclosures
- Clustering wallet addresses based on shared inputs and known exchange deposit patterns (Correct answer)
Correct answer: Clustering wallet addresses based on shared inputs and known exchange deposit patterns
Blockchain analytics firms cluster wallet addresses using heuristics such as common-input-ownership (wallets spending from the same transaction are likely controlled by the same entity) and tagging known exchange deposit addresses to attribute wallets to real-world entities.
Question 63: Which of the following situations would mandate a financial institution to conduct customer due diligence (CDD) measures, according to FATF Recommendation 10?
- Only when a transaction exceeds a very high, pre-defined internal threshold set by the bank's board.
- Only when a customer requests to open an account for a trust or legal arrangement.
- Only when establishing a new business relationship.
- When there is a suspicion of money laundering, regardless of any transaction threshold. (Correct answer)
Correct answer: When there is a suspicion of money laundering, regardless of any transaction threshold.
FATF Recommendation 10 states that CDD must be performed in several circumstances, including: when establishing business relations; when carrying out occasional transactions above the designated threshold; when there is a suspicion of money laundering or terrorist financing; or when the institution has doubts about the veracity of previously obtained customer identification data. A suspicion of ML/TF triggers the CDD requirement irrespective of any threshold.
Question 64: Under FATF Recommendation 12, for how long after an individual leaves a prominent public position should enhanced due diligence measures continue?
- PEP status ends immediately upon leaving office
- A risk-based period, often cited as 12–18 months or longer (Correct answer)
- Six months
- One year
Correct answer: A risk-based period, often cited as 12–18 months or longer
FATF recommends applying a risk-based approach for former PEPs, and many jurisdictions and industry guidance suggest monitoring for at least 12–18 months or longer depending on risk.
Question 65: What is the Financial Action Task Force's (FATF) mandate and membership structure?
- FATF is an NGO funded by private banks to develop voluntary AML best practices
- FATF is a World Bank initiative that provides technical assistance to developing countries on AML compliance
- FATF is a UN agency with 193 member countries that issues binding resolutions
- FATF is an intergovernmental policy-making body established in 1989 with 39 members (37 member jurisdictions plus the European Commission and Gulf Co-operation Council) that sets AML/CFT standards and assesses compliance (Correct answer)
Correct answer: FATF is an intergovernmental policy-making body established in 1989 with 39 members (37 member jurisdictions plus the European Commission and Gulf Co-operation Council) that sets AML/CFT standards and assesses compliance
FATF is an intergovernmental body established at the G7 Paris Summit in 1989. It has 39 members (37 jurisdictions plus the European Commission and GCC) and sets global AML/CFT standards through its 40 Recommendations.
Question 66: Under the FATF framework, what are 'Designated Non-Financial Businesses and Professions' (DNFBPs) required to do?
- Register with FinCEN and obtain a money transmitter license
- Apply AML/CFT measures including CDD and suspicious transaction reporting when performing certain activities (Correct answer)
- Only report suspicious transactions above $50,000
- Hire a dedicated compliance officer for every 10 employees
Correct answer: Apply AML/CFT measures including CDD and suspicious transaction reporting when performing certain activities
FATF Recommendations 22 and 23 require DNFBPs to apply customer due diligence, record-keeping, and suspicious transaction reporting requirements when they engage in specified financial activities.
Question 67: What does the Basel Committee's AML guidance (Basel III and CDD Paper) require of internationally active banks?
- Consolidated, enterprise-wide AML/CFT programs that apply the highest applicable standards across all subsidiaries, branches, and affiliates globally, with adequate information sharing between group entities (Correct answer)
- Only capital adequacy ratios related to AML fines and penalties
- Annual FATF Mutual Evaluation Report submission to the Basel Committee
- Mandatory AML insurance coverage for international operations
Correct answer: Consolidated, enterprise-wide AML/CFT programs that apply the highest applicable standards across all subsidiaries, branches, and affiliates globally, with adequate information sharing between group entities
The Basel Committee's CDD paper and related guidance require internationally active banks to implement enterprise-wide AML programs that apply the most stringent applicable standards globally, ensure information flows between group entities, and manage consolidated risk across all affiliates.
Question 68: When a financial institution identifies a discrepancy in beneficial ownership information provided by a customer, what is the appropriate response?
- Accept the customer's explanation without documentation
- Close the account immediately
- Immediately file a SAR without further investigation
- Conduct additional due diligence to resolve the discrepancy; escalate and file a SAR if suspicion remains (Correct answer)
Correct answer: Conduct additional due diligence to resolve the discrepancy; escalate and file a SAR if suspicion remains
FinCEN guidance requires institutions to conduct additional due diligence when discrepancies arise, and to file a SAR if the discrepancy cannot be satisfactorily resolved and suspicion of illicit activity remains.
Question 69: Which insurance product is most prone to money laundering?
- Collateral
- Regulated pension
- Casualty
- Annuity (Correct answer)
Correct answer: Annuity
Annuities are highly susceptible to money laundering due to their ability to convert large lump-sum payments into legitimate-looking income streams or to be surrendered for cash value. Their complex structure and long-term nature can obscure the true source of funds, making them an attractive vehicle for criminals to clean illicit proceeds.
Question 70: A financial institution's risk assessment identifies that it facilitates a high volume of international trade finance for a variety of goods. Which money laundering method should be of PRIMARY concern when developing risk mitigation strategies for this line of business?
- Structuring cash deposits below reporting thresholds.
- Trade-Based Money Laundering (TBML). (Correct answer)
- Smurfing through multiple third-party accounts.
- Misuse of correspondent banking relationships.
Correct answer: Trade-Based Money Laundering (TBML).
Trade-Based Money Laundering (TBML) is a method of disguising criminal proceeds through the use of trade transactions. Given that the institution is heavily involved in international trade finance, it is directly exposed to risks such as over- and under-invoicing of goods, phantom shipments, and other schemes used to move value and legitimize illicit funds. While other methods are possible, TBML is the most direct and significant risk associated with this specific business activity.
Question 71: What is 'mutual legal assistance' (MLA) and why is it important for international AML investigations?
- The FATF peer review process for evaluating member country AML programs
- Formal legal mechanisms (treaties and agreements) allowing countries to request and provide investigative assistance — including sharing evidence, executing search warrants, and seizing assets — across national borders (Correct answer)
- Bilateral agreements between financial institutions to share customer information across borders
- Technical assistance provided by developed countries to help developing countries build AML programs
Correct answer: Formal legal mechanisms (treaties and agreements) allowing countries to request and provide investigative assistance — including sharing evidence, executing search warrants, and seizing assets — across national borders
Mutual legal assistance treaties (MLATs) and agreements allow countries to formally request investigative assistance from each other — gathering evidence, executing judicial orders, and sharing financial intelligence — which is essential for prosecuting cross-border money laundering cases.
Question 72: What is a 'legal entity customer' under FinCEN's CDD Rule, and what are the primary exemptions from the beneficial ownership requirement?
- A corporation, LLC, partnership, or other entity formed by filing with a state; exemptions include publicly listed companies, government entities, regulated financial institutions, and certain pooled investment vehicles (Correct answer)
- Any business entity regardless of size; there are no exemptions
- Only privately held companies with revenues over $10 million; exemptions include sole proprietorships
- Any entity registered for tax purposes; exemptions include non-profit organizations
Correct answer: A corporation, LLC, partnership, or other entity formed by filing with a state; exemptions include publicly listed companies, government entities, regulated financial institutions, and certain pooled investment vehicles
Legal entity customers are entities formed by filing with state or federal authorities. Key exemptions from beneficial ownership requirements include publicly traded companies (registered with the SEC), government entities, federally regulated financial institutions, and certain SEC-registered investment vehicles.
Question 73: An investigator identifies a customer making frequent cash deposits in amounts just under the $10,000 reporting threshold across several different branches on the same day. This pattern is inconsistent with the customer's stated business profile. This activity is a classic red flag for:
- Structuring. (Correct answer)
- Correspondent banking risk.
- Trade-based money laundering.
- Terrorist financing.
Correct answer: Structuring.
Structuring is the act of breaking down a large transaction into smaller, individual transactions to evade currency reporting requirements. Making multiple cash deposits below the reporting threshold is a common method used to structure transactions and is a significant red flag for money laundering that requires investigation.
Question 74: In the FATF risk-based approach, what are the three primary risk categories that institutions must assess?
- Inherent risk, residual risk, and control risk
- Credit risk, market risk, and operational risk
- Regulatory risk, reputational risk, and legal risk
- Country/geographic risk, customer risk, and product/service/transaction risk (Correct answer)
Correct answer: Country/geographic risk, customer risk, and product/service/transaction risk
The FATF risk-based approach requires financial institutions to assess three primary AML risk categories: country/geographic risk (jurisdictions with higher ML/TF risk), customer risk (types of customers and their risk profiles), and product/service/transaction risk (financial services that may be more vulnerable to abuse).
Question 75: Which of the following is a key component of an effective Know Your Customer (KYC) program?
- Reviewing customer credit history before approving transactions
- Establishing a Customer Identification Program (CIP) to verify identity (Correct answer)
- Collecting marketing preferences from customers at onboarding
- Offering loyalty rewards to long-standing customers
Correct answer: Establishing a Customer Identification Program (CIP) to verify identity
CIP is a foundational KYC element requiring institutions to collect and verify identity information for each customer.
Question 76: What is 'PEP screening' and at what point in the customer lifecycle should it occur?
- A one-time check at account opening only
- An ongoing process at onboarding and periodically throughout the relationship to detect new PEP status or connections (Correct answer)
- A process conducted only when a customer initiates a wire transfer
- A manual review required only for customers with accounts above $1 million
Correct answer: An ongoing process at onboarding and periodically throughout the relationship to detect new PEP status or connections
PEP screening must be conducted at onboarding and on an ongoing basis because customers can acquire PEP status after account opening (e.g., a customer is elected to public office), requiring continuous monitoring.
Question 77: What does the legal term 'tipping off' mean in the AML context, and what is its consequence?
- Sharing customer information with another financial institution; it may violate privacy laws
- Providing anonymous tips to law enforcement; it is legally protected
- Disclosing to a subject that a SAR has been filed or is being considered about them; it is a federal crime under 31 USC 5318(g)(2) (Correct answer)
- Informing a supervisor about a colleague's suspicious behavior; it is encouraged
Correct answer: Disclosing to a subject that a SAR has been filed or is being considered about them; it is a federal crime under 31 USC 5318(g)(2)
Tipping off is the illegal act of notifying a customer or any person that they are the subject of a SAR investigation. Under 31 USC 5318(g)(2), tipping off is a federal crime that can result in imprisonment and fines.
Question 78: What information should be gathered during the initial stage of an AML investigation triggered by a transaction monitoring alert?
- Only the beneficial ownership information for the account
- Only the transaction details that triggered the alert
- Customer identity information, account history, related party information, transaction patterns, and any prior SAR or alert history (Correct answer)
- External law enforcement reports and media searches only
Correct answer: Customer identity information, account history, related party information, transaction patterns, and any prior SAR or alert history
A thorough AML investigation requires gathering comprehensive information from multiple sources: customer identity and KYC file, full account and transaction history, related party connections, prior alert/SAR history, and external sources such as public records and adverse media.
Question 79: Which of the following best describes a 'shell company' in the context of money laundering?
- A company that manufactures protective housing products
- A subsidiary of a publicly traded corporation
- A company in the early stages of incorporation
- A legal entity with no active business operations used to obscure ownership (Correct answer)
Correct answer: A legal entity with no active business operations used to obscure ownership
Shell companies have no genuine business activity and are often used to conceal the true beneficial owner of funds or assets.
Question 80: What is the recommended first step for a bank's trade finance unit when a TBML red flag is identified?
- Immediately freeze the account and report to FinCEN
- Notify the customer that the transaction is under review
- Conduct enhanced due diligence and escalate to the AML compliance team for review (Correct answer)
- Reject the transaction without investigation
Correct answer: Conduct enhanced due diligence and escalate to the AML compliance team for review
Upon identifying a TBML red flag, the appropriate response is to conduct enhanced due diligence, gather additional information, and escalate to AML compliance before deciding on any account action or SAR filing.
Question 81: In addition to identifying equity owners, FinCEN's beneficial ownership rule also requires identification of which individual?
- The entity's largest creditor
- All directors of the company
- The entity's registered agent
- A single person with significant responsibility to control, manage, or direct the entity (Correct answer)
Correct answer: A single person with significant responsibility to control, manage, or direct the entity
The CDD Rule's two-prong approach requires identifying equity owners at 25%+ and one control person with significant responsibility for managing or directing the entity.
Question 82: Which of the following best describes how an informal value transfer system (IVTS) like Hawala can be exploited for terrorist financing?
- By creating complex layers of publicly-listed shell corporations to obscure ownership.
- By requiring mandatory government registration and transparent reporting for every transaction.
- By processing high-value transactions exclusively through formal, regulated banking channels.
- By moving value across jurisdictions with minimal documentation and without the physical cross-border movement of currency. (Correct answer)
Correct answer: By moving value across jurisdictions with minimal documentation and without the physical cross-border movement of currency.
Informal value transfer systems such as Hawala operate on trust-based networks, allowing for the transfer of value from one location to another without the money physically crossing borders through formal financial institutions. This lack of a formal audit trail and reliance on anonymity makes them attractive for illicit financing.
Question 83: Which of the following customer types typically carries the HIGHEST inherent AML risk?
- A publicly traded company with audited financials
- A non-resident alien operating a cash-intensive business with no explained source of wealth (Correct answer)
- A domestic retail customer with direct deposit payroll
- A salaried government employee opening a savings account
Correct answer: A non-resident alien operating a cash-intensive business with no explained source of wealth
Non-resident aliens operating cash-intensive businesses with unexplained wealth combine multiple high-risk indicators: foreign status, cash-intensive industry, and lack of transparent financial history — all of which elevate inherent AML risk significantly.
Question 84: Non-Fungible Tokens (NFTs) present a money laundering risk primarily through which mechanism?
- Wash trading — selling NFTs to oneself at inflated prices to layer illicit funds (Correct answer)
- NFTs are exempt from AML regulations in all jurisdictions
- NFTs can be secretly converted to fiat currency without triggering reporting
- NFT platforms do not require internet connectivity, avoiding transaction records
Correct answer: Wash trading — selling NFTs to oneself at inflated prices to layer illicit funds
Wash trading in NFTs — where a seller transfers an NFT to themselves or a colluding party at an artificially high price — allows illicit funds to enter the market as 'sale proceeds,' effectively layering and integrating dirty money.
Question 85: A key component of a robust AML program is having a system of internal controls. This system should be designed to:
- Guarantee that no money laundering will ever occur at the institution.
- Ensure the institution's profitability by minimizing compliance-related costs.
- Provide daily reports to the board of directors on all customer transactions.
- Mitigate and manage the institution's identified ML/TF risks through policies, procedures, and processes. (Correct answer)
Correct answer: Mitigate and manage the institution's identified ML/TF risks through policies, procedures, and processes.
Internal controls are the policies, procedures, and systems put in place to mitigate the specific money laundering and terrorist financing (ML/TF) risks identified by the institution. This includes customer due diligence (CDD), transaction monitoring, and reporting requirements. The goal is to manage risk, not necessarily to guarantee its complete elimination.
Question 86: In the context of AML, what does 'layering' primarily aim to achieve?
- Converting cash into other asset types
- Disguising the audit trail between illicit funds and their source (Correct answer)
- Reintroducing funds into the legitimate economy
- Identifying the beneficial owner of an account
Correct answer: Disguising the audit trail between illicit funds and their source
Layering is the second stage of money laundering, designed to create a complex web of financial transactions that obscures the audit trail and makes tracing funds back to their criminal origin extremely difficult.
Question 87: An AML program's policies, procedures, and internal controls should be MOST influenced by which of the following?
- The AML programs of competing financial institutions.
- The personal preferences of the Chief Executive Officer.
- The results of the institution's enterprise-wide risk assessment. (Correct answer)
- The number of employees in the compliance department.
Correct answer: The results of the institution's enterprise-wide risk assessment.
The foundation of a risk-based AML program is the enterprise-wide risk assessment. The results of this assessment, which identifies the specific ML/TF risks the institution faces from its customers, products, services, and geographies, should directly inform the design and implementation of its policies, procedures, and controls.
Question 88: What is 'perpetual KYC' (pKYC) and how does it differ from traditional periodic CDD reviews?
- A one-time comprehensive KYC review replacing all future reviews
- An automated system that files SARs without human review
- A legal requirement that customer information be verified once every 12 months
- A continuous, event-driven approach to CDD that updates customer risk profiles in real time as new information is received, rather than conducting scheduled periodic reviews (Correct answer)
Correct answer: A continuous, event-driven approach to CDD that updates customer risk profiles in real time as new information is received, rather than conducting scheduled periodic reviews
Perpetual KYC is a modern approach that continuously monitors and updates customer risk profiles based on real-time data triggers, replacing or supplementing the traditional periodic (annual/triennial) review cycle with dynamic, event-driven updates.
Question 89: What is 'regulatory examination management' and why is it an important AML program component?
- The process of preparing for, managing, and responding to regulatory examinations of the AML program, including organizing documentation, coordinating staff responses, addressing findings promptly, and implementing corrective action plans (Correct answer)
- Hiring former regulators to lead the compliance department
- Lobbying regulators to reduce AML requirements
- Scheduling examinations at times that minimize business disruption
Correct answer: The process of preparing for, managing, and responding to regulatory examinations of the AML program, including organizing documentation, coordinating staff responses, addressing findings promptly, and implementing corrective action plans
Regulatory examination management ensures the institution is always examination-ready, that examiners have efficient access to required documentation, and that findings are addressed promptly through documented corrective action plans.
Question 90: A compliance officer at a bank is investigating a series of complex wire transfers involving a corporate account. The transfers originate from a high-risk jurisdiction and are immediately moved to another account in a different country, with no clear business rationale. After a thorough review of the customer's due diligence file and transaction history, the officer develops a reasonable suspicion of money laundering. What is the immediate and most critical obligation of the financial institution?
- Report the suspicious activity to the relevant Financial Intelligence Unit (FIU) without delay. (Correct answer)
- Continue monitoring the account for another 90 days to gather more evidence.
- Discontinue the customer relationship and close the account immediately.
- Request a meeting with the customer's management to discuss the transactions.
Correct answer: Report the suspicious activity to the relevant Financial Intelligence Unit (FIU) without delay.
Once reasonable grounds to suspect money laundering or terrorist financing are established, the primary obligation is to report the activity to the appropriate authorities, which is the Financial Intelligence Unit (FIU) in most jurisdictions, by filing a Suspicious Activity Report (SAR) or Suspicious Transaction Report (STR). Delaying the report or tipping off the customer by discussing the suspicion with them would be a violation of AML regulations. While account closure may be a subsequent step, the immediate legal duty is to report.
Question 91: A bank receives a large cash deposit from a business customer that is inconsistent with the business's stated purpose. Which type of report is the bank most likely required to file?
- FinCEN Form 105
- Currency Transaction Report (CTR)
- Suspicious Activity Report (SAR) (Correct answer)
- Foreign Bank Account Report (FBAR)
Correct answer: Suspicious Activity Report (SAR)
A SAR is filed when a transaction is unusual or suspicious, even if it meets CTR thresholds, because it may indicate money laundering.
Question 92: What should an effective AML training program include to meet regulatory expectations?
- Training only for new hires during their onboarding process
- A single annual training module covering all BSA topics for all employees
- AML training only for employees in the compliance department
- Risk-based training tailored to employees' roles and responsibilities, covering relevant AML regulations, red flags specific to their business line, SAR filing obligations, and training on current typologies and schemes (Correct answer)
Correct answer: Risk-based training tailored to employees' roles and responsibilities, covering relevant AML regulations, red flags specific to their business line, SAR filing obligations, and training on current typologies and schemes
Effective AML training must be risk-based and role-specific — front-line tellers receive different training than private bankers or trade finance officers — and must be regularly updated to cover current typologies, schemes, and regulatory developments.
Question 93: A VASP's risk-based approach to customer due diligence should assign higher risk to which type of customer?
- A customer who has completed full KYC and provided government-issued ID
- A retail investor making small recurring purchases of Bitcoin over 12 months
- An institutional investor subject to its own regulated AML program
- A business customer whose principal is a Politically Exposed Person operating from a high-risk jurisdiction (Correct answer)
Correct answer: A business customer whose principal is a Politically Exposed Person operating from a high-risk jurisdiction
Customers who are Politically Exposed Persons (PEPs) or are based in high-risk jurisdictions require enhanced due diligence under a risk-based approach, as the combination of public influence and geographic risk significantly elevates the potential for corruption and money laundering.
Question 94: A financial institution is onboarding a new corporate customer. According to the FATF Recommendations, identifying and verifying the identity of which of the following is a mandatory part of Customer Due Diligence?
- The corporation's largest supplier.
- The customer's primary legal counsel.
- The beneficial owner(s) of the corporation. (Correct answer)
- All senior managers of the corporation.
Correct answer: The beneficial owner(s) of the corporation.
The Financial Action Task Force (FATF) Recommendations state that a key component of Customer Due Diligence (CDD) is identifying the beneficial owner and taking reasonable measures to verify their identity. This ensures that the financial institution knows who ultimately owns or controls the legal entity customer, which is crucial for assessing risk.
Question 95: What enhanced due diligence measures are specifically required for Politically Exposed Persons (PEPs) under FATF Recommendation 12?
- PEPs need only standard CDD since their public role makes them lower risk
- PEPs are only subject to EDD if they are from high-risk jurisdictions
- Senior management approval for the relationship, reasonable measures to establish the source of wealth and funds, and enhanced ongoing monitoring (Correct answer)
- PEPs must be refused all banking services under FATF standards
Correct answer: Senior management approval for the relationship, reasonable measures to establish the source of wealth and funds, and enhanced ongoing monitoring
FATF Recommendation 12 requires that for PEPs, institutions must: obtain senior management approval; take reasonable measures to establish source of wealth and funds; and conduct enhanced ongoing monitoring of the business relationship.
Question 96: What is the significance of the FATF 'grey list' (Jurisdictions Under Increased Monitoring) for a VASP conducting due diligence on counterparty VASPs?
- Grey-listed countries have banned all cryptocurrency activity and must be blocked entirely
- VASPs from grey-listed jurisdictions face enhanced scrutiny because their home country has strategic AML/CFT deficiencies (Correct answer)
- Grey-listed countries are exempt from the Travel Rule for a transitional period
- Transactions to grey-listed jurisdictions are automatically flagged as terrorist financing
Correct answer: VASPs from grey-listed jurisdictions face enhanced scrutiny because their home country has strategic AML/CFT deficiencies
FATF grey-listed jurisdictions have identified strategic AML/CFT deficiencies and are under increased monitoring; VASPs should apply enhanced due diligence to counterparty VASPs and customers from these countries, as the regulatory oversight in their home jurisdiction may be inadequate.
Question 97: What is the purpose of 'independent testing' (AML audit) and what are the key attributes of an effective AML audit?
- An annual IT security audit of the transaction monitoring system
- An objective evaluation conducted by individuals independent of the AML function that assesses the adequacy and effectiveness of the AML program and its compliance with BSA requirements (Correct answer)
- The AML compliance team audits itself to identify self-improvement opportunities
- A review of individual SAR filing decisions conducted by the BSA Officer
Correct answer: An objective evaluation conducted by individuals independent of the AML function that assesses the adequacy and effectiveness of the AML program and its compliance with BSA requirements
Independent testing provides objective assurance that the AML program is adequate, effective, and compliant with BSA requirements. It must be conducted by parties independent of the compliance function, on a risk-based schedule, with results reported to the board.
Question 98: What is the role of the 'board of directors' in overseeing the BSA/AML compliance program?
- The board's only role is to approve the AML budget annually
- The board has no AML responsibility — that rests entirely with the compliance officer
- The board only becomes involved when a regulatory enforcement action is initiated
- The board approves the AML program and policies, receives regular reports on AML program performance, and is ultimately accountable for ensuring the institution maintains effective AML controls (Correct answer)
Correct answer: The board approves the AML program and policies, receives regular reports on AML program performance, and is ultimately accountable for ensuring the institution maintains effective AML controls
The board of directors bears ultimate accountability for BSA/AML compliance. The board approves the AML program and policies, receives regular compliance reports, ensures adequate resources are allocated, and is held responsible by regulators for the effectiveness of the program.
Question 99: Which of the following entities is typically EXEMPT from FinCEN beneficial ownership reporting under the Corporate Transparency Act?
- A foreign company with a US bank account
- A small business with fewer than 10 employees
- A newly formed single-member LLC with no employees
- A publicly traded company subject to SEC reporting requirements (Correct answer)
Correct answer: A publicly traded company subject to SEC reporting requirements
Publicly traded companies subject to SEC reporting requirements are among the 23 categories of entities exempt from CTA reporting because their ownership is already publicly disclosed.
Question 100: Which of the following is a primary purpose of the independent testing (or audit) component of an AML program?
- To replace the need for ongoing employee training.
- To ensure the program is functioning as designed and is effective in mitigating ML/TF risks. (Correct answer)
- To set the risk appetite and tolerance for the financial institution.
- To discipline employees who fail to meet their compliance obligations.
Correct answer: To ensure the program is functioning as designed and is effective in mitigating ML/TF risks.
The independent testing or audit function is a critical component of an AML program. Its primary purpose is to provide an objective evaluation of the program's adequacy and effectiveness, ensuring that policies are being followed and that the program is appropriately mitigating money laundering and terrorist financing risks.
ACAMS CAMS Certification Exam
The ACAMS CAMS exam certifies anti-money laundering specialists with 100 questions over 3.5 hours, covering AML/CFT risks, compliance programs, customer due diligence, investigations, and global sanctions.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds